This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Horse ccfgn.dll

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi vetri vendan and welcome to the forums here at WTT.

:welcome:

No need to attach the logs, unless we have something really big.

Looks like some stubborn stuff here. Let's see what we can do….

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi,
Thankyou for immediate response.
I have done what you had asked for and have provided the log below
Had no problem in running combofix and hijackthis but ccfgn.dll still there and norton keeps alerting every time i open IE
(earlier reply got auto rejected as i had used older version of hijackthis downloaded from the link you had provided, below log from the latest version) Awaiting your reply.
Vetri.

ComboFix 09-02-11.02 - ramnath 2009-02-12 11:49:20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.399 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-12 to 2009-02-12 )))))))))))))))))))))))))))))))
.

2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\documents and settings\ramnath\Application Data\Malwarebytes
2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-11 14:17 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 14:17 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-06 14:49 . 2009-02-08 11:36 d——– c:\program files\Emoze
2009-02-06 14:49 . 2009-02-06 14:53 d——– c:\documents and settings\ramnath\Application Data\emoze
2009-02-04 18:27 . 2009-02-04 18:27 d——– c:\documents and settings\ramnath\Application Data\Apple Computer
2009-02-04 18:16 . 2009-02-04 18:17 d——– c:\program files\QuickTime
2009-02-04 18:15 . 2009-02-04 18:15 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-04 18:13 . 2009-02-04 18:13 d——– c:\program files\Apple Software Update
2009-02-04 18:13 . 2009-02-04 18:13 d——– c:\documents and settings\All Users\Application Data\Apple
2009-02-04 14:07 . 2009-02-04 14:07 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-04 14:07 . 2009-02-04 14:07 1,409 –a—— c:\windows\QTFont.for
2009-01-25 18:47 . 2009-01-25 18:47 d——– c:\documents and settings\LocalService\Application Data\Symantec
2009-01-23 13:14 . 2009-01-23 13:14 d——– c:\windows\lhsp
2009-01-23 13:13 . 2009-01-23 13:13 d——– c:\windows\speech
2009-01-20 10:19 . 2009-01-20 10:19 d——– c:\documents and settings\ramnath\Contacts
2009-01-20 10:17 . 2009-01-20 10:17 d—-c— c:\windows\system32\DRVSTORE
2009-01-20 10:14 . 2009-01-20 10:14 d–hsc— c:\program files\Common Files\WindowsLiveInstaller
2009-01-20 10:13 . 2009-01-20 10:16 d——– c:\program files\Windows Live
2009-01-20 10:13 . 2009-01-20 10:13 d——– c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-19 19:57 . 2009-01-19 19:57 d——– c:\documents and settings\ramnath\Application Data\pdf995
2009-01-19 19:57 . 2009-01-19 19:57 28 –a—— c:\windows\pdf995.ini
2009-01-19 19:55 . 2009-01-19 19:55 5,391,760 –a—— C:\ps2pdf995.exe
2009-01-19 19:47 . 2009-01-19 19:55 d——– c:\program files\pdf995
2009-01-19 19:47 . 2009-01-30 13:35 d——– c:\documents and settings\All Users\Application Data\pdf995
2009-01-19 19:47 . 2009-01-19 19:47 249,856 –a—— c:\windows\system32\pdfmona.dll
2009-01-19 19:47 . 2009-01-19 19:47 51,716 –a—— c:\windows\system32\pdf995mon.dll
2009-01-19 19:47 . 2009-01-30 13:35 59 –a—— c:\windows\wpd99.drv
2009-01-19 15:56 . 2008-09-25 18:50 483,328 –a—— c:\windows\system32\actskn45.ocx
2009-01-19 15:54 . 2009-01-19 15:54 9,833,120 –a—— C:\iMeshV8.exe
2009-01-17 18:36 . 2009-01-17 18:36 d——– c:\program files\Softick
2009-01-13 16:32 . 2001-08-18 17:30 10,129,408 –a—— c:\windows\system32\dllcache\hwxkor.dll
2009-01-13 16:31 . 2001-08-18 17:30 57,398 –a—— c:\windows\system32\dllcache\imjpdadm.exe
2009-01-13 16:31 . 2001-08-18 17:30 45,109 –a—— c:\windows\system32\dllcache\imjpuex.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 10:11 ——— d—–w c:\documents and settings\ramnath\Application Data\Murasu
2009-02-04 09:13 ——— d—–w c:\documents and settings\ramnath\Application Data\LimeWire
2009-01-31 10:44 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-30 08:51 ——— d—–w c:\program files\LimeWire
2009-01-30 07:52 ——— d—–w c:\documents and settings\ramnath\Application Data\Image Zone Express
2009-01-22 06:47 ——— d—–w c:\program files\ThreatExpert Memory Scanner
2009-01-09 09:40 ——— d—–w c:\program files\ORITE
2009-01-09 09:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-07 10:38 ——— d—–w c:\program files\Common Files\InstallShield
2009-01-07 10:31 ——— d—–w c:\program files\Dorgem
2009-01-05 08:33 ——— d—–w c:\documents and settings\ramnath\Application Data\RecordNow
2009-01-05 07:13 ——— d—–w c:\program files\Common Files\Adobe
2009-01-04 08:20 ——— d—–w c:\program files\Common Files\SWF Studio
2008-12-29 14:31 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-24 04:59 ——— d—–w c:\program files\Norton AntiVirus
2008-12-23 03:55 ——— d—–w c:\program files\Google
2008-12-22 18:16 ——— d—–w c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-22 14:30 ——— d—–w c:\program files\Symantec
2008-12-22 14:29 ——— d—–w c:\program files\SymNetDrv
2008-12-22 12:39 ——— d—–w c:\documents and settings\NetworkService\Application Data\Symantec
2008-12-22 11:49 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2008-12-22 11:46 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-22 10:12 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-21 14:21 ——— d—–w c:\program files\Common Files\xing shared
2008-12-21 14:19 ——— d—–w c:\program files\Common Files\Real
2008-12-19 14:41 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-02 06:36 16,421 —-a-w c:\documents and settings\ramnath\Start Menu.zip
.

((((((((((((((((((((((((((((( snapshot@2009-01-05_17.02.46.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-06-30 13:39:06 175,968 —-a-w c:\windows\Downloaded Program Files\IEAWSDC.DLL
+ 2009-01-05 17:40:29 884,736 —-a-w c:\windows\gmer.dll
+ 2008-04-17 15:43:02 811,008 —-a-w c:\windows\gmer.exe
+ 2008-10-16 20:38:34 124,928 -c—-w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c—-w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c—-w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c—-w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c—-w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c—-w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c—-w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c—-w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c—-w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c—-w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c—-w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c—-w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c—-w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c—-w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c—-w c:\windows\ie7updates\KB961260-IE7\wininet.dll
+ 2008-04-14 00:10:34 175,104 —-a-w c:\windows\ime\chsime\applets\PINTLCSA.DLL
+ 2008-04-14 00:10:34 53,760 —-a-w c:\windows\ime\chsime\applets\PINTLCSD.DLL
+ 2008-04-14 00:09:05 97,792 —-a-w c:\windows\ime\CHTIME\Applets\CHTMBX.DLL
+ 2008-04-14 00:09:05 56,320 —-a-w c:\windows\ime\CHTIME\Applets\CHTSKDIC.DLL
+ 2008-04-14 00:09:05 173,568 —-a-w c:\windows\ime\CHTIME\Applets\CHTSKF.DLL
+ 2001-08-18 12:00:00 10,096,640 —-a-w c:\windows\ime\CHTIME\Applets\HWXCHT.DLL
+ 2008-04-14 00:09:39 13,463,552 —-a-w c:\windows\ime\imjp8_1\applets\hwxjpn.dll
+ 2001-08-18 12:00:00 471,102 —-a-w c:\windows\ime\imjp8_1\applets\imskdic.dll
+ 2008-04-14 00:09:47 315,455 —-a-w c:\windows\ime\imjp8_1\applets\imskf.dll
+ 2001-08-18 12:00:00 229,439 —-a-w c:\windows\ime\imjp8_1\applets\multibox.dll
+ 2001-08-18 12:00:00 143,422 —-a-w c:\windows\ime\imjp8_1\applets\softkey.dll
+ 2008-04-14 00:11:04 426,041 —-a-w c:\windows\ime\imjp8_1\applets\voicepad.dll
+ 2008-04-14 00:11:04 86,073 —-a-w c:\windows\ime\imjp8_1\applets\voicesub.dll
+ 2004-08-04 05:31:38 57,399 —-a-w c:\windows\ime\imjp8_1\cplexe.exe
+ 2008-04-14 00:09:45 368,696 —-a-w c:\windows\ime\imjp8_1\imjpcic.dll
+ 2008-04-14 00:09:45 716,856 —-a-w c:\windows\ime\imjp8_1\imjpcus.dll
+ 2001-08-18 12:00:00 57,398 —-a-w c:\windows\ime\imjp8_1\imjpdadm.exe
+ 2008-04-14 00:09:45 81,976 —-a-w c:\windows\ime\imjp8_1\imjpdct.dll
+ 2004-08-04 05:31:53 307,257 —-a-w c:\windows\ime\imjp8_1\imjpdct.exe
+ 2004-08-04 05:31:54 155,705 —-a-w c:\windows\ime\imjp8_1\imjpdsvr.exe
+ 2004-08-04 05:31:57 196,665 —-a-w c:\windows\ime\imjp8_1\imjpinst.exe
+ 2004-08-04 05:31:59 208,952 —-a-w c:\windows\ime\imjp8_1\imjpmig.exe
+ 2004-08-04 05:32:11 233,527 —-a-w c:\windows\ime\imjp8_1\imjprw.exe
+ 2001-08-18 12:00:00 45,109 —-a-w c:\windows\ime\imjp8_1\imjpuex.exe
+ 2004-08-04 05:32:14 262,200 —-a-w c:\windows\ime\imjp8_1\imjputy.exe
+ 2008-04-14 00:09:46 274,489 —-a-w c:\windows\ime\imjp8_1\imjputyc.dll
+ 2001-08-18 12:00:00 10,129,408 —-a-w c:\windows\ime\imkr6_1\applets\hwxkor.dll
+ 2008-04-14 00:09:43 86,016 —-a-w c:\windows\ime\imkr6_1\applets\imekrmbx.dll
+ 2001-08-18 12:00:00 36,864 —-a-w c:\windows\ime\imkr6_1\dicts\hanjadic.dll
+ 2008-04-14 00:09:43 106,496 —-a-w c:\windows\ime\imkr6_1\imekrcic.dll
+ 2001-08-18 12:00:00 44,032 —-a-w c:\windows\ime\imkr6_1\imekrmig.exe
+ 2001-08-18 12:00:00 59,904 —-a-w c:\windows\ime\imkr6_1\imkrinst.exe
+ 2001-08-18 12:00:00 102,463 —-a-w c:\windows\ime\shared\imepadsm.dll
+ 2001-08-18 12:00:00 311,359 —-a-w c:\windows\ime\shared\imepadsv.exe
+ 2008-04-14 00:09:46 102,456 —-a-w c:\windows\ime\shared\imlang.dll
+ 2008-04-14 00:10:33 15,872 —-a-w c:\windows\ime\shared\res\PADRS404.DLL
+ 2001-08-18 12:00:00 36,927 —-a-w c:\windows\ime\shared\res\padrs411.dll
+ 2001-08-18 12:00:00 14,336 —-a-w c:\windows\ime\shared\res\padrs412.dll
+ 2008-04-14 00:10:33 15,360 —-a-w c:\windows\ime\shared\res\padrs804.dll
+ 2009-01-20 04:45:39 29,926 —-a-r c:\windows\Installer\{508CE775-4BA4-4748-82DF-FE28DA9F03B0}\MsblIco.Exe
+ 2009-02-04 12:44:08 27,136 —-a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2009-01-19 10:51:27 295,606 —-a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
+ 2009-01-07 10:39:26 40,960 —-a-r c:\windows\Installer\{F83E1C1A-B039-4035-90B4-AE43D4EABB9A}\NewShortcut1.exe
+ 2009-01-07 10:39:26 40,960 —-a-r c:\windows\Installer\{F83E1C1A-B039-4035-90B4-AE43D4EABB9A}\NewShortcut2.EXE
+ 2009-01-07 10:39:26 45,056 —-a-r c:\windows\Installer\{F83E1C1A-B039-4035-90B4-AE43D4EABB9A}\NewShortcut3.exe
+ 1998-09-30 04:39:20 1,276,416 —-a-w c:\windows\lhsp\tv\tv_enua.dll
+ 1998-09-24 09:45:44 40,960 —-a-w c:\windows\lhsp\tv\tvenuax.dll
+ 2007-04-02 18:25:59 19,456 —-a-w c:\windows\msagent\intl\agt0404.dll
+ 2007-04-02 18:26:00 19,456 —-a-w c:\windows\msagent\intl\agt0411.dll
+ 2007-04-02 18:26:00 19,456 —-a-w c:\windows\msagent\intl\agt0412.dll
+ 2007-04-02 18:26:02 19,456 —-a-w c:\windows\msagent\intl\agt0804.dll
- 2000-08-31 02:30:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 02:30:00 29,696 —-a-w c:\windows\NIRCMD.exe
+ 2001-11-05 11:20:24 69,632 —-a-w c:\windows\PAC207\AmCap.exe
+ 2004-01-15 10:31:20 61,440 —-a-w c:\windows\PAC207\StillImg.exe
+ 1999-01-12 09:49:12 248,832 —-a-w c:\windows\speech\spchtel.dll
+ 1999-01-12 09:49:12 562,176 —-a-w c:\windows\speech\speech.dll
+ 1999-01-12 09:39:36 380,928 —-a-w c:\windows\speech\vcmd.exe
+ 1999-01-12 09:49:12 156,160 —-a-w c:\windows\speech\vcmshl.dll
+ 1999-01-12 09:49:12 179,712 —-a-w c:\windows\speech\Vdict.dll
+ 1999-01-12 09:49:12 173,056 —-a-w c:\windows\speech\VText.dll
+ 1999-01-12 06:05:30 53,760 —-a-w c:\windows\speech\WrapSAPI.dll
+ 1999-01-12 09:49:12 128,000 —-a-w c:\windows\speech\Xcommand.dll
+ 1999-01-12 09:49:12 208,896 —-a-w c:\windows\speech\Xlisten.dll
+ 1999-01-12 09:49:12 203,776 —-a-w c:\windows\speech\XTel.Dll
+ 1999-01-12 09:49:12 195,584 —-a-w c:\windows\speech\Xvoice.dll
- 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-04-14 00:11:50 218,112 —-a-w c:\windows\system32\c_g18030.dll
+ 2001-08-18 12:00:00 1,677,824 —-a-w c:\windows\system32\chsbrkr.dll
+ 2001-08-18 12:00:00 838,144 —-a-w c:\windows\system32\chtbrkr.dll
- 2008-10-16 20:38:34 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2007-04-02 18:25:59 19,456 —-a-w c:\windows\system32\dllcache\agt0404.dll
+ 2007-04-02 18:26:00 19,456 —-a-w c:\windows\system32\dllcache\agt0411.dll
+ 2007-04-02 18:26:00 19,456 —-a-w c:\windows\system32\dllcache\agt0412.dll
+ 2007-04-02 18:26:02 19,456 —-a-w c:\windows\system32\dllcache\agt0804.dll
+ 2008-04-14 00:11:50 218,112 —-a-w c:\windows\system32\dllcache\c_g18030.dll
+ 2001-08-18 12:00:00 1,677,824 —-a-w c:\windows\system32\dllcache\chsbrkr.dll
+ 2001-08-18 12:00:00 838,144 —-a-w c:\windows\system32\dllcache\chtbrkr.dll
+ 2008-04-14 00:09:05 97,792 —-a-w c:\windows\system32\dllcache\chtmbx.dll
+ 2008-04-14 00:09:05 56,320 —-a-w c:\windows\system32\dllcache\chtskdic.dll
+ 2008-04-14 00:09:05 173,568 —-a-w c:\windows\system32\dllcache\chtskf.dll
+ 2008-04-14 00:09:06 198,656 —-a-w c:\windows\system32\dllcache\cintime.dll
+ 2004-08-04 05:31:54 480,256 —-a-w c:\windows\system32\dllcache\cintsetp.exe
+ 2004-08-04 05:31:38 57,399 —-a-w c:\windows\system32\dllcache\cplexe.exe
+ 2008-06-20 17:46:57 147,968 ——w c:\windows\system32\dllcache\dnsapi.dll
- 2008-10-16 20:38:34 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-04-14 00:09:30 7,168 —-a-w c:\windows\system32\dllcache\f3ahvoas.dll
+ 2001-08-18 12:00:00 36,864 —-a-w c:\windows\system32\dllcache\hanjadic.dll
+ 2001-08-18 12:00:00 10,096,640 —-a-w c:\windows\system32\dllcache\hwxcht.dll
+ 2008-04-14 00:09:39 13,463,552 —-a-w c:\windows\system32\dllcache\hwxjpn.dll
- 2008-10-16 20:38:35 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 ——w c:\windows\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 ——w c:\windows\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-14 00:09:43 106,496 —-a-w c:\windows\system32\dllcache\imekrcic.dll
+ 2008-04-14 00:09:43 86,016 —-a-w c:\windows\system32\dllcache\imekrmbx.dll
+ 2001-08-18 12:00:00 44,032 —-a-w c:\windows\system32\dllcache\imekrmig.exe
+ 2001-08-18 12:00:00 102,463 —-a-w c:\windows\system32\dllcache\imepadsm.dll
+ 2001-08-18 12:00:00 311,359 —-a-w c:\windows\system32\dllcache\imepadsv.exe
+ 2008-04-14 00:09:44 811,064 —-a-w c:\windows\system32\dllcache\imjp81k.dll
+ 2008-04-14 00:09:45 368,696 —-a-w c:\windows\system32\dllcache\imjpcic.dll
+ 2008-04-14 00:09:45 716,856 —-a-w c:\windows\system32\dllcache\imjpcus.dll
+ 2008-04-14 00:09:45 81,976 —-a-w c:\windows\system32\dllcache\imjpdct.dll
+ 2004-08-04 05:31:53 307,257 —-a-w c:\windows\system32\dllcache\imjpdct.exe
+ 2004-08-04 05:31:54 155,705 —-a-w c:\windows\system32\dllcache\imjpdsvr.exe
+ 2004-08-04 05:31:57 196,665 —-a-w c:\windows\system32\dllcache\imjpinst.exe
+ 2004-08-04 05:31:59 208,952 —-a-w c:\windows\system32\dllcache\imjpmig.exe
+ 2004-08-04 05:32:11 233,527 —-a-w c:\windows\system32\dllcache\imjprw.exe
+ 2004-08-04 05:32:14 262,200 —-a-w c:\windows\system32\dllcache\imjputy.exe
+ 2008-04-14 00:09:46 274,489 —-a-w c:\windows\system32\dllcache\imjputyc.dll
+ 2001-08-18 12:00:00 59,904 —-a-w c:\windows\system32\dllcache\imkrinst.exe
+ 2008-04-14 00:09:46 102,456 —-a-w c:\windows\system32\dllcache\imlang.dll
+ 2004-08-04 05:31:48 59,392 —-a-w c:\windows\system32\dllcache\imscinst.exe
+ 2001-08-18 12:00:00 471,102 —-a-w c:\windows\system32\dllcache\imskdic.dll
+ 2008-04-14 00:09:47 315,455 —-a-w c:\windows\system32\dllcache\imskf.dll
+ 2008-04-14 00:11:56 47,616 —-a-w c:\windows\system32\dllcache\iyuv_32.dll
- 2008-10-16 20:38:37 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\dllcache\kbd101.dll
- 2001-08-17 22:55:56 6,144 —-a-w c:\windows\system32\dllcache\kbd101b.dll
+ 2001-08-17 09:25:56 6,144 —-a-w c:\windows\system32\dllcache\kbd101b.dll
- 2001-08-17 22:55:56 6,144 —-a-w c:\windows\system32\dllcache\kbd101c.dll
+ 2001-08-17 09:25:56 6,144 —-a-w c:\windows\system32\dllcache\kbd101c.dll
- 2001-08-17 22:55:56 5,632 —-a-w c:\windows\system32\dllcache\kbd103.dll
+ 2001-08-17 09:25:56 5,632 —-a-w c:\windows\system32\dllcache\kbd103.dll
+ 2008-04-14 00:09:56 6,144 —-a-w c:\windows\system32\dllcache\kbd106.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\dllcache\kbd106n.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\dllcache\kbdax2.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\windows\system32\dllcache\kbdibm02.dll
- 2001-08-18 06:36:18 8,704 —-a-w c:\windows\system32\dllcache\kbdjpn.dll
+ 2001-08-17 17:06:18 8,704 —-a-w c:\windows\system32\dllcache\kbdjpn.dll
- 2001-08-18 06:36:18 8,192 —-a-w c:\windows\system32\dllcache\kbdkor.dll
+ 2001-08-17 17:06:18 8,192 —-a-w c:\windows\system32\dllcache\kbdkor.dll
+ 2008-04-14 00:09:55 6,656 —-a-w c:\windows\system32\dllcache\kbdlk41a.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\dllcache\kbdlk41j.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\windows\system32\dllcache\kbdnec.dll
+ 2001-08-18 12:00:00 70,656 —-a-w c:\windows\system32\dllcache\korwbrkr.dll
+ 2008-04-13 19:16:36 141,056 —-a-w c:\windows\system32\dllcache\ks.sys
+ 2008-04-14 00:11:56 4,096 —-a-w c:\windows\system32\dllcache\ksuser.dll
- 2008-10-16 20:38:37 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-16 16:05:14 3,594,752 ——w c:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2001-08-18 12:00:00 98,304 —-a-w c:\windows\system32\dllcache\msir3jp.dll
- 2008-10-16 20:38:38 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 ——w c:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-06-20 17:46:57 245,248 ——w c:\windows\system32\dllcache\mswsock.dll
+ 2008-04-14 00:12:02 16,896 —-a-w c:\windows\system32\dllcache\msyuv.dll
+ 2001-08-18 12:00:00 229,439 —-a-w c:\windows\system32\dllcache\multibox.dll
- 2008-10-16 20:38:39 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 00:10:33 15,872 —-a-w c:\windows\system32\dllcache\padrs404.dll
+ 2001-08-18 12:00:00 36,927 —-a-w c:\windows\system32\dllcache\padrs411.dll
+ 2001-08-18 12:00:00 14,336 —-a-w c:\windows\system32\dllcache\padrs412.dll
+ 2008-04-14 00:10:33 15,360 —-a-w c:\windows\system32\dllcache\padrs804.dll
+ 2008-04-14 00:10:34 175,104 —-a-w c:\windows\system32\dllcache\pintlcsa.dll
+ 2008-04-14 00:10:34 53,760 —-a-w c:\windows\system32\dllcache\pintlcsd.dll
+ 2008-04-13 16:43:36 70,144 —-a-w c:\windows\system32\dllcache\pintlphr.exe
+ 2008-04-14 00:10:34 67,584 —-a-w c:\windows\system32\dllcache\pmigrate.dll
- 2008-10-16 20:38:39 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2001-08-18 12:00:00 143,422 —-a-w c:\windows\system32\dllcache\softkey.dll
- 2008-09-08 10:41:42 333,824 ——w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 ——w c:\windows\system32\dllcache\srv.sys
+ 2008-06-20 11:51:12 361,600 ——w c:\windows\system32\dllcache\tcpip.sys
+ 2008-06-20 11:08:27 225,856 ——w c:\windows\system32\dllcache\tcpip6.sys
+ 2004-08-04 05:32:15 44,032 —-a-w c:\windows\system32\dllcache\tintlphr.exe
+ 2004-08-04 05:32:15 455,168 —-a-w c:\windows\system32\dllcache\tintsetp.exe
+ 2008-04-14 00:10:59 10,240 —-a-w c:\windows\system32\dllcache\tmigrate.dll
- 2001-08-18 06:36:34 8,192 —-a-w c:\windows\system32\dllcache\tsbyuv.dll
+ 2001-08-17 17:06:34 8,192 —-a-w c:\windows\system32\dllcache\tsbyuv.dll
+ 2008-04-14 00:11:01 76,288 —-a-w c:\windows\system32\dllcache\uniime.dll
- 2008-10-16 20:38:39 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 ——w c:\windows\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 00:12:08 53,760 —-a-w c:\windows\system32\dllcache\vfwwdm32.dll
+ 2008-04-14 00:11:04 426,041 —-a-w c:\windows\system32\dllcache\voicepad.dll
+ 2008-04-14 00:11:04 86,073 —-a-w c:\windows\system32\dllcache\voicesub.dll
- 2008-10-16 20:38:39 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:38:40 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 ——w c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 00:11:52 147,968 —-a-w c:\windows\system32\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 —-a-w c:\windows\system32\dnsapi.dll
+ 2009-01-05 17:40:30 85,969 —-a-w c:\windows\system32\drivers\gmer.sys
+ 2003-09-16 01:05:08 108,092 —-a-r c:\windows\system32\drivers\pfc027.sys
- 2008-09-08 10:41:42 333,824 —-a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 10:57:09 333,952 —-a-w c:\windows\system32\drivers\srv.sys
- 2008-04-13 19:20:16 361,344 —-a-w c:\windows\system32\drivers\tcpip.sys
+ 2008-06-20 11:51:12 361,600 —-a-w c:\windows\system32\drivers\tcpip.sys
- 2008-04-13 19:00:02 225,664 —-a-w c:\windows\system32\drivers\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 —-a-w c:\windows\system32\drivers\tcpip6.sys
- 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-04-14 00:09:30 7,168 —-a-w c:\windows\system32\f3ahvoas.dll
- 2008-12-23 07:39:05 175,464 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-02-11 05:55:55 187,408 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w c:\windows\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-04-14 00:09:06 198,656 —-a-w c:\windows\system32\IME\CINTLGNT\CINTIME.DLL
+ 2004-08-04 05:31:54 480,256 —-a-w c:\windows\system32\IME\CINTLGNT\CINTSETP.EXE
+ 2004-08-04 05:31:48 59,392 —-a-w c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
+ 2008-04-13 16:43:36 70,144 —-a-w c:\windows\system32\IME\PINTLGNT\PINTLPHR.EXE
+ 2008-04-14 00:10:34 67,584 —-a-w c:\windows\system32\IME\PINTLGNT\PMIGRATE.DLL
+ 2004-08-04 05:32:15 44,032 —-a-w c:\windows\system32\IME\TINTLGNT\TINTLPHR.EXE
+ 2004-08-04 05:32:15 455,168 —-a-w c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
+ 2008-04-14 00:10:59 10,240 —-a-w c:\windows\system32\IME\TINTLGNT\TMIGRATE.DLL
+ 2008-04-14 00:09:44 811,064 —-a-w c:\windows\system32\imjp81k.dll
- 2008-04-14 00:11:55 47,616 —-a-w c:\windows\system32\iyuv_32.dll
+ 2008-04-14 00:11:56 47,616 —-a-w c:\windows\system32\iyuv_32.dll
- 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\kbd101.dll
+ 2001-08-18 12:00:00 6,144 —-a-w c:\windows\system32\kbd101a.dll
- 2001-08-17 22:55:56 6,144 —-a-w c:\windows\system32\kbd101b.dll
+ 2001-08-17 09:25:56 6,144 —-a-w c:\windows\system32\kbd101b.dll
- 2001-08-17 22:55:56 6,144 —-a-w c:\windows\system32\kbd101c.dll
+ 2001-08-17 09:25:56 6,144 —-a-w c:\windows\system32\kbd101c.dll
- 2001-08-17 22:55:56 5,632 —-a-w c:\windows\system32\kbd103.dll
+ 2001-08-17 09:25:56 5,632 —-a-w c:\windows\system32\kbd103.dll
- 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\kbd106.dll
+ 2008-04-14 00:09:56 6,144 —-a-w c:\windows\system32\kbd106.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\kbd106n.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\kbdax2.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\windows\system32\kbdibm02.dll
- 2001-08-18 06:36:18 8,704 —-a-w c:\windows\system32\kbdjpn.dll
+ 2001-08-17 17:06:18 8,704 —-a-w c:\windows\system32\kbdjpn.dll
- 2001-08-18 06:36:18 8,192 —-a-w c:\windows\system32\kbdkor.dll
+ 2001-08-17 17:06:18 8,192 —-a-w c:\windows\system32\kbdkor.dll
+ 2008-04-14 00:09:55 6,656 —-a-w c:\windows\system32\kbdlk41a.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\windows\system32\kbdlk41j.dll
+ 2001-08-18 12:00:00 7,168 —-a-w c:\windows\system32\kbdnec95.dll
+ 2001-08-18 12:00:00 9,216 —-a-w c:\windows\system32\kbdnecAT.dll
+ 2001-08-18 12:00:00 7,680 —-a-w c:\windows\system32\kbdnecNT.dll
+ 2001-08-18 12:00:00 70,656 —-a-w c:\windows\system32\korwbrkr.dll
- 2008-12-09 09:54:38 17,593,280 —-a-w c:\windows\system32\MRT.exe
+ 2009-02-03 23:21:12 21,244,864 —-a-w c:\windows\system32\MRT.exe
- 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-04-14 00:12:45 294,912 —-a-w c:\windows\system32\msh263.drv
+ 2008-04-14 00:12:46 294,912 —-a-w c:\windows\system32\msh263.drv
- 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2009-01-16 16:05:14 3,594,752 —-a-w c:\windows\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
+ 2001-08-18 12:00:00 98,304 —-a-w c:\windows\system32\msir3jp.dll
- 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-04-14 00:12:01 245,248 —-a-w c:\windows\system32\mswsock.dll
+ 2008-06-20 17:46:57 245,248 —-a-w c:\windows\system32\mswsock.dll
- 2008-04-14 00:12:01 16,896 —-a-w c:\windows\system32\msyuv.dll
+ 2008-04-14 00:12:02 16,896 —-a-w c:\windows\system32\msyuv.dll
- 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\occache.dll
+ 2004-01-08 05:00:22 11,170 —-a-w c:\windows\system32\PA207Usd.dll
- 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2006-01-24 19:34:24 118,784 —-a-w c:\windows\system32\sirenacm.dll
+ 2007-10-18 06:01:46 51,224 —-a-w c:\windows\system32\sirenacm.dll
- 2007-07-27 05:11:40 16,760 ——w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w c:\windows\system32\spmsg.dll
+ 2009-01-19 14:17:37 135,248 —-a-w c:\windows\system32\spool\drivers\w32x86\3\pdf995ps5ui.dll
+ 2009-01-19 14:17:37 15,872 —-a-w c:\windows\system32\spool\drivers\w32x86\3\pdf995ui5.DLL
+ 2009-01-19 14:17:36 470,608 —-a-w c:\windows\system32\spool\drivers\w32x86\3\pscript5-32.dll
+ 2009-01-19 14:17:37 135,248 —-a-w c:\windows\system32\spool\drivers\w32x86\pdf995ps5ui.dll
+ 2009-01-19 14:17:33 218,816 —-a-w c:\windows\system32\spool\drivers\w32x86\Pdf995ui.dll
+ 2009-01-19 14:17:37 15,872 —-a-w c:\windows\system32\spool\drivers\w32x86\pdf995ui5.DLL
+ 2009-01-19 14:17:33 225,648 —-a-w c:\windows\system32\spool\drivers\w32x86\Pscript.dll
+ 2009-01-19 14:17:36 470,608 —-a-w c:\windows\system32\spool\drivers\w32x86\pscript5-32.dll
- 2001-08-18 06:36:34 8,192 —-a-w c:\windows\system32\tsbyuv.dll
+ 2001-08-17 17:06:34 8,192 —-a-w c:\windows\system32\tsbyuv.dll
+ 2008-04-14 00:11:01 76,288 —-a-w c:\windows\system32\uniime.dll
- 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\urlmon.dll
+ 2003-09-16 01:05:08 57,344 —-a-r c:\windows\system32\VFWUI.dll
- 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w c:\windows\system32\wininet.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC6CEA02-6835-4C1A-9887-77B380A84881}]
2008-11-13 11:02 116480 –a—— c:\windows\System32\ccfgn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-09 68856]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2008-10-24 1336560]
"Google Update"="c:\documents and settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-13 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2002-03-01 69632]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-03-14 102455]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"PaperPort PTD"="c:\program files\Scansoft\PaperPort\pptd40nt.exe" [2002-06-11 45108]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-06-11 36864]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-02 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 58728]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2008-12-22 100056]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SoftickPPP"="c:\program files\Softick\PPP\Bin\PPPGate.exe" [2004-10-21 160256]
"AGRSMMSG"="AGRSMMSG.exe" [2002-02-23 c:\windows\AGRSMMSG.exe]
"TrackPointSrv"="tp4serv.exe" [2002-03-20 c:\windows\system32\tp4serv.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-04-17 c:\windows\system32\Ati2mdxx.exe]
"TP4EX"="tp4ex.exe" [2002-02-22 c:\windows\system32\TP4EX.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2008-08-01 152952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\ramnath\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\ramnath\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dorgem\\Dorgem.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 hllfetcr;hllfetcr;c:\windows\system32\drivers\hllfetcr.sys [1980-01-01 23424]
R1 DSMBATT;DSMBATT;c:\windows\system32\drivers\DSMBATT.SYS [2002-08-22 9888]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2002-08-22 2295]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2002-08-22 12288]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [1980-01-01 14175]
S3 AmeAtmPc;AmeAtmPc;c:\windows\system32\DRIVERS\AmeAtmPc.sys –> c:\windows\system32\DRIVERS\AmeAtmPc.sys [?]
S3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [1980-01-01 55808]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [1980-01-01 55808]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2003-09-11 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\drivers\BrParImg.sys [2003-09-11 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\drivers\BrParwdm.sys [2003-09-11 39552]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2003-09-11 60416]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys –> c:\windows\system32\DRIVERS\CnxEtP.sys [?]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys –> c:\windows\system32\DRIVERS\CnxEtU.sys [?]
S3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNP.sys –> c:\windows\system32\DRIVERS\CnxTgNP.sys [?]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNW.sys –> c:\windows\system32\DRIVERS\CnxTgNW.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-02-11 38496]
S3 ORITE;Mini-cam(SC120);c:\windows\system32\drivers\pfc027.sys [2009-01-09 108092]
S3 PCDRDRV;Pcdr CPU Helper Driver;c:\windows\system32\drivers\PCDRDRV.sys –> c:\windows\system32\drivers\PCDRDRV.sys [?]

— Other Services/Drivers In Memory —

*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - Automatic LiveUpdate Scheduler
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fax
*Deregistered* - helpsvc
*Deregistered* - IBMPMSVC
*Deregistered* - Irmon
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LiveUpdate
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NPFMntor
*Deregistered* - NWCWorkstation
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - QCONSVC
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SBService
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SNDSrvc
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - SymWSC
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-12 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\Bmmtask.exe [2002-03-26 13:54]

2009-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266486392-572454927-963639892-1004.job
- c:\documents and settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 11:30]

2009-02-06 c:\windows\Tasks\Norton AntiVirus - Scan my computer - ramnath.job
- c:\progra~1\NORTON~1\Navw32.exe [2005-10-19 12:54]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-emoze - c:\progra~1\Emoze\emoze.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 11:59:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\windows\system32\ati2evxx.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\fxssvc.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2009-02-12 12:07:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-12 06:37:01
ComboFix2.txt 2009-01-05 11:35:44

Pre-Run: 7,585,909,248 bytes free
Post-Run: 7,567,770,112 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
639 — E O F — 2009-02-11 06:26:08


—————————————————————————————————————————————————————————
—————————————————————————————————————————————————————————






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:12 PM, on 2/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: (no name) - {FC6CEA02-6835-4C1A-9887-77B380A84881} - C:\WINDOWS\System32\ccfgn.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 9422 bytes
I believe there's a driver/service protecting the removal of the file. Let's see if we can get it. This may be much worse than just this though. We'll do some more scans to see after. Appears you have been dealing with this for some time now so. This you over here I assume?

http://www.techsupportforum.com/security-c…-ccfgn-dll.html

1. Open Notepad

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\System32\ccfgn.dll
c:\windows\system32\drivers\hllfetcr.sys

Driver::
hllfetcr 

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC6CEA02-6835-4C1A-9887-77B380A84881}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Looks like you have done it ! Thank you so much. I didnt get any alert from norton on opening IE

yes, thats me in techsupport forum, a member there who is in WTT now refered me to this forum.
had this virus since end december.

combofix & hijackthis log below, please let me know if there is anything more i should do, also
advice if norton alone is enough or do i need to install some other program for protection.

Thankyou.
Vetri.

ComboFix 09-02-12.03 - ramnath 2009-02-13 12:53:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.306 [GMT 5.5:30]
Running from: c:\vv\wtt2\ComboFix.exe
Command switches used :: c:\documents and settings\ramnath\Desktop\CFScript.txt
AV: Norton AntiVirus 2005 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *enabled*
* Created a new restore point

FILE ::
c:\windows\System32\ccfgn.dll
c:\windows\system32\drivers\hllfetcr.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\System32\ccfgn.dll
c:\windows\system32\drivers\hllfetcr.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_HLLFETCR
——-\Service_hllfetcr


((((((((((((((((((((((((( Files Created from 2009-01-13 to 2009-02-13 )))))))))))))))))))))))))))))))
.

2009-02-13 12:13 . 2009-02-13 12:12 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-12 12:33 . 2009-02-12 12:33 d——– c:\program files\Trend Micro
2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\documents and settings\ramnath\Application Data\Malwarebytes
2009-02-11 14:17 . 2009-02-11 14:17 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-11 14:17 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 14:17 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-06 14:49 . 2009-02-08 11:36 d——– c:\program files\Emoze
2009-02-06 14:49 . 2009-02-06 14:53 d——– c:\documents and settings\ramnath\Application Data\emoze
2009-02-04 18:27 . 2009-02-04 18:27 d——– c:\documents and settings\ramnath\Application Data\Apple Computer
2009-02-04 18:16 . 2009-02-04 18:17 d——– c:\program files\QuickTime
2009-02-04 18:15 . 2009-02-04 18:15 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-04 18:13 . 2009-02-04 18:13 d——– c:\program files\Apple Software Update
2009-02-04 18:13 . 2009-02-04 18:13 d——– c:\documents and settings\All Users\Application Data\Apple
2009-02-04 14:07 . 2009-02-04 14:07 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-04 14:07 . 2009-02-04 14:07 1,409 –a—— c:\windows\QTFont.for
2009-01-25 18:47 . 2009-01-25 18:47 d——– c:\documents and settings\LocalService\Application Data\Symantec
2009-01-23 13:14 . 2009-01-23 13:14 d——– c:\windows\lhsp
2009-01-23 13:13 . 2009-01-23 13:13 d——– c:\windows\speech
2009-01-20 10:19 . 2009-01-20 10:19 d——– c:\documents and settings\ramnath\Contacts
2009-01-20 10:17 . 2009-01-20 10:17 d—-c— c:\windows\system32\DRVSTORE
2009-01-20 10:14 . 2009-01-20 10:14 d–hsc— c:\program files\Common Files\WindowsLiveInstaller
2009-01-20 10:13 . 2009-01-20 10:16 d——– c:\program files\Windows Live
2009-01-20 10:13 . 2009-01-20 10:13 d——– c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-19 19:57 . 2009-01-19 19:57 d——– c:\documents and settings\ramnath\Application Data\pdf995
2009-01-19 19:57 . 2009-01-19 19:57 28 –a—— c:\windows\pdf995.ini
2009-01-19 19:55 . 2009-01-19 19:55 5,391,760 –a—— C:\ps2pdf995.exe
2009-01-19 19:47 . 2009-01-19 19:55 d——– c:\program files\pdf995
2009-01-19 19:47 . 2009-01-30 13:35 d——– c:\documents and settings\All Users\Application Data\pdf995
2009-01-19 19:47 . 2009-01-19 19:47 249,856 –a—— c:\windows\system32\pdfmona.dll
2009-01-19 19:47 . 2009-01-19 19:47 51,716 –a—— c:\windows\system32\pdf995mon.dll
2009-01-19 19:47 . 2009-01-30 13:35 59 –a—— c:\windows\wpd99.drv
2009-01-19 15:56 . 2008-09-25 18:50 483,328 –a—— c:\windows\system32\actskn45.ocx
2009-01-19 15:54 . 2009-01-19 15:54 9,833,120 –a—— C:\iMeshV8.exe
2009-01-17 18:36 . 2009-01-17 18:36 d——– c:\program files\Softick
2009-01-13 16:32 . 2001-08-18 17:30 10,129,408 –a—— c:\windows\system32\dllcache\hwxkor.dll
2009-01-13 16:31 . 2001-08-18 17:30 57,398 –a—— c:\windows\system32\dllcache\imjpdadm.exe
2009-01-13 16:31 . 2001-08-18 17:30 45,109 –a—— c:\windows\system32\dllcache\imjpuex.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 06:41 ——— d—–w c:\program files\Java
2009-02-07 10:11 ——— d—–w c:\documents and settings\ramnath\Application Data\Murasu
2009-02-04 09:13 ——— d—–w c:\documents and settings\ramnath\Application Data\LimeWire
2009-01-31 10:44 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-30 08:51 ——— d—–w c:\program files\LimeWire
2009-01-30 07:52 ——— d—–w c:\documents and settings\ramnath\Application Data\Image Zone Express
2009-01-22 06:47 ——— d—–w c:\program files\ThreatExpert Memory Scanner
2009-01-09 09:40 ——— d—–w c:\program files\ORITE
2009-01-09 09:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-07 10:38 ——— d—–w c:\program files\Common Files\InstallShield
2009-01-07 10:31 ——— d—–w c:\program files\Dorgem
2009-01-05 08:33 ——— d—–w c:\documents and settings\ramnath\Application Data\RecordNow
2009-01-05 07:13 ——— d—–w c:\program files\Common Files\Adobe
2009-01-04 08:20 ——— d—–w c:\program files\Common Files\SWF Studio
2008-12-29 14:31 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-24 04:59 ——— d—–w c:\program files\Norton AntiVirus
2008-12-23 03:55 ——— d—–w c:\program files\Google
2008-12-22 18:16 ——— d—–w c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-22 14:30 ——— d—–w c:\program files\Symantec
2008-12-22 14:29 ——— d—–w c:\program files\SymNetDrv
2008-12-22 12:39 ——— d—–w c:\documents and settings\NetworkService\Application Data\Symantec
2008-12-22 11:49 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2008-12-22 11:46 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-22 10:12 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-21 14:21 ——— d—–w c:\program files\Common Files\xing shared
2008-12-21 14:19 ——— d—–w c:\program files\Common Files\Real
2008-12-19 14:41 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-02 06:36 16,421 —-a-w c:\documents and settings\ramnath\Start Menu.zip
.

((((((((((((((((((((((((((((( SnapShot_2009-02-12_12.04.22.58 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-09 19:51:01 135,168 —-a-w c:\windows\system32\java.exe
+ 2009-02-13 06:42:16 144,792 —-a-w c:\windows\system32\java.exe
- 2008-06-09 19:51:04 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2009-02-13 06:42:16 144,792 —-a-w c:\windows\system32\javaw.exe
- 2008-06-09 21:02:34 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2009-02-13 06:42:16 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2009-02-13 07:32:27 16,384 —-atw c:\windows\temp\Perflib_Perfdata_594.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-09 68856]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2008-10-24 1336560]
"Google Update"="c:\documents and settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-13 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2002-03-01 69632]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-03-14 102455]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"PaperPort PTD"="c:\program files\Scansoft\PaperPort\pptd40nt.exe" [2002-06-11 45108]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-06-11 36864]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-02 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-13 136600]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 58728]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2008-12-22 100056]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SoftickPPP"="c:\program files\Softick\PPP\Bin\PPPGate.exe" [2004-10-21 160256]
"AGRSMMSG"="AGRSMMSG.exe" [2002-02-23 c:\windows\AGRSMMSG.exe]
"TrackPointSrv"="tp4serv.exe" [2002-03-20 c:\windows\system32\tp4serv.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-04-17 c:\windows\system32\Ati2mdxx.exe]
"TP4EX"="tp4ex.exe" [2002-02-22 c:\windows\system32\TP4EX.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2008-08-01 152952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\ramnath\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\ramnath\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dorgem\\Dorgem.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 DSMBATT;DSMBATT;c:\windows\system32\drivers\DSMBATT.SYS [2002-08-22 9888]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2002-08-22 2295]
S3 AmeAtmPc;AmeAtmPc;c:\windows\system32\DRIVERS\AmeAtmPc.sys –> c:\windows\system32\DRIVERS\AmeAtmPc.sys [?]
S3 AtmElan;ATM Emulated LAN;c:\windows\system32\drivers\atmlane.sys [1980-01-01 55808]
S3 AtmLane;ATM LAN Emulation;c:\windows\system32\drivers\atmlane.sys [1980-01-01 55808]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2003-09-11 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\drivers\BrParImg.sys [2003-09-11 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\drivers\BrParwdm.sys [2003-09-11 39552]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2003-09-11 60416]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys –> c:\windows\system32\DRIVERS\CnxEtP.sys [?]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys –> c:\windows\system32\DRIVERS\CnxEtU.sys [?]
S3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNP.sys –> c:\windows\system32\DRIVERS\CnxTgNP.sys [?]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNW.sys –> c:\windows\system32\DRIVERS\CnxTgNW.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-02-11 38496]
S3 ORITE;Mini-cam(SC120);c:\windows\system32\drivers\pfc027.sys [2009-01-09 108092]
S3 PCDRDRV;Pcdr CPU Helper Driver;c:\windows\system32\drivers\PCDRDRV.sys –> c:\windows\system32\drivers\PCDRDRV.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - HLLFETCR
*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - Automatic LiveUpdate Scheduler
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fax
*Deregistered* - helpsvc
*Deregistered* - IBMPMSVC
*Deregistered* - Irmon
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LiveUpdate
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NPFMntor
*Deregistered* - NWCWorkstation
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - QCONSVC
*Deregistered* - RasMan
*Deregistered* - Raspti
*Deregistered* - Rawwan
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SAVRTPEL
*Deregistered* - SBService
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Smapint
*Deregistered* - SNDSrvc
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssrtln
*Deregistered* - StarOpen
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - SymWSC
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TDSMAPI
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - tfsnboio
*Deregistered* - tfsncofs
*Deregistered* - tfsndrct
*Deregistered* - tfsndres
*Deregistered* - tfsnifs
*Deregistered* - tfsnopio
*Deregistered* - tfsnpool
*Deregistered* - tfsnudf
*Deregistered* - tfsnudfa
*Deregistered* - Themes
*Deregistered* - TPHKDRV
*Deregistered* - TPPWR
*Deregistered* - TrkWks
*Deregistered* - TSMAPIP
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WS2IFSL
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-13 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\Bmmtask.exe [2002-03-26 13:54]

2009-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266486392-572454927-963639892-1004.job
- c:\documents and settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 11:30]

2009-02-06 c:\windows\Tasks\Norton AntiVirus - Scan my computer - ramnath.job
- c:\progra~1\NORTON~1\Navw32.exe [2005-10-19 12:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-13 13:03:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\windows\system32\ati2evxx.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\fxssvc.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2009-02-13 13:11:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-13 07:41:07
ComboFix2.txt 2009-02-12 06:37:12
ComboFix3.txt 2009-01-05 11:35:44

Pre-Run: 7,417,714,688 bytes free
Post-Run: 7,412,767,744 bytes free

321 — E O F — 2009-02-11 06:26:08


———————————————————————————————————————————————————————–










Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:13:34 PM, on 2/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Softick\PPP\Bin\PPPGate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 9070 bytes
Yes, looks better. I still have some concerns about things here so we'll do some scans. Let's do this one first.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
Please post the report back here and let me know how it's running now.
downloaded and ran cureit, infections were found and moved/deleted. Have given below report from cureit Vetrivendan. 606208_5cb1a3a8f_\_tv14A5.tmp;C:\IBMTOOLS\APPS\ACCSUPT\ASPT121.EXE/vault\sd\sdcmon.dll\606208_5cb1a3a8f_;Probably DLOADER.Trojan;; \vault\sd\sdcmon.dll\606208_5cb1a3a8f_;C:\IBMTOOLS\APPS\ACCSUPT\ASPT121.EXE/vault\sd\sdcmon.dll;Archive contains infected objects;; 802816_5b998ece5_\_tv155B.tmp;C:\IBMTOOLS\APPS\ACCSUPT\ASPT121.EXE/vault\tg\tgupdate.exe\802816_5b998ece5_;Probably DLOADER.Trojan;; \vault\tg\tgupdate.exe\802816_5b998ece5_;C:\IBMTOOLS\APPS\ACCSUPT\ASPT121.EXE/vault\tg\tgupdate.exe;Archive contains infected objects;; ASPT121.EXE;C:\IBMTOOLS\APPS\ACCSUPT;Archive contains infected objects;Moved.; 37B64DF0.exe;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.PWS.GoldSpy.2573;Deleted.; redifftoolbar.dll;C:\Program Files\Rediff Toolbar\tbu133;Adware.Softomate.origin;Incurable.Deleted.; WhiteList.dll;C:\Program Files\Rediff Toolbar\tbu133;Adware.SideSearch;Incurable.Deleted.; A0003851.exe;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP13;Trojan.PWS.GoldSpy.2573;Deleted.; A0021817.bat;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP30;Probably BATCH.Virus;Incurable.Deleted.; A0021898.bat;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP31;Probably BATCH.Virus;Incurable.Deleted.; A0021910.EXE;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP31;Program.PsExec.170;Incurable.Deleted.; A0021987.bat;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP32;Probably BATCH.Virus;Incurable.Deleted.; A0022071.bat;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33;Probably BATCH.Virus;Incurable.Deleted.; A0022088.EXE;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33;Program.PsExec.170;Incurable.Deleted.; 606208_5cb1a3a8f_\_tv14A5.tmp;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33\A0022157.EXE/vault\sd\sdcmon.dll\606208_5cb1a3;Probably DLOADER.Trojan;; \vault\sd\sdcmon.dll\606208_5cb1a3a8f_;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33\A0022157.EXE/vault\sd\sdcmon.dll;Archive contains infected objects;; 802816_5b998ece5_\_tv155B.tmp;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33\A0022157.EXE/vault\tg\tgupdate.exe\802816_5b99;Probably DLOADER.Trojan;; \vault\tg\tgupdate.exe\802816_5b998ece5_;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33\A0022157.EXE/vault\tg\tgupdate.exe;Archive contains infected objects;; A0022157.EXE;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33;Archive contains infected objects;Moved.; A0022158.exe;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP33;Trojan.PWS.GoldSpy.2573;Deleted.; A0000325.EXE;C:\System Volume Information\_restore{4BFFCAFF-0890-43C1-85B1-F73EF796C415}\RP4;Program.PsExec.170;Incurable.Deleted.; c4f6b.msi\stream003;C:\WINDOWS\Installer\c4f6b.msi;Trojan.PWS.Wsgame.origin;; c4f6b.msi;C:\WINDOWS\Installer;Archive contains infected objects;Moved.;
Hi,

Okay no virut showing, which is good. Let's do some more work though. I would like you to run MBAM again, and I know you have it so just ignore the download part of my instructions.

First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run
Hi,
Sorry for the delayed response, was travelling and couldnt access.
Have scanned and provided below logs you had asked for.
please advise.
Vetri.

—————————————————————————————————————————————-
Malwarebytes' Anti-Malware 1.33
Database version: 1747
Windows 5.1.2600 Service Pack 3

2/17/2009 10:31:06 AM
mbam-log-2009-02-17 (10-31-06).txt

Scan type: Quick Scan
Objects scanned: 54422
Time elapsed: 10 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






————————————————————————————————————————————————

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 17, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, February 17, 2009 04:17:41
Records in database: 1806620
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 48362
Threat name: 5
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 03:15:20


File name / Threat name / Threats count
C:\Program Files\Norton AntiVirus\Quarantine\12571460.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Program Files\Norton AntiVirus\Quarantine\15CC0692.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Program Files\Norton AntiVirus\Quarantine\2B637DB3.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Program Files\Norton AntiVirus\Quarantine\701A0014.avi Infected: Trojan-Downloader.WMA.GetCodec.b 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_hllfetcr_.sys.zip Infected: Trojan.Win32.BHO.ext 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_ccfgn_.dll.zip Infected: Trojan.Win32.BHO.ibx 1
C:\WINDOWS\system32\dialersetup\WetGirls_in-uninstall.exe Infected: not-a-virus:Dialer.Win32.Small.gen 1

The selected area was scanned.




——————————————————————————————————————————————


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:17:33 PM, on 2/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Murasu Systems\Anjal2000\anjal.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 9456 bytes
Looks pretty clean. How's it running? One folder I want to take a look at.

Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the textfield labeled "Directory:":

    C:\WINDOWS\system32\dialersetup
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)

Note: Scanning may take longer for large folders.
Hi,
Computer is running good, no virus alerts from norton. Thanks to you.
DirLook log details pasted below.

DirLook.exe v2.0 by jpshortstuff
Log created at 09:13 on 18/02/2009
==================================
Contents of "C:\WINDOWS\system32\dialersetup"

—FOLDERS—

(none found)

—FILES—

WetGirls_in-uninstall.exe (105472 bytes - created on 04/10/2003 at 04:30, modified on 04/10/2003 at 04:30) –a—

==================================
=EOF=
Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\WINDOWS\system32\dialersetup
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Post hopefully one last fresh HJT log and let me know how it's running.
Hi,
System is running well and no alerts / popup
pasted logs below for your reference
vetri.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\system32\dialersetup moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\slu455.tmp\VIRSCAN7.DAT scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_124.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\T30DebugLogFile.txt scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02192009_160138

Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\slu455.tmp\VIRSCAN7.DAT moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_124.dat not found!
C:\WINDOWS\temp\T30DebugLogFile.txt moved successfully.



================================================================================


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:10:30 PM, on 2/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ramnath\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 9278 bytes
I think we're all set here. Just some cleanup and a little advice.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]

Next,
  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt3.exe to run it.
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

Remove the following if still present:

DrWebCureIt
DirLook

You can keep ATFCleaner and MalwareBytes' if you like. They are both good for occasional clean up and scans.

In addition to updating and using what you currently have you may want to consider the following:

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Hi Dave, Clean-up done and as advised all programme's you had mentioned installed and updated. Thankyou again for helping me out of this problem, had been suffering since end december. Now my system is clean and completely protected. Regards, Vetrivendan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI