Malware Removal & HijackThis Logs |
| |

| | Thread Tools |
|
28-Jun-2008, 11:03 AM
#1 |
| Solved: Newbie needing help with SYS32 Error Initially, I just want to say my limited knowledge has had me trying to fix this for days and any help would be greatly appricated. OK here goes......... For a week now, everytime i boot up my PC, i get an error message C/WINDOWS/SYSTEM/32/bynvkkmp.dll At the same time I couldnt seem to log into LIVE MESSENGER..... I was told to use some registry software cleaning programs to clean up my directory. I've tried CCleaner, Advanced Registry fix and finally Regcure. Ive run several date clean up and optimizes and to be honest, its made my systen run a little better. In Regcure, there is a management section. I saw the error in there and disabled the section that showed the above error. I then closed tried to reboot messenger up again and SOMETIMES it worked so im guessing these are connected some how? Also but not always, when i try to open a file mainly a photo file but someimes an AVI file, i get the following message Settings for Personalizsed settings for C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe Can someone please assist me in this matter? Thank you (I tried to attach some images ive saved but i have no idea how to reduce the size of a BMF file? I can email images if required?) Dutch! |
|
01-Jul-2008, 01:37 PM
#3 |
| Hjt Log Please Help Sorry me and PC's seemt ohave this love hate thing going and i totally forgot to attach my log. Could someone out these please help me? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:32:32, on 01/07/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\oodtray.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Nikon\PictureProject\NkbMonitor.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\BitTorrent\bittorrent.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {4BC97E6D-0783-4206-8701-907AA87758F3} - (no file) O2 - BHO: {881f1dff-e8c9-713a-9504-112e1b2106c4} - {4c6012b1-e211-4059-a317-9c8effd1f188} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" O4 - HKLM\..\Run: [BM7540f224] Rundll32.exe "C:\WINDOWS\system32\bynvkkmp.dll",s O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220" O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [MCCInstall] C:\WINDOWS\Motive\blueyonder\MCCUninst.exe -Uninstall O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1201882736484 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: fccdaaBq - fccdaaBq.dll (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 8129 bytes |
|
04-Jul-2008, 10:41 AM
#4 |
| Hi Welcome to TSG!! Please visit this webpage for instructions for downloading and running ComboFix. Post the log from ComboFix when you've accomplished that, along with a new HijackThis log. |
|
06-Jul-2008, 11:11 AM
#5 |
| Combifix and HJT Log's Initially i just to say thanks for helping ran combi fix and when it booted up the sys 32 error message popped up but MSN booted for the 1st time in weeks ! hopefully it's cured this for good! here goes ComboFix 08-07-05.1 - Ian 2008-07-06 15:56:46.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1451 [GMT 1:00] Running from: C:\Documents and Settings\Ian\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Ian\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\fylyayyu.dll C:\WINDOWS\system32\gjhnlnmj.ini C:\WINDOWS\system32\KllUCcdd.ini C:\WINDOWS\system32\KllUCcdd.ini2 C:\WINDOWS\system32\uyyaylyf.ini . ((((((((((((((((((((((((( Files Created from 2008-06-06 to 2008-07-06 ))))))))))))))))))))))))))))))) . 2008-07-01 18:31 . 2008-07-01 18:31 <DIR> d-------- C:\Program Files\Trend Micro 2008-07-01 16:31 . 2008-07-02 17:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-01 16:31 . 2008-07-01 16:31 1,409 --a------ C:\WINDOWS\QTFont.for 2008-06-22 17:29 . 2008-06-22 17:32 <DIR> d-------- C:\Program Files\RegCure 2008-06-21 17:57 . 2008-06-21 17:57 <DIR> d-------- C:\WINDOWS\system32\QVJGTGljZW5zZUluZm8= 2008-06-21 17:57 . 2008-06-21 19:51 <DIR> d-------- C:\Program Files\Advanced Registry Fix 2008-06-19 18:49 . 2008-06-19 18:49 <DIR> d-------- C:\Program Files\Google 2008-06-19 18:49 . 2008-07-06 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-06-19 18:43 . 2008-07-01 18:52 <DIR> d-------- C:\Program Files\CCleaner 2008-06-19 18:33 . 2008-06-19 18:33 <DIR> d-------- C:\DVR111D 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\scripting 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\en 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\bits 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\l2schemas 2008-06-19 17:54 . 2008-06-19 17:54 <DIR> d-------- C:\WINDOWS\ServicePackFiles 2008-06-19 17:42 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys 2008-06-16 19:40 . 2008-06-16 19:40 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-16 18:28 . 2008-06-16 18:28 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\EPSON 2008-06-16 18:27 . 2008-06-16 18:27 0 --a------ C:\WINDOWS\BM7540f224.xml 2008-06-15 19:35 . 2008-06-21 19:55 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-06-15 19:30 . 2008-06-30 16:54 69 --a------ C:\WINDOWS\NeroDigital.ini 2008-06-15 19:28 . 2005-01-20 13:29 2,658,304 --------- C:\WINDOWS\UNNeroVision.exe 2008-06-15 19:28 . 2004-07-09 08:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2008-06-15 19:28 . 2005-01-21 20:58 136,672 --------- C:\WINDOWS\UNNeroVision.cfg 2008-06-15 19:26 . 2008-06-15 19:26 <DIR> d-------- C:\Program Files\Common Files\Ahead 2008-06-15 19:26 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-06-15 19:26 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-06-15 19:26 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-06-15 19:26 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-06-15 19:26 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-06-15 19:26 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2008-06-15 19:26 . 2000-06-26 11:45 106,496 --------- C:\WINDOWS\system32\TwnLib20.dll 2008-06-15 19:26 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2008-06-15 18:35 . 2008-07-06 15:09 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-06-15 18:35 . 2008-06-20 20:46 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-06-15 18:35 . 2008-06-20 20:46 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys 2008-06-15 18:35 . 2008-06-20 20:46 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys 2008-06-15 18:35 . 2008-06-20 20:46 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-06-15 18:34 . 2008-06-15 18:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8 2008-06-15 18:33 . 2008-06-15 18:33 <DIR> d-------- C:\Program Files\AVG 2008-06-15 10:29 . 2008-06-15 10:29 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies 2008-06-15 10:16 . 2007-10-01 04:53 4,702,208 -ra------ C:\WINDOWS\RtHDVCpl.exe 2008-06-15 10:16 . 2007-08-31 08:36 2,087,936 -ra------ C:\WINDOWS\system32\RtkAPO.dll 2008-06-15 10:16 . 2007-09-20 10:30 584,704 -ra------ C:\WINDOWS\system32\RtkPgExt.dll 2008-06-15 10:16 . 2006-12-13 03:30 339,968 -ra------ C:\WINDOWS\system32\SRSTSXT.dll 2008-06-15 10:16 . 2007-03-23 08:34 266,240 -ra------ C:\WINDOWS\system32\RtkApoApi.dll 2008-06-15 10:16 . 2007-05-17 04:26 185,776 -ra------ C:\WINDOWS\system32\SRSTSHD.dll 2008-06-15 10:16 . 2007-04-16 10:09 167,936 -ra------ C:\WINDOWS\system32\SRSHP360.dll 2008-06-15 10:16 . 2007-07-25 02:33 135,168 -ra------ C:\WINDOWS\system32\SRSWOW.dll 2008-06-15 10:16 . 2007-07-30 11:26 126,976 -ra------ C:\WINDOWS\system32\maxxaudioapo.dll 2008-06-15 10:16 . 2007-10-01 07:01 23,552 -ra------ C:\WINDOWS\system32\RtkCoInst.dll 2008-06-15 10:15 . 2008-06-15 10:16 <DIR> d-------- C:\WINDOWS\system32\RTCOM 2008-06-15 10:15 . 2008-06-15 10:16 <DIR> d-------- C:\WINDOWS\ASUSInstAll 2008-06-15 10:15 . 2007-03-23 12:19 9,715,200 -r------- C:\WINDOWS\RTLCPL.exe 2008-06-15 10:15 . 2007-10-02 09:30 1,967,576 -ra------ C:\WINDOWS\system32\drivers\RTKVHDA.sys 2008-06-15 10:15 . 2007-08-03 06:22 1,826,816 -ra------ C:\WINDOWS\SkyTel.exe 2008-06-15 10:15 . 2007-07-26 11:06 1,191,936 -ra------ C:\WINDOWS\RtlUpd.exe 2008-06-15 10:15 . 2007-07-06 04:04 532,480 -ra------ C:\WINDOWS\system32\RTSndMgr.cpl 2008-06-15 10:15 . 2006-07-21 09:14 86,016 -r------- C:\WINDOWS\SoundMan.exe 2008-06-15 10:15 . 2006-08-01 08:02 49,152 -r------- C:\WINDOWS\system32\ChCfg.exe 2008-06-15 10:14 . 2008-06-15 10:14 <DIR> d-------- C:\Program Files\Realtek 2008-06-15 10:14 . 2007-09-27 07:20 16,844,800 -ra------ C:\WINDOWS\RTHDCPL.exe 2008-06-15 10:14 . 2007-10-02 09:32 4,613,120 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.sys 2008-06-15 10:14 . 2006-05-04 09:26 2,808,832 -r------- C:\WINDOWS\alcwzrd.exe 2008-06-15 10:14 . 2007-06-28 09:44 2,165,760 -r------- C:\WINDOWS\MicCal.exe 2008-06-15 10:14 . 2007-07-26 10:09 520,192 -r------- C:\WINDOWS\RtlExUpd.dll 2008-06-15 10:14 . 2008-06-15 10:14 315,392 --a------ C:\WINDOWS\HideWin.exe 2008-06-15 10:14 . 2005-09-21 03:25 299,008 -r------- C:\WINDOWS\system32\ALSndMgr.cpl 2008-06-15 10:14 . 2005-05-03 11:43 69,632 -r------- C:\WINDOWS\Alcmtr.exe 2008-06-15 10:13 . 2008-06-15 10:16 15,873 --a------ C:\WINDOWS\Ascd_log.ini 2008-06-15 10:12 . 2008-06-15 10:12 15,693 --a------ C:\WINDOWS\Ascd_tmp.ini 2008-06-15 10:03 . 2008-04-13 19:45 17,152 --a------ C:\WINDOWS\system32\drivers\usbohci.sys 2008-06-11 14:28 . 2008-06-13 12:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 14:28 . 2008-06-13 12:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 14:21 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-06 15:00 --------- d-----w C:\Documents and Settings\Ian\Application Data\DNA 2008-07-02 20:05 --------- d-----w C:\Documents and Settings\Ian\Application Data\BitTorrent 2008-06-30 16:47 --------- d-----w C:\Program Files\EPSON Print CD 2008-06-29 17:27 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2008-06-26 22:02 --------- d-----w C:\Documents and Settings\Ian\Application Data\Vso 2008-06-26 21:59 87,608 ----a-w C:\Documents and Settings\Ian\Application Data\inst.exe 2008-06-26 21:59 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys 2008-06-26 21:59 47,360 ----a-w C:\Documents and Settings\Ian\Application Data\pcouffin.sys 2008-06-26 21:59 --------- d-----w C:\Program Files\vso 2008-06-21 17:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-06-20 20:19 --------- d-----w C:\Program Files\Windows Live 2008-06-19 18:52 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-06-19 15:35 --------- d-----w C:\Program Files\Thief - Deadly Shadows 2008-06-17 10:15 --------- d-----w C:\Program Files\Yahoo! 2008-06-16 21:39 --------- d-----w C:\Documents and Settings\Ian\Application Data\Yahoo! 2008-06-16 21:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! 2008-06-16 18:40 --------- d-----w C:\Documents and Settings\Ian\Application Data\Lavasoft 2008-06-15 18:28 --------- d-----w C:\Program Files\Ahead 2008-06-15 09:32 --------- d-----w C:\Program Files\ATI Technologies 2008-06-10 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-25 08:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL 2008-05-25 08:33 --------- d-----w C:\Program Files\EPSON 2008-05-25 08:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON 2008-05-22 17:45 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-05-20 20:29 --------- d-----w C:\Program Files\SecondLife 2008-05-13 19:47 --------- d-----w C:\Program Files\DivX 2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe 2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll 2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe 2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe 2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe 2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe 2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe 2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll 2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll 2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll 2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll 2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll 2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll 2008-02-04 20:39 87,608 ----a-w C:\Documents and Settings\Ian\Application Data\ezpinst.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 19:35 289088] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-09-18 15:16 171464] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56 64512] "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-04-01 11:52 1368064] "OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 03:08 2512392] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-04 19:13 98304] "AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2004-09-16 16:15 538112] "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-03-26 15:40 794624] C:\Documents and Settings\Ian\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [10/26/2006 9:24:54 PM 98632] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2/4/2008 7:15:49 PM 118784] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\syste m] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM7540f224 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\DNA\\btdna.exe"= "C:\\Program Files\\BitTorrent\\bittorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\SecondLife\\SecondLife.exe"= "C:\\Program Files\\SecondLife\\SLVoice.exe"= "C:\\WINDOWS\\system32\\dpvsetup.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Lavasoft\\Ad-Aware SE Professional\\Ad-Aware.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Administrative Tools\\Recycle Bin\\kdja.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-20 20:46] R0 OODrvled;OODrvled;C:\WINDOWS\system32\DRIVERS\OODrvled.sys [2004-09-22 14:57] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-20 20:46] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-20 20:46] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-20 20:46] R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-20 20:46] S3 S3chipid;S3chipid;C:\DOCUME~1\Ian\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys [] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F8B9E5C0-4DCC-CFCF-ABA5-00401D608516}] C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe . Contents of the 'Scheduled Tasks' folder "2008-06-30 02:00:00 C:\WINDOWS\Tasks\Advanced Registry Fix.job" - C:\Program Files\Advanced Registry Fix\AdvancedRegistryFix.exe "2008-07-06 15:01:18 C:\WINDOWS\Tasks\RegCure Program Check.job" - C:\Program Files\RegCure\RegCure.exe "2008-06-26 02:01:25 C:\WINDOWS\Tasks\RegCure.job" - C:\Program Files\RegCure\RegCure.exe . - - - - ORPHANS REMOVED - - - - HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe HKLM-Run-EPSON Stylus Photo R220 Series - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe HKLM-Run-RaidTool - C:\Program Files\VIA\RAID\raid_tool.exe HKLM-Run-AVG7_CC - C:\PROGRA~1\Grisoft\AVG7\avgcc.exe HKLM-Run-BM7540f224 - C:\WINDOWS\system32\bynvkkmp.dll HKLM-Run-MCCInstall - C:\WINDOWS\Motive\blueyonder\MCCUninst.exe Notify-fccdaaBq - fccdaaBq.dll Notify-WgaLogon - (no file) ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-06 16:01:33 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\Documents and Settings\Ian\Local Settings\Application Data\Microsoft\Messenger\ianandjulieholland@hotmail.co.uk\SharingMetadata\W orking\database_9E76_73E9_7673_C117\fsrtmp.log 131072 bytes C:\Documents and Settings\Ian\Local Settings\Application Data\Microsoft\Messenger\ianandjulieholland@hotmail.co.uk\SharingMetadata\W orking\database_9E76_73E9_7673_C117\tmp.edb 131072 bytes ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\ehome\ehrecvr.exe C:\WINDOWS\ehome\ehSched.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehmsas.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\AVG\AVG8\avgrsx.exe . ************************************************************************** . Completion time: 2008-07-06 16:05:38 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-06 15:04:31 Pre-Run: 86,094,168,064 bytes free Post-Run: 86,082,056,192 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 253 --- E O F --- 2008-06-20 19:25:46 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:09:50, on 06/07/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\oodtray.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Nikon\PictureProject\NkbMonitor.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1201882736484 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 7040 bytes Thank you hope to hear from you soon |
|
06-Jul-2008, 05:38 PM
#6 | |
| Open Notepad and copy and paste the text in the quote box below into it: Quote:
Save the file to you desktop and name it CFScript.txt Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below. ![]() This will start ComboFix again. It may ask to reboot. Post the contents of Combofix.txt in your next reply. Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only
Click Exit on the Main menu to close the program. Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2
Please do an online scan with Kaspersky WebScanner Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.
Upgrading Java:
__________________ Microsoft MVP/Windows - Consumer Security If we have helped you, please consider making a donation to TSG! |
|
06-Jul-2008, 07:00 PM
#7 |
| Malwarebytes' Anti-Malware 1.19 Database version: 928 Windows 5.1.2600 Service Pack 3 23:21:53 06/07/2008 mbam-log-7-6-2008 (23-21-53).txt Scan type: Quick Scan Objects scanned: 41050 Time elapsed: 2 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\ihistorycookies.clshistorycookies (Rogue.ErrorEraser) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8502d876-f5a4-42cb-8ba7-55413c6cd36f} (Rogue.ErrorEraser) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{fe7beebd-7d16-4efc-a204-310ada898c32} (Rogue.ErrorEraser) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4b5563b7-2353-4c1e-865d-a3c84259d548} (Rogue.ErrorEraser) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM7540f224 (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Advanced Registry Fix\IHistoryCookies.dll (Rogue.ErrorEraser) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:58:27, on 06/07/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\oodtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe C:\Program Files\DNA\btdna.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Nikon\PictureProject\NkbMonitor.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220" O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [MCCInstall] C:\WINDOWS\Motive\blueyonder\MCCUninst.exe -Uninstall O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1201882736484 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 8301 bytes The Kaspersky scan is taking ages ill post this later (off the bed) |
|
07-Jul-2008, 01:25 AM
#8 |
| -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Monday, July 7, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, July 06, 2008 18:57:34 Records in database: 918909 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ I:\ Scan statistics: Files scanned: 90334 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 01:07:53 File name / Threat name / Threats count C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe Infected: Backdoor.Win32.Agent.lcw 1 C:\QooBox\Quarantine\C\WINDOWS\system32\fylyayyu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.yuv 1 The selected area was scanned. as promised i have just closed this down and left these threats on the PC |
|
07-Jul-2008, 01:41 PM
#9 | |
| Did you run the Combofix I gave you? Open Notepad and copy and paste the text in the quote box below into it: Quote:
Save the file to you desktop and name it CFScript.txt Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below. ![]() This will start ComboFix again. It may ask to reboot. Post the contents of Combofix.txt in your next reply together with a new HijackThis log.
__________________ Microsoft MVP/Windows - Consumer Security If we have helped you, please consider making a donation to TSG! |
|
08-Jul-2008, 11:41 AM
#10 |
| OK here goes not sure if this is relavent at the mo but it still booted up with that error? ComboFix 08-07-05.1 - Ian 2008-07-08 16:30:48.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1632 [GMT 1:00] Running from: C:\Documents and Settings\Ian\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Ian\Desktop\CFScript.txt * Created a new restore point FILE :: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe . ((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 ))))))))))))))))))))))))))))))) . 2008-07-06 23:33 . 2008-07-06 23:33 <DIR> d-------- C:\WINDOWS\Sun 2008-07-06 23:33 . 2008-07-06 23:33 <DIR> d-------- C:\Program Files\Java 2008-07-06 23:33 . 2008-07-06 23:33 <DIR> d-------- C:\Program Files\Common Files\Java 2008-07-06 23:33 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-06 23:17 . 2008-07-06 23:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-06 23:17 . 2008-07-06 23:17 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\Malwarebytes 2008-07-06 23:17 . 2008-07-06 23:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-06 23:17 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-06 23:17 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-06 16:24 . 2008-07-06 16:24 <DIR> d-------- C:\Program Files\isoHunt 2008-07-01 18:31 . 2008-07-01 18:31 <DIR> d-------- C:\Program Files\Trend Micro 2008-07-01 16:31 . 2008-07-07 16:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-01 16:31 . 2008-07-01 16:31 1,409 --a------ C:\WINDOWS\QTFont.for 2008-06-22 17:29 . 2008-06-22 17:32 <DIR> d-------- C:\Program Files\RegCure 2008-06-21 17:57 . 2008-07-06 23:21 <DIR> d-------- C:\Program Files\Advanced Registry Fix 2008-06-19 18:49 . 2008-06-19 18:49 <DIR> d-------- C:\Program Files\Google 2008-06-19 18:49 . 2008-07-07 16:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-06-19 18:43 . 2008-07-01 18:52 <DIR> d-------- C:\Program Files\CCleaner 2008-06-19 18:33 . 2008-06-19 18:33 <DIR> d-------- C:\DVR111D 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\scripting 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\en 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\system32\bits 2008-06-19 17:56 . 2008-06-19 17:56 <DIR> d-------- C:\WINDOWS\l2schemas 2008-06-19 17:54 . 2008-06-19 17:54 <DIR> d-------- C:\WINDOWS\ServicePackFiles 2008-06-19 17:42 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys 2008-06-16 19:40 . 2008-06-16 19:40 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-16 18:28 . 2008-06-16 18:28 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\EPSON 2008-06-15 19:35 . 2008-06-21 19:55 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-06-15 19:30 . 2008-07-07 17:36 116 --a------ C:\WINDOWS\NeroDigital.ini 2008-06-15 19:28 . 2005-01-20 13:29 2,658,304 --------- C:\WINDOWS\UNNeroVision.exe 2008-06-15 19:28 . 2004-07-09 08:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2008-06-15 19:28 . 2005-01-21 20:58 136,672 --------- C:\WINDOWS\UNNeroVision.cfg 2008-06-15 19:26 . 2008-06-15 19:26 <DIR> d-------- C:\Program Files\Common Files\Ahead 2008-06-15 19:26 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-06-15 19:26 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-06-15 19:26 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-06-15 19:26 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-06-15 19:26 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-06-15 19:26 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2008-06-15 19:26 . 2000-06-26 11:45 106,496 --------- C:\WINDOWS\system32\TwnLib20.dll 2008-06-15 19:26 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2008-06-15 18:35 . 2008-07-08 09:38 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-06-15 18:35 . 2008-06-20 20:46 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-06-15 18:35 . 2008-06-20 20:46 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys 2008-06-15 18:35 . 2008-06-20 20:46 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys 2008-06-15 18:35 . 2008-07-08 09:38 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-06-15 18:34 . 2008-06-15 18:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8 2008-06-15 18:33 . 2008-06-15 18:33 <DIR> d-------- C:\Program Files\AVG 2008-06-15 10:29 . 2008-06-15 10:29 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies 2008-06-15 10:16 . 2007-10-01 04:53 4,702,208 -ra------ C:\WINDOWS\RtHDVCpl.exe 2008-06-15 10:16 . 2007-08-31 08:36 2,087,936 -ra------ C:\WINDOWS\system32\RtkAPO.dll 2008-06-15 10:16 . 2007-09-20 10:30 584,704 -ra------ C:\WINDOWS\system32\RtkPgExt.dll 2008-06-15 10:16 . 2006-12-13 03:30 339,968 -ra------ C:\WINDOWS\system32\SRSTSXT.dll 2008-06-15 10:16 . 2007-03-23 08:34 266,240 -ra------ C:\WINDOWS\system32\RtkApoApi.dll 2008-06-15 10:16 . 2007-05-17 04:26 185,776 -ra------ C:\WINDOWS\system32\SRSTSHD.dll 2008-06-15 10:16 . 2007-04-16 10:09 167,936 -ra------ C:\WINDOWS\system32\SRSHP360.dll 2008-06-15 10:16 . 2007-07-25 02:33 135,168 -ra------ C:\WINDOWS\system32\SRSWOW.dll 2008-06-15 10:16 . 2007-07-30 11:26 126,976 -ra------ C:\WINDOWS\system32\maxxaudioapo.dll 2008-06-15 10:16 . 2007-10-01 07:01 23,552 -ra------ C:\WINDOWS\system32\RtkCoInst.dll 2008-06-15 10:15 . 2008-06-15 10:16 <DIR> d-------- C:\WINDOWS\system32\RTCOM 2008-06-15 10:15 . 2008-06-15 10:16 <DIR> d-------- C:\WINDOWS\ASUSInstAll 2008-06-15 10:15 . 2007-03-23 12:19 9,715,200 -r------- C:\WINDOWS\RTLCPL.exe 2008-06-15 10:15 . 2007-10-02 09:30 1,967,576 -ra------ C:\WINDOWS\system32\drivers\RTKVHDA.sys 2008-06-15 10:15 . 2007-08-03 06:22 1,826,816 -ra------ C:\WINDOWS\SkyTel.exe 2008-06-15 10:15 . 2007-07-26 11:06 1,191,936 -ra------ C:\WINDOWS\RtlUpd.exe 2008-06-15 10:15 . 2007-07-06 04:04 532,480 -ra------ C:\WINDOWS\system32\RTSndMgr.cpl 2008-06-15 10:15 . 2006-07-21 09:14 86,016 -r------- C:\WINDOWS\SoundMan.exe 2008-06-15 10:15 . 2006-08-01 08:02 49,152 -r------- C:\WINDOWS\system32\ChCfg.exe 2008-06-15 10:14 . 2008-06-15 10:14 <DIR> d-------- C:\Program Files\Realtek 2008-06-15 10:14 . 2007-09-27 07:20 16,844,800 -ra------ C:\WINDOWS\RTHDCPL.exe 2008-06-15 10:14 . 2007-10-02 09:32 4,613,120 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.sys 2008-06-15 10:14 . 2006-05-04 09:26 2,808,832 -r------- C:\WINDOWS\alcwzrd.exe 2008-06-15 10:14 . 2007-06-28 09:44 2,165,760 -r------- C:\WINDOWS\MicCal.exe 2008-06-15 10:14 . 2007-07-26 10:09 520,192 -r------- C:\WINDOWS\RtlExUpd.dll 2008-06-15 10:14 . 2008-06-15 10:14 315,392 --a------ C:\WINDOWS\HideWin.exe 2008-06-15 10:14 . 2005-09-21 03:25 299,008 -r------- C:\WINDOWS\system32\ALSndMgr.cpl 2008-06-15 10:14 . 2005-05-03 11:43 69,632 -r------- C:\WINDOWS\Alcmtr.exe 2008-06-15 10:13 . 2008-06-15 10:16 15,873 --a------ C:\WINDOWS\Ascd_log.ini 2008-06-15 10:12 . 2008-06-15 10:12 15,693 --a------ C:\WINDOWS\Ascd_tmp.ini 2008-06-15 10:03 . 2008-04-13 19:45 17,152 --a------ C:\WINDOWS\system32\drivers\usbohci.sys 2008-06-11 14:28 . 2008-06-13 12:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 14:28 . 2008-06-13 12:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 14:21 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-08 12:44 --------- d-----w C:\Documents and Settings\Ian\Application Data\DNA 2008-07-07 16:57 --------- d-----w C:\Documents and Settings\Ian\Application Data\BitTorrent 2008-06-30 16:47 --------- d-----w C:\Program Files\EPSON Print CD 2008-06-29 17:27 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2008-06-26 22:02 --------- d-----w C:\Documents and Settings\Ian\Application Data\Vso 2008-06-26 21:59 87,608 ----a-w C:\Documents and Settings\Ian\Application Data\inst.exe 2008-06-26 21:59 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys 2008-06-26 21:59 47,360 ----a-w C:\Documents and Settings\Ian\Application Data\pcouffin.sys 2008-06-26 21:59 --------- d-----w C:\Program Files\vso 2008-06-21 17:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-06-20 20:19 --------- d-----w C:\Program Files\Windows Live 2008-06-19 18:52 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-06-19 15:35 --------- d-----w C:\Program Files\Thief - Deadly Shadows 2008-06-17 10:15 --------- d-----w C:\Program Files\Yahoo! 2008-06-16 21:39 --------- d-----w C:\Documents and Settings\Ian\Application Data\Yahoo! 2008-06-16 21:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! 2008-06-16 18:40 --------- d-----w C:\Documents and Settings\Ian\Application Data\Lavasoft 2008-06-15 18:28 --------- d-----w C:\Program Files\Ahead 2008-06-15 09:32 --------- d-----w C:\Program Files\ATI Technologies 2008-06-10 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-25 08:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL 2008-05-25 08:33 --------- d-----w C:\Program Files\EPSON 2008-05-25 08:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON 2008-05-22 17:45 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-05-20 20:29 --------- d-----w C:\Program Files\SecondLife 2008-05-13 19:47 --------- d-----w C:\Program Files\DivX 2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe 2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll 2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe 2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe 2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe 2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe 2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe 2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll 2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll 2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll 2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll 2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll 2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll 2008-02-04 20:39 87,608 ----a-w C:\Documents and Settings\Ian\Application Data\ezpinst.exe . ((((((((((((((((((((((((((((( snapshot@2008-07-06_16.04.20.23 ))))))))))))))))))))))))))))))))))))))))) . - 2008-07-06 15:01:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-08 15:33:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-06-20 19:46:17 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys + 2008-07-08 08:38:20 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys + 2008-03-25 00:28:39 135,168 ----a-w C:\WINDOWS\system32\java.exe + 2008-03-25 00:28:43 135,168 ----a-w C:\WINDOWS\system32\javaw.exe + 2008-03-25 01:37:01 139,264 ----a-w C:\WINDOWS\system32\javaws.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 19:35 289088] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-09-18 15:16 171464] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [BU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56 64512] "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-04-01 11:52 1368064] "OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 03:08 2512392] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-04 19:13 98304] "AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2004-09-16 16:15 538112] "EPSON Stylus Photo R220 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE" [BU] "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU] "RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [BU] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [BU] "MCCInstall"="C:\WINDOWS\Motive\blueyonder\MCCUninst.exe" [BU] "BM7540f224"="C:\WINDOWS\system32\bynvkkmp.dll" [BU] "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-03-26 15:40 794624] C:\Documents and Settings\Ian\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [10/26/2006 9:24:54 PM 98632] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2/4/2008 7:15:49 PM 118784] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\syste m] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM7540f224 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\DNA\\btdna.exe"= "C:\\Program Files\\BitTorrent\\bittorrent.exe"= "%windir%\\N |




