| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
30-Jun-2009, 09:51 AM
#1 |
| Malwarebytes anti-malware uses chkdsk? Hi, i am new to using Malwarebyes anti malware. I recently did a full drive scan of drive C, and a it found a few hundred things and most of them it couldn't remove without a reboot. so it reboots and i'm surprised to see chkdsk running on reboot. is this normal? does malwarebytes use this to remove those files? or did something else happen to cause this? after this was done and i got back onto the desktop, i did another scan to make sure it really did get rid of everything and it seems that it did. it did not find anything at all on the second scan. i just wanted to confirm if this was normal behavior because it kinds scared me . i normally only see chkdsk run on it's own after something bad happend. i wasn't able to read it all cause it went so fast but it seemed to be repairing a lot of things and deleting things....it was hard to tell. any info on this is greatly appreciated. thoughts, ideas, (maybe something similar happend to other people) anything at all to help me understand this would be great. thx a lot. |
| |
30-Jun-2009, 10:45 AM
#2 | |||||
| I don't think MalwareBytes triggers chkdsk but chkdsk will run on its own if problems with the drive are detected. Let's see the report from the chkdsk run and see what it did. I assume it's not running one very boot but only the one time? Go to Start - Run and type in eventvwr.msc, and hit enter. When Event Viewer opens, click on "Application", then scroll down to "Winlogon" and double-click on it to open it up. This is the log created after running chkdsk. Click on the icon that looks like two pieces of paper to copy it and then paste it here please. Also, please post your MalwareBytes scan log.
__________________ Microsoft MVP - Consumer Security |
|
30-Jun-2009, 05:24 PM
#3 | |
| thx for your help. here is what you requested. eventviewer Quote:
post was too long so i'll put the malwarebytes log after this. |
|
30-Jun-2009, 05:24 PM
#4 | |
| MALWAREBYTES log Quote:
also. when i shutdown. it seemed to take a very long time. and when i booted up again after it was off for the night, i got another chkdsk but it seemed/felt shorter and faster. but the log appears to be just as long now that i compare the two. |
|
30-Jun-2009, 05:46 PM
#5 |
| Do you have an antivirus on that machine? That's a lot of infected files! ![]() Remember, MBAM is not an antivirus program. You might want to post a HijackThis log. It will help malware removal experts. Please click here to download and install the HijackThis installer. Run it and select Do a system scan and save a logfile. The log will be saved in Notepad. Copy and paste the log in your next post. Do not fix anything |
|
30-Jun-2009, 06:00 PM
#6 | |
| thx. i do. recently replaced norton with avira antivir. been using it for a few weeks now. here it is Quote:
|
|
30-Jun-2009, 07:11 PM
#7 |
| You still have traces of Norton you should remove. Use the Norton Removal Tool. |
30-Jun-2009, 07:18 PM
#8 | |||||
| Well if you had any wallpaper on your desktop, perhaps now you can see it. ![]() ![]() Please visit Combofix Guide & Instructions for instructions for installing the recovery console and downloading and running ComboFix. The only thing different from the instructions there is that when downloading and saving the ComboFix.exe I would like you to rename it to Combo-Fix.exe please. Post the log from ComboFix when you've accomplished that along with a new HijackThis log. Important notes regarding ComboFix: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser. This can easily be changed once we're finished. ComboFix also prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you, please let me know. This can be undone manually when we're finished. Read HERE for an article written by dvk01 on why we disable autoruns. Note: During this process, it would help a great deal and be very much appreciated if you would refrain from installing any new software or hardware on this machine, unless absolutely necessary, until the clean up process is finished as it makes our job more tedious, with additional new files that may have to be researched, which is very time consuming. Also, please do not run any security programs or fixes on your own as doing so may compromise what we will be doing. It is important that you wait for instructions.
__________________ Microsoft MVP - Consumer Security |
|
30-Jun-2009, 08:20 PM
#9 | |
| okie dokie. here is the combofix log Quote:
|
|
30-Jun-2009, 08:21 PM
#10 | |
| new HJT log Quote:
something that came up which i hope will not ruin everything thus far. I used to have teatimer from Spybot isntalled, which would bug me about registry changes, i disabled it a few weeks ago and removed it from my startup. however AFTER the combofix thingy finished, i got a series of warnings from teatimer about registry changes. i denied them all. i hope that was ok. and i'm sorry i didn't pay too much attention to what they were. one of them was blank in the "old/new" change, and the first 3 or so were trying to update a microsoft link from "microsoft.com..." to "go.microsoft.com..." the rest i cant' remember. so hopefully i didn't ruin things. i thought it would be safest to deny them. i should probably completely uninstall teatimer now isntead to make sure it doesn't somehow revive again. |
01-Jul-2009, 12:25 PM
#11 | |||||
| TeaTimer wasn't showing as running in your HijackThis log but if you allowed it to block registry changes ComboFix was trying to make then yes, that could have compromised the fix. I suggest you uninstall Spybot S&D and then reboot the computer. You can always reinstall it after we're finished is you wish. Then run ComboFix again and post the new scan log.
__________________ Microsoft MVP - Consumer Security |
|
01-Jul-2009, 09:48 PM
#12 |
| uninstalled spybot, rebooted, and then ran combox fix again ComboFix 09-07-01.01 - Tact 07/01/2009 17:40.2 - NTFSx86 Running from: c:\documents and settings\Tact\Desktop\Combo-Fix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 ))))))))))))))))))))))))))))))) . 2009-07-02 00:42 . 2009-07-02 00:42 53248 ----a-w- c:\temp\catchme.dll 2009-07-02 00:40 . 2009-07-02 00:40 -------- d-----w- c:\temp\WPDNSE 2009-06-30 23:00 . 2009-06-30 23:13 -------- d-----w- c:\temp\7zS15.tmp 2009-06-30 20:59 . 2009-06-30 20:59 -------- d-----w- c:\program files\Trend Micro 2009-06-30 20:06 . 2009-06-30 20:06 -------- d-sh--w- C:\found.001 2009-06-30 11:49 . 2009-06-30 11:49 -------- d-sh--w- C:\found.000 2009-06-21 10:07 . 2009-06-21 10:07 -------- d-----w- c:\program files\VS Revo Group 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\documents and settings\Tact\Application Data\Malwarebytes 2009-06-20 02:36 . 2009-06-17 18:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-20 02:36 . 2009-06-17 18:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-20 01:55 . 2009-07-02 00:36 117760 ----a-w- c:\documents and settings\Tact\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-20 01:55 . 2009-06-20 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-20 01:55 . 2009-06-30 10:19 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-20 01:55 . 2009-06-20 01:55 -------- d-----w- c:\documents and settings\Tact\Application Data\SUPERAntiSpyware.com 2009-06-19 05:38 . 2008-10-17 19:39 20092 ----a-w- c:\windows\system32\drivers\lgusbbus.sys 2009-06-14 21:58 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-06-14 21:58 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-06-14 04:13 . 2009-06-29 23:28 -------- d-----w- c:\documents and settings\Tact\Tracing 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Microsoft 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Windows Live 2009-06-14 04:06 . 2009-06-14 04:06 -------- d-----w- c:\program files\Common Files\Windows Live 2009-06-10 19:10 . 2009-06-10 19:10 -------- d-----w- c:\documents and settings\Tact\Local Settings\Application Data\Blizzard Entertainment 2009-06-10 04:39 . 2008-05-29 06:03 37176 ----a-w- c:\documents and settings\Tact\Application Data\Macromedia\Flash Player\http://www.macromedia.com\bin\airapp...pinstaller.exe 2009-06-10 02:54 . 2009-06-11 03:08 -------- d-----w- c:\documents and settings\Tact\Application Data\gtk-2.0 2009-06-10 02:54 . 2009-06-10 02:54 -------- d-----w- c:\documents and settings\Tact\Application Data\Inkscape 2009-06-08 06:24 . 2009-06-08 06:24 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet 2009-06-08 06:16 . 2009-06-08 06:16 -------- d-----w- c:\program files\Adobe Media Player 2009-06-08 06:16 . 2009-06-08 06:16 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-06-08 03:07 . 2009-06-08 06:01 -------- d-----w- c:\documents and settings\Tact\Application Data\Download Manager 2009-06-02 23:20 . 2009-06-02 23:20 -------- d-----w- c:\documents and settings\Tact\Local Settings\Application Data\Xenocode . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 00:31 . 2007-01-08 05:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-30 23:02 . 2007-01-08 04:52 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-06-20 04:07 . 2009-05-13 20:18 -------- d-----w- c:\program files\Lavasoft 2009-06-20 03:48 . 2007-01-08 04:15 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-20 01:55 . 2008-01-12 07:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-06-18 04:04 . 2007-01-14 04:50 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-14 04:12 . 2007-01-08 03:59 254880 ----a-w- c:\documents and settings\Tact\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-14 04:12 . 2007-03-06 18:36 -------- d-----w- c:\program files\MSN Messenger 2009-06-02 06:52 . 2008-03-18 22:18 -------- d-----w- c:\documents and settings\Tact\Application Data\FileZilla 2009-05-25 04:03 . 2009-05-25 04:03 -------- d-----w- c:\program files\Windows Media Connect 2 2009-05-16 04:14 . 2009-05-16 04:14 -------- d-----w- c:\program files\Avira 2009-05-16 04:14 . 2009-05-16 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2009-05-14 21:22 . 2009-05-14 21:22 -------- d-----w- c:\program files\Panda Security 2009-05-13 20:18 . 2008-01-12 07:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-05-08 20:13 . 2007-01-08 04:10 -------- d-----w- c:\program files\Common Files\InstallShield 2009-05-07 15:44 . 2001-08-23 19:00 344064 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:52 . 2001-08-23 19:00 659456 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:52 . 2007-01-08 03:54 81920 ------w- c:\windows\system32\ieencode.dll 2009-04-23 02:23 . 2009-04-27 23:08 2797468 ----a-w- c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll 2009-04-17 09:58 . 2001-08-23 19:00 1846656 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 15:11 . 2001-08-23 19:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Zone Labs Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 755480] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavaso ft Ad-Aware Service] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Background Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Background Monitor.lnk backup=c:\windows\pss\EPSON Background Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check.lnk backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Tact^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=c:\documents and settings\Tact\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "NVSvc"=2 (0x2) "SNDSrvc"=3 (0x3) "ccPwdSvc"=3 (0x3) "ERSvc"=2 (0x2) "Schedule"=2 (0x2) "srservice"=2 (0x2) "SBService"=2 (0x2) "mysql"=2 (0x2) "Apache2.2"=2 (0x2) "usnjsvc"=3 (0x3) "gusvc"=3 (0x3) "Adobe LM Service"=3 (0x3) "CCALib8"=2 (0x2) "aawservice"=2 (0x2) "IDriverT"=3 (0x3) "EpsonBidirectionalService"=2 (0x2) "npkcmsvc"=2 (0x2) "WMPNetworkSvc"=3 (0x3) "Symantec Core LC"=3 (0x3) "Lavasoft Ad-Aware Service"=3 (0x3) "FLEXnet Licensing Service"=3 (0x3) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="d:\program files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "d:\\Program Files\\LimeWire\\LimeWire.exe"= R0 oeiwl;oeiwl;c:\windows\system32\drivers\tcxmd.sys [x] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-20 28544] S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-05-26 72944] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-14 108289] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-26 7408] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download with Star Downloader - d:\program files\Star Downloader\sdie.htm IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm TaskBar Icon - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab DPF: {4A116A80-85B6-4299-A018-A717FD7AC66A} - hxxp://m1.cdn.gaiaonline.com/plugins/IDMFlash.cab DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} - hxxp://www.gamengame.com/KALogoutComponent.cab FF - ProfilePath - c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\ FF - component: c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll FF - component: c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll FF - plugin: d:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\np32dsw.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npnul32.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin2.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin3.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin4.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin5.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin6.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin7.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin3.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin4.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin5.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin6.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin7.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nppl3260.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprjplug.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll FF - plugin: d:\program files\VideoLAN\VLC\npvlc.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-01 17:42 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1606980848-838170752-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Erogos\~0{0_0~0*0J0W0ƒ0v0Š0è}-*SOšHr-*] "Order"=hex:08,00,00,00,02,00,00,00,1c,01,00,00,01,00,00,00,02,00,00,00,86, 00, 00,00,00,00,00,00,78,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,32, \ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(588) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(2456) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-07-02 17:44 ComboFix-quarantined-files.txt 2009-07-02 00:44 ComboFix2.txt 2009-06-30 23:16 Pre-Run: 20,629,712,896 bytes free Post-Run: 20,628,807,680 bytes free 226 --- E O F --- 2009-06-15 20:56 btw. since yesterday's combofix, i no longer have a super looong shutdown and i did not get chkdsk anymore. so i think it helped. ![]() not sure if i have anything though. and from the last log, ijji should have been a harmless file since i use that to run an online game. but ah well. i rarely play it so i didn't care that combofix got rid of it. Last edited by Cookiegal; 02-Jul-2009 at 09:10 PM.. |
02-Jul-2009, 09:15 PM
#14 | |||||
| Open Notepad and copy and paste the text in the code box below into it: Code: File:: c:\temp\7zS15.tmp Driver:: oeiwl Referring to the picture below, drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you. Post that log in your next reply. ![]() This will start ComboFix again. It may ask to reboot. Post the contents of Combofix.txt in your next reply together with a new HijackThis log. **Note** When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
Note: These instructions and script were created specifically for this user. If you are not this user, do NOT follow these instructions or use this script as it could damage the workings of your system.
__________________ Microsoft MVP - Consumer Security |
|
03-Jul-2009, 07:29 AM
#15 |
| alrighty. here's combo's ComboFix 09-07-02.02 - Tact 07/03/2009 3:18.3 - NTFSx86 Running from: c:\documents and settings\Tact\Desktop\Combo-Fix.exe Command switches used :: c:\documents and settings\Tact\Desktop\CFScript.txt * Created a new restore point FILE :: "c:\temp\7zS15.tmp" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_oeiwl ((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 ))))))))))))))))))))))))))))))) . 2009-07-03 10:23 . 2009-07-03 10:23 53248 ----a-w- c:\temp\catchme.dll 2009-07-03 10:23 . 2009-07-03 10:23 -------- d-----w- c:\temp\WPDNSE 2009-07-03 10:21 . 2009-07-03 10:21 60416 ----a-w- c:\temp\Perflib_Perfdata__755.dat 2009-07-03 04:22 . 2009-07-03 04:22 -------- d-----w- c:\temp\MessengerCache 2009-06-30 23:00 . 2009-06-30 23:13 -------- d-----w- c:\temp\7zS15.tmp 2009-06-30 20:59 . 2009-06-30 20:59 -------- d-----w- c:\program files\Trend Micro 2009-06-30 20:06 . 2009-06-30 20:06 -------- d-sh--w- C:\found.001 2009-06-30 11:49 . 2009-06-30 11:49 -------- d-sh--w- C:\found.000 2009-06-21 10:07 . 2009-06-21 10:07 -------- d-----w- c:\program files\VS Revo Group 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\documents and settings\Tact\Application Data\Malwarebytes 2009-06-20 02:36 . 2009-06-17 18:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-20 02:36 . 2009-06-20 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-20 02:36 . 2009-06-17 18:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-20 01:55 . 2009-07-03 10:23 117760 ----a-w- c:\documents and settings\Tact\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-20 01:55 . 2009-06-20 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-20 01:55 . 2009-06-30 10:19 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-20 01:55 . 2009-06-20 01:55 -------- d-----w- c:\documents and settings\Tact\Application Data\SUPERAntiSpyware.com 2009-06-19 05:38 . 2008-10-17 19:39 20092 ----a-w- c:\windows\system32\drivers\lgusbbus.sys 2009-06-14 21:58 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-06-14 21:58 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-06-14 04:13 . 2009-07-03 04:22 -------- d-----w- c:\documents and settings\Tact\Tracing 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Microsoft 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-06-14 04:11 . 2009-06-14 04:11 -------- d-----w- c:\program files\Windows Live 2009-06-14 04:06 . 2009-06-14 04:06 -------- d-----w- c:\program files\Common Files\Windows Live 2009-06-10 19:10 . 2009-06-10 19:10 -------- d-----w- c:\documents and settings\Tact\Local Settings\Application Data\Blizzard Entertainment 2009-06-10 04:39 . 2008-05-29 06:03 37176 ----a-w- c:\documents and settings\Tact\Application Data\Macromedia\Flash Player\http://www.macromedia.com\bin\airapp...pinstaller.exe 2009-06-10 02:54 . 2009-06-11 03:08 -------- d-----w- c:\documents and settings\Tact\Application Data\gtk-2.0 2009-06-10 02:54 . 2009-06-10 02:54 -------- d-----w- c:\documents and settings\Tact\Application Data\Inkscape 2009-06-08 06:24 . 2009-06-08 06:24 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet 2009-06-08 06:16 . 2009-06-08 06:16 -------- d-----w- c:\program files\Adobe Media Player 2009-06-08 06:16 . 2009-06-08 06:16 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-06-08 03:07 . 2009-06-08 06:01 -------- d-----w- c:\documents and settings\Tact\Application Data\Download Manager . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 00:31 . 2007-01-08 05:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-30 23:02 . 2007-01-08 04:52 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-06-20 04:07 . 2009-05-13 20:18 -------- d-----w- c:\program files\Lavasoft 2009-06-20 03:48 . 2007-01-08 04:15 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-20 01:55 . 2008-01-12 07:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-06-18 04:04 . 2007-01-14 04:50 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-14 04:12 . 2007-01-08 03:59 254880 ----a-w- c:\documents and settings\Tact\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-14 04:12 . 2007-03-06 18:36 -------- d-----w- c:\program files\MSN Messenger 2009-06-02 06:52 . 2008-03-18 22:18 -------- d-----w- c:\documents and settings\Tact\Application Data\FileZilla 2009-05-25 04:03 . 2009-05-25 04:03 -------- d-----w- c:\program files\Windows Media Connect 2 2009-05-16 04:14 . 2009-05-16 04:14 -------- d-----w- c:\program files\Avira 2009-05-16 04:14 . 2009-05-16 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2009-05-14 21:22 . 2009-05-14 21:22 -------- d-----w- c:\program files\Panda Security 2009-05-13 20:18 . 2008-01-12 07:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-05-08 20:13 . 2007-01-08 04:10 -------- d-----w- c:\program files\Common Files\InstallShield 2009-05-07 15:44 . 2001-08-23 19:00 344064 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:52 . 2001-08-23 19:00 659456 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:52 . 2007-01-08 03:54 81920 ------w- c:\windows\system32\ieencode.dll 2009-04-23 02:23 . 2009-04-27 23:08 2797468 ----a-w- c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll 2009-04-17 09:58 . 2001-08-23 19:00 1846656 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 15:11 . 2001-08-23 19:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( SnapShot@2009-06-30_23.14.16 ))))))))))))))))))))))))))))))))))))))))) . + 2005-11-14 23:38 . 2005-11-14 23:38 72192 c:\windows\Installer\80702.msp + 2009-06-08 06:16 . 2009-06-08 06:16 23552 c:\windows\Installer\1ea5d16.msi + 2009-06-08 06:16 . 2009-06-08 06:16 26112 c:\windows\Installer\1ea5d0d.msi + 2009-06-14 04:11 . 2009-06-14 04:11 25088 c:\windows\Installer\17b239.msi + 2009-06-14 04:11 . 2009-06-14 04:11 28160 c:\windows\Installer\17b230.msi + 2009-06-14 04:11 . 2009-06-14 04:11 83456 c:\windows\Installer\17b202.msi + 2009-06-14 04:11 . 2009-06-14 04:11 59904 c:\windows\Installer\17b1f9.msi + 2008-08-18 20:06 . 2008-08-18 20:06 89600 c:\windows\Installer\1064c.msi + 2008-07-15 03:03 . 2008-07-15 03:03 451584 c:\windows\Installer\fe734b.msi + 2008-11-12 20:05 . 2008-11-12 20:05 432640 c:\windows\Installer\89935.msi + 2008-07-23 06:20 . 2008-07-23 06:20 110592 c:\windows\Installer\80779.msp + 2009-04-20 21:59 . 2009-04-20 21:59 219648 c:\windows\Installer\80749.msp + 2009-02-10 15:50 . 2009-02-10 15:50 536576 c:\windows\Installer\8068a.msp + 2008-01-24 17:04 . 2008-01-24 17:04 678400 c:\windows\Installer\8063f.msp + 2008-05-23 18:18 . 2008-05-23 18:18 409600 c:\windows\Installer\620bc.msi + 2007-06-08 17:57 . 2007-06-08 17:57 213504 c:\windows\Installer\44dafc.msi + 2009-05-13 20:18 . 2009-05-13 20:18 236032 c:\windows\Installer\2dc09d.msi + 2009-05-16 04:12 . 2009-05-16 04:12 228352 c:\windows\Installer\2d42561.msi + 2007-01-08 03:34 . 2007-01-08 03:34 264704 c:\windows\Installer\20319.msi + 2007-01-26 06:46 . 2007-01-26 06:46 188928 c:\windows\Installer\1b6fb09.msi + 2009-06-14 04:11 . 2009-06-14 04:11 431104 c:\windows\Installer\17b244.msi + 2009-06-14 04:11 . 2009-06-14 04:11 140288 c:\windows\Installer\17b227.msi + 2009-06-14 04:11 . 2009-06-14 04:11 202752 c:\windows\Installer\17b214.msi + 2009-06-14 04:11 . 2009-06-14 04:11 152576 c:\windows\Installer\17b20b.msi + 2009-06-14 04:10 . 2009-06-14 04:10 107008 c:\windows\Installer\17b1f0.msi + 2009-06-14 04:10 . 2009-06-14 04:10 301056 c:\windows\Installer\17b1e7.msi + 2008-08-22 05:49 . 2008-08-22 05:49 527872 c:\windows\Installer\1381160.msi + 2008-07-27 08:52 . 2008-07-27 08:52 431104 c:\windows\Installer\11f1e5b.msi + 2008-08-03 23:52 . 2008-08-03 23:52 579584 c:\windows\Installer\119b0ed.msi + 2008-08-18 20:13 . 2008-08-18 20:13 390656 c:\windows\Installer\1065c.msi + 2001-08-23 19:00 . 2004-07-17 19:35 1326080 c:\windows\system32\webfldrs.msi + 2007-01-08 03:53 . 2004-07-17 19:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi + 2008-07-26 00:53 . 2008-07-26 00:53 1602560 c:\windows\Installer\e16af6.msi + 2007-01-14 04:53 . 2007-01-14 04:53 3537408 c:\windows\Installer\cdaf0a.msi + 2007-04-19 03:24 . 2007-04-19 03:24 1067520 c:\windows\Installer\ca870.msi + 2007-03-16 06:04 . 2007-03-16 06:04 3485184 c:\windows\Installer\8e6e4e.msi + 2009-05-01 06:02 . 2009-05-01 06:02 9628672 c:\windows\Installer\80732.msp + 2008-09-04 22:52 . 2008-09-04 22:52 4337664 c:\windows\Installer\80719.msp + 2008-01-11 21:13 . 2008-01-11 21:13 5862912 c:\windows\Installer\806d1.msp + 2008-01-14 21:26 . 2008-01-14 21:26 4478464 c:\windows\Installer\806ba.msp + 2006-02-27 23:31 . 2006-02-27 23:31 1269248 c:\windows\Installer\806a2.msp + 2006-03-28 22:37 . 2006-03-28 22:37 6956032 c:\windows\Installer\80671.msp + 2006-08-30 00:50 . 2006-08-30 00:50 3210240 c:\windows\Installer\80657.msp + 2004-03-10 16:13 . 2004-03-10 16:13 2602496 c:\windows\Installer\80623.msp + 2009-04-29 22:03 . 2009-04-29 22:03 8404992 c:\windows\Installer\8060c.msp + 2004-09-13 07:35 . 2004-09-13 07:35 1452544 c:\windows\Installer\805f4.msp + 2008-06-12 03:13 . 2008-06-12 03:13 7988224 c:\windows\Installer\8059d.msp + 2008-03-31 23:35 . 2008-03-31 23:35 8309760 c:\windows\Installer\80584.msp + 2006-02-22 16:41 . 2006-02-22 16:41 2815488 c:\windows\Installer\8056d.msp + 2007-03-22 01:03 . 2007-03-22 01:03 3443712 c:\windows\Installer\772c83.msi + 2008-08-12 20:03 . 2008-08-12 20:03 1341440 c:\windows\Installer\5098bb.msi + 2007-01-08 06:20 . 2007-01-08 06:20 2262016 c:\windows\Installer\3b33ae.msi + 2008-07-30 20:36 . 2008-07-30 20:36 1528832 c:\windows\Installer\2bfc8e4.msi + 2007-01-08 04:15 . 2007-01-08 04:15 2707456 c:\windows\Installer\27e49.msi + 2008-05-28 23:01 . 2008-05-28 23:01 8984576 c:\windows\Installer\156d66.msi + 2007-01-25 22:44 . 2007-01-25 22:44 2910720 c:\windows\Installer\14ad1b.msi + 2009-06-20 01:55 . 2009-06-20 01:55 1516544 c:\windows\Installer\14639d.msi + 2007-01-08 03:49 . 2001-08-23 19:00 1308672 c:\windows\$NtServicePackUninstall$\webfldrs.msi + 2007-03-06 18:36 . 2007-01-19 21:20 16633344 c:\windows\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi + 2009-05-06 01:06 . 2009-05-06 01:06 17515008 c:\windows\Installer\80791.msp + 2008-01-24 22:56 . 2008-01-24 22:56 13570560 c:\windows\Installer\80762.msp + 2005-09-25 18:46 . 2005-09-25 18:46 16084480 c:\windows\Installer\806ea.msp + 2004-01-30 10:19 . 2004-01-30 10:19 56269996 c:\windows\Installer\19c0345.msp . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Zone Labs Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 755480] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavaso ft Ad-Aware Service] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Background Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Background Monitor.lnk backup=c:\windows\pss\EPSON Background Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check.lnk backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Tact^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=c:\documents and settings\Tact\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "NVSvc"=2 (0x2) "SNDSrvc"=3 (0x3) "ccPwdSvc"=3 (0x3) "ERSvc"=2 (0x2) "Schedule"=2 (0x2) "srservice"=2 (0x2) "SBService"=2 (0x2) "mysql"=2 (0x2) "Apache2.2"=2 (0x2) "usnjsvc"=3 (0x3) "gusvc"=3 (0x3) "Adobe LM Service"=3 (0x3) "CCALib8"=2 (0x2) "aawservice"=2 (0x2) "IDriverT"=3 (0x3) "EpsonBidirectionalService"=2 (0x2) "npkcmsvc"=2 (0x2) "WMPNetworkSvc"=3 (0x3) "Symantec Core LC"=3 (0x3) "Lavasoft Ad-Aware Service"=3 (0x3) "FLEXnet Licensing Service"=3 (0x3) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="d:\program files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "d:\\Program Files\\LimeWire\\LimeWire.exe"= S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-20 28544] S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-05-26 72944] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-14 108289] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-26 7408] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download with Star Downloader - d:\program files\Star Downloader\sdie.htm IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm TaskBar Icon - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab DPF: {4A116A80-85B6-4299-A018-A717FD7AC66A} - hxxp://m1.cdn.gaiaonline.com/plugins/IDMFlash.cab DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} - hxxp://www.gamengame.com/KALogoutComponent.cab FF - ProfilePath - c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\ FF - component: c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll FF - component: c:\documents and settings\Tact\Application Data\Mozilla\Firefox\Profiles\dkj8wlux.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll FF - plugin: d:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\np32dsw.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npnul32.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin2.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin3.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin4.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin5.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin6.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npqtplugin7.dll FF - plugin: d:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin3.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin4.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin5.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin6.dll FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin7.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nppl3260.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprjplug.dll FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll FF - plugin: d:\program files\VideoLAN\VLC\npvlc.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-03 03:23 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1606980848-838170752-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Erogos\~0{0_0~0*0J0W0ƒ0v0Š0è}-*SOšHr-*] "Order"=hex:08,00,00,00,02,00,00,00,1c,01,00,00,01,00,00,00,02,00,00,00,86, 00, 00,00,00,00,00,00,78,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,32, \ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(592) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(3048) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Avira\AntiVir Desktop\avguard.exe c:\windows\system32\ZoneLabs\vsmon.exe . ************************************************************************** . Completion time: 2009-07-03 3:27 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-03 10:26 ComboFix2.txt 2009-07-02 00:44 ComboFix3.txt 2009-06-30 23:16 Pre-Run: 20,542,603,264 bytes free Post-Run: 20,524,572,672 bytes free 311 --- E O F --- 2009-06-15 20:56 Last edited by Cookiegal; 03-Jul-2009 at 05:41 PM.. |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 05:28 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |
