GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

Trojan.Zlob.G HELP please :(

View previous topic View next topic Go down

Solved Trojan.Zlob.G HELP please :(

Post by SailorMRC on Wed Dec 10, 2008 3:47 am

I just got this trojan virus like everyone else. Same pop ups with the fake alert messages and no access to the internet. It says the internet has a threat and to download the pretender 2009, but i didn't. It keeps shutting the browser down and its also affected my AIM too. Here is my Hijackthis log. Please help. Thank you

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:42:05 PM, on 12/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\CDProxyServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LifeCam] "c:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Policies\Explorer\Run: [skwc.exe] C:\WINDOWS\system\skwc.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Yahoo! Fleet - [You must be registered and logged in to see this link.]
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - [You must be registered and logged in to see this link.]
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {C9E2242D-DC05-4C54-9483-A5C90653F7BC} (TIClientControl Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - [You must be registered and logged in to see this link.]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - Unknown owner - C:\WINDOWS\System32\$sys$filesystem\$sys$DRMServer.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 9734 bytes

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Wed Dec 10, 2008 2:21 pm

Hello.


  • Download combofix from here, use the top links - [You must be registered and logged in to see this link.]
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Thu Dec 11, 2008 1:28 am

ComboFix 08-12-09.03 - Owner 2008-12-10 19:59:27.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.793 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\uninstall information
c:\program files\INSTALL.LOG
c:\windows\system32\quqpd.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_$SYS$ARIES
-------\Legacy_$SYS$DRMSERVER
-------\Legacy_CD_PROXY
-------\Legacy_SVCPROC
-------\Service_$sys$DRMServer
-------\Service_CD_Proxy

((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-09 22:41 . 2008-12-09 22:41 d-------- c:\program files\Trend Micro
2008-12-07 11:43 . 2008-12-09 20:04 d--h----- C:\$AVG8.VAULT$
2008-12-01 20:48 . 2008-12-01 20:48 d-------- c:\program files\Yahoo!
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\program files\iTunes
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\program files\iPod
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-24 01:21 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-11-24 01:21 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-24 00:20 . 2008-11-24 00:21 d-------- c:\program files\QuickTime
2008-11-21 22:55 . 2008-11-21 22:55 d-------- c:\program files\Ventrilo
2008-11-21 22:55 . 2008-11-21 22:55 d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-21 22:55 . 2008-11-21 22:55 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-11-20 23:14 . 2008-11-20 23:14 d-------- c:\program files\CCleaner
2008-11-20 15:44 . 2008-11-20 15:44 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-11-20 09:37 . 2008-11-20 09:37 d-------- C:\Intel
2008-11-20 09:37 . 2004-08-20 15:50 159,744 --a------ c:\windows\system32\igfxres.dll
2008-11-19 17:05 . 2008-12-10 20:05 d-------- c:\windows\system32\drivers\Avg
2008-11-19 17:05 . 2008-11-19 17:05 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-19 17:05 . 2008-11-19 17:05 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-19 16:50 . 2008-05-09 05:53 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll
2008-11-19 16:50 . 2008-05-09 05:53 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll
2008-11-19 16:50 . 2008-05-08 06:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe
2008-11-19 16:50 . 2008-05-09 18:23 135,168 -----c--- c:\windows\system32\dllcache\wshom.ocx
2008-11-19 16:50 . 2008-05-07 04:07 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe
2008-11-19 16:50 . 2008-05-09 05:53 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll
2008-11-19 16:25 . 2008-10-03 12:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-19 16:25 . 2007-04-17 04:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-19 16:25 . 2007-03-08 00:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-19 16:25 . 2008-08-26 02:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-19 16:25 . 2008-08-26 02:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-19 16:25 . 2008-08-26 02:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-19 16:25 . 2008-08-26 02:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-19 16:25 . 2008-08-26 02:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-19 16:25 . 2008-08-25 03:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-19 15:36 . 2008-04-13 19:12 1,306,624 -----c--- c:\windows\system32\dllcache\msxml6.dll
2008-11-19 15:36 . 2008-04-13 12:27 79,872 -----c--- c:\windows\system32\dllcache\msxml6r.dll
2008-11-19 15:35 . 2006-12-28 14:01 19,569 --a------ c:\windows\003184_.tmp
2008-11-19 15:24 . 2008-09-08 05:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-19 15:24 . 2008-06-13 06:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-19 15:24 . 2008-08-14 05:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-11-19 15:23 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-19 15:23 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-19 15:23 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-19 15:23 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-19 15:23 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-11-19 15:23 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-19 15:23 . 2008-05-01 09:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-11-19 15:23 . 2008-05-08 09:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-11-19 15:22 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-19 15:22 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-19 15:21 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-19 14:11 . 2008-11-19 14:11 1,396 --a------ c:\windows\system32\wpa.bak
2008-11-19 13:57 . 2008-04-13 19:11 482,304 --a--c--- c:\windows\system32\dllcache\pintlgnt.ime
2008-11-19 13:56 . 2004-08-04 07:00 10,096,640 --a--c--- c:\windows\system32\dllcache\hwxcht.dll
2008-11-19 13:55 . 2004-08-04 07:00 480,256 --a--c--- c:\windows\system32\dllcache\cintsetp.exe
2008-11-19 13:54 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-19 13:51 . 2004-08-04 07:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-11-19 13:44 . 2004-08-03 22:31 20,992 --a------ c:\windows\system32\drivers\RTL8139.sys
2008-11-19 13:37 . 2004-08-04 07:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-19 13:37 . 2004-08-04 07:00 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-19 13:37 . 2004-08-04 07:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-19 13:37 . 2004-08-04 07:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-11-19 13:36 . 2004-08-04 07:00 1,086,058 -ra------ c:\windows\SETC2.tmp
2008-11-19 13:36 . 2004-08-04 07:00 1,042,903 --a--c--- c:\windows\system32\dllcache\SP2.CAT
2008-11-19 13:36 . 2004-08-04 07:00 1,042,903 -ra------ c:\windows\SETBF.tmp
2008-11-19 13:36 . 2004-08-04 07:00 797,189 --a--c--- c:\windows\system32\dllcache\NT5IIS.CAT
2008-11-19 13:36 . 2004-08-04 07:00 399,645 --a--c--- c:\windows\system32\dllcache\MAPIMIG.CAT
2008-11-19 13:36 . 2004-08-04 07:00 37,484 --a--c--- c:\windows\system32\dllcache\MW770.CAT
2008-11-19 13:36 . 2004-08-04 07:00 13,753 -ra------ c:\windows\SETCE.tmp
2008-11-19 13:36 . 2004-08-04 07:00 13,472 --a--c--- c:\windows\system32\dllcache\HPCRDP.CAT
2008-11-19 13:36 . 2004-08-04 07:00 8,574 --a--c--- c:\windows\system32\dllcache\IASNT4.CAT
2008-11-19 13:36 . 2004-08-04 07:00 7,382 --a--c--- c:\windows\system32\dllcache\OEMBIOS.CAT
2008-11-19 13:36 . 2004-08-04 07:00 7,334 --a--c--- c:\windows\system32\dllcache\wmerrenu.cat
2008-11-19 11:50 . 2006-03-30 13:18 100,992 -ra------ c:\windows\system32\drivers\viamraid.sys
2008-11-19 11:49 . 2008-11-19 11:50 d-------- c:\program files\VIA
2008-11-19 11:49 . 2005-04-12 14:54 331,184 --a------ c:\windows\system32\difxapi.dll
2008-11-19 11:29 . 2008-11-19 12:31 d-------- c:\program files\ACW
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\scripting
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\en
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\bits
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\l2schemas
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Sonic RecordNow!
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Sonic
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Common Files\SureThing Shared
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Common Files\Sonic
2008-11-15 17:21 . 2008-11-15 17:21 d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-15 17:21 . 2008-11-15 17:21 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-14 00:54 . 2008-11-19 17:05 d-------- c:\documents and settings\All Users\Application Data\Avg8

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Thu Dec 11, 2008 1:31 am

Hello.
Please post the rest of the log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Thu Dec 11, 2008 1:37 am

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-12-11 00:56 --------- d-----w c:\documents and settings\Owner\Application Data\Xfire
2008-12-10 03:08 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 02:09 --------- d-----w c:\program files\Steam
2008-12-10 02:00 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-10 00:32 --------- d-----w c:\documents and settings\Owner\Application Data\Skype
2008-12-07 16:37 --------- d-----w c:\program files\Xfire
2008-12-03 04:01 --------- d-----w c:\program files\Common Files\Adobe
2008-12-02 01:49 --------- d-----w c:\program files\Java
2008-11-24 06:21 --------- d-----w c:\program files\Common Files\Apple
2008-11-22 03:56 --------- d-----w c:\documents and settings\Owner\Application Data\Ventrilo
2008-11-09 09:11 --------- d-----w c:\documents and settings\Owner\Application Data\PlayFirst
2008-11-09 09:11 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-02-18 04:40 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2003-09-25 07:37 73,598 -c--a-w c:\program files\Uninst.isu
1999-11-29 23:20 116,938 -c--a-r c:\program files\BUYTUTOR.EXE
1999-11-18 17:02 79,649 -c--a-r c:\program files\playlab.exe
1999-08-29 23:20 126,896 -c--a-r c:\program files\WINTUTOR.EXE
1999-08-29 23:09 107,100 -c--a-r c:\program files\TRBTUTOR.EXE
1999-08-28 16:20 6,151,092 -c--a-r c:\program files\photo.flc
1999-08-27 19:48 174,850 -c--a-r c:\program files\BUY.EXE
1999-08-10 17:29 21,079 -c--a-r c:\program files\COURSLAB.HLP
1999-06-29 20:46 117,216 -c--a-r c:\program files\PHOTO.EXE
1999-06-29 20:03 142,338 -c--a-r c:\program files\WINDIRS.EXE
1999-06-29 19:40 330,550 -c--a-r c:\program files\MNU256.BMP
1999-06-29 19:39 330,550 -c--a-r c:\program files\MNU2-256.BMP
1999-06-29 19:39 164,854 -c--a-r c:\program files\MNU2-16.BMP
1999-06-29 19:38 221,302 -c--a-r c:\program files\MNUHELP.BMP
1999-06-29 19:38 164,854 -c--a-r c:\program files\MNU16.BMP
1999-06-29 19:10 196,608 -c--a-r c:\program files\BUY.MDB
1999-06-29 19:10 128 -c--a-r c:\program files\BUY.LDB
1999-06-15 16:57 29,733 -c--a-r c:\program files\photo.ecs
1999-05-07 21:08 983,094 -c--a-r c:\program files\DOG.BMP
1999-05-03 20:22 312,578 -c--a-r c:\program files\TROUBLE.EXE
1999-05-01 22:02 308,278 -c--a-r c:\program files\WINDIR3.BMP
1999-05-01 22:01 308,278 -c--a-r c:\program files\WINDIR2.BMP
1999-05-01 22:01 308,278 -c--a-r c:\program files\WINDIR1.BMP
1999-04-29 22:14 912,663 -c--a-r c:\program files\KEYS.EXE
1999-04-29 22:08 93,813 -c--a-r c:\program files\AD8.PCX
1999-04-29 22:08 86,941 -c--a-r c:\program files\AD7.PCX
1999-04-29 22:08 329,736 -c--a-r c:\program files\AD10.PCX
1999-04-29 22:08 245,722 -c--a-r c:\program files\AD3.PCX
1999-04-29 22:08 235,011 -c--a-r c:\program files\AD6.PCX
1999-04-29 22:08 214,141 -c--a-r c:\program files\AD9.PCX
1999-04-29 22:08 197,816 -c--a-r c:\program files\AD1.PCX
1999-04-29 22:08 189,627 -c--a-r c:\program files\AD4.PCX
1999-04-29 22:08 165,069 -c--a-r c:\program files\AD2.PCX
1999-04-29 22:08 143,740 -c--a-r c:\program files\AD5.PCX
1998-05-05 23:05 128 -c--a-w c:\program files\System.ldb
1997-12-31 20:00 140,525 -c--a-r c:\program files\HTML.EXE
1997-11-19 22:34 6,969 -c--a-r c:\program files\perot.jpg
1997-11-19 22:33 8,878 -c--a-r c:\program files\MIR.JPG
1997-11-19 22:33 12,231 -c--a-r c:\program files\DOG.JPG
1997-11-19 22:33 10,757 -c--a-r c:\program files\WATRFALL.jpg
1997-11-19 22:31 9,160 -c--a-r c:\program files\CITY.JPG
1997-11-03 21:20 20,928 -c-ha-r c:\program files\HISTORY.GID
1997-10-29 19:41 2,369 -c--a-r c:\program files\INCOME.XLS
1997-10-24 15:07 125,744 -c--a-r c:\program files\EMTUTOR.EXE
1997-10-08 18:34 16,143 -c--a-r c:\program files\SHUTTLE.EXE
1997-10-06 19:22 182,024 -c--a-r c:\program files\MMTUTOR.EXE
1997-10-06 18:12 174,829 -c--a-r c:\program files\MMSOFT.EXE
1997-10-06 15:58 129,228 -c--a-r c:\program files\HTMTUTOR.EXE
1997-10-06 15:45 7,643,752 -c--a-r c:\program files\SHUTTLE.FLC
1997-10-05 16:37 10,433 -c--a-r c:\program files\SHUT06.PAG
1997-10-05 16:35 10,647 -c--a-r c:\program files\SHUT11.PAG
1997-10-05 16:31 41,738 -c--a-r c:\program files\SHUT16.PAG
1997-10-05 16:26 11,039 -c--a-r c:\program files\SHUT13.PAG
1997-10-05 16:21 50,514 -c--a-r c:\program files\SHUT12.PAG
1997-10-05 16:19 56,380 -c--a-r c:\program files\SHUT09.PAG
1997-10-05 16:18 10,371 -c--a-r c:\program files\SHUT07.PAG
1997-10-05 16:17 44,480 -c--a-r c:\program files\SHUT05.PAG
1997-10-05 16:12 32,963 -c--a-r c:\program files\SHUT02.PAG
1997-10-05 00:04 117,646 -c--a-r c:\program files\HISTORY.EXE
1997-10-03 22:23 175,934 -c--a-r c:\program files\WPTUTOR.EXE
1997-10-02 21:21 3,639 -c--a-r c:\program files\FILM.GIF
1997-10-02 20:50 10,296 -c--a-r c:\program files\LINCOLN.GIF
1997-10-02 03:24 623 -c--a-r c:\program files\LIFTOFF.MID
1997-10-02 02:31 2,446 -c--a-r c:\program files\MMINTRO.MID
1997-10-02 02:04 613 -c--a-r c:\program files\GODOWN.MID
1997-10-02 02:01 802 -c--a-r c:\program files\PANEL.MID
1997-10-02 02:01 170,170 -c--a-r c:\program files\MMINTRO.BMP
1997-10-02 01:25 523,030 -c--a-r c:\program files\MMWAVE.WAV
1997-09-30 21:13 75,722 -c--a-r c:\program files\MMBMP05.BMP
1997-09-30 21:13 75,722 -c--a-r c:\program files\MMBMP04.BMP
1997-09-30 21:12 150,442 -c--a-r c:\program files\MMBMP03.BMP
1997-09-30 21:11 150,442 -c--a-r c:\program files\MMBMP02.BMP
1997-09-30 21:10 448,146 -c--a-r c:\program files\MMBMP01.BMP
1997-09-30 19:17 50,278 -c--a-r c:\program files\MMBMP.BMP
1997-09-30 17:44 3,984,666 -c--a-r c:\program files\MM3D.FLC
1997-09-30 17:02 152,506 -c--a-r c:\program files\SHUT01.PAG
1997-09-30 16:41 54,777 -c--a-r c:\program files\SHUT15.PAG
1997-09-30 16:22 9,401 -c--a-r c:\program files\SHUT04.PAG
1997-09-29 18:49 12,958 -c--a-r c:\program files\MMVECT.WMF
1997-09-29 03:13 843,318 -c--a-r c:\program files\SHSCH4.BMP
1997-09-29 03:13 1,219,230 -c--a-r c:\program files\SHSCH5.BMP
1997-09-29 03:12 541,978 -c--a-r c:\program files\SHSCH3.BMP
1997-09-29 03:12 305,278 -c--a-r c:\program files\SHSCH2.BMP
1997-09-29 03:12 136,678 -c--a-r c:\program files\SHSCH1.BMP
1997-09-29 03:04 70,725 -c--a-r c:\program files\SHUT14.PAG
1997-09-29 03:04 41,329 -c--a-r c:\program files\SHUT17.PAG
2007-06-21 23:38 30,280 ----a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-06-21 23:38 79,432 ----a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-06-21 23:38 71,240 ----a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-06-21 23:38 140,872 ----a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-06-21 23:39 38,472 ----a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-06-21 23:39 46,664 ----a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-06-21 23:39 34,376 ----a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-06-21 23:39 685,640 ----a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-21 23:40 30,280 ----a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-08-29 44032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nwiz"="nwiz.exe" [2006-11-17 c:\windows\system32\nwiz.exe]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
"LTMSG"="LTMSG.exe" [2003-07-14 c:\windows\ltmsg.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-12-18 8720384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 05:50 40960 c:\program files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
backup=c:\windows\pss\Image Transfer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=c:\windows\pss\spamsubtract.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
--a--c--- 2002-06-22 09:27 69632 c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
--a------ 2003-06-02 13:25 270336 c:\program files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a--c--- 2002-12-02 22:56 40960 c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2004-08-20 15:51 118784 c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-10-23 18:51 233472 c:\program files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 10:24 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd.exe

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Thu Dec 11, 2008 1:38 am

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2006-01-13 02:14 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a--c--- 1998-05-07 18:04 52736 c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2007-03-05 12:57 1103480 c:\program files\IGN\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
--a------ 2007-05-17 13:45 279912 c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2006-01-17 12:03 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-18 20:47 8720384 c:\program files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
--a------ 2002-10-16 17:57 81920 c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a--c--- 2002-09-13 23:42 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a--c--- 2002-04-17 19:42 69632 c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-09 19:05 1410296 c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
--a------ 2003-08-19 01:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 02:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-10-16 05:19 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
--a------ 2007-04-10 16:46 709992 c:\windows\vVX1000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-03 18:02 36352 c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-10-18 20:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
--a------ 2005-07-15 16:48 479232 c:\program files\Google\Gmail Notifier\gnotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
--a------ 2003-07-14 10:52 40960 c:\windows\ltmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2006-03-02 07:22 577536 c:\windows\soundman.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Steam\\steamapps\\sailormrc\\day of defeat\\hl.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Steam\\steamapps\\sailormrc\\team fortress classic\\hl.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R0 $sys$cor;$sys$cor;c:\windows\system32\Drivers\$sys$cor.sys [2004-10-06 10368]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-19 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-19 231704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-01-15 24652]
S1 $sys$crater;$sys$crater;\??\c:\windows\System32\$sys$filesystem\crater.sys []
S3 asbp2poa;asbp2poa;\??\c:\docume~1\Owner\LOCALS~1\Temp\asbp2poa.sys []
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\DRIVERS\rt2500usb.sys [2005-06-26 79616]
S3 XDva007;XDva007;\??\c:\windows\system32\XDva007.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f08aaa0-b349-11dd-a88d-0018f8b12db5}]
\Shell\AutoRun\command - E:\StartPortableApps.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e933a0d2-b652-11dd-a89a-0018f8b12db5}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

*Newly Created Service* - GTNDIS5

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\b179fc54-b45c-41b3-a617-6cce8c2eff9c]
c:\windows\System32\qmqbodm.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Explorer_Run-skwc.exe - c:\windows\system\skwc.exe
Notify-NavLogon - (no file)
MSConfigStartUp-AAWTray - c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-ccRegVfy - c:\program files\Common Files\Symantec Shared\ccRegVfy.exe
MSConfigStartUp-KBD - c:\hp\KBD\KBD.EXE
MSConfigStartUp-Weather - c:\program files\AWS\WeatherBug\weather.exe
MSConfigStartUp-WT GameChannel - c:\program files\WildTangent\Apps\GameChannel.exe
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mSearch Bar =
uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
[You must be registered and logged in to see this link.]

c:\windows\Downloaded Program Files\TiControlClient.dll - c:\windows\Downloaded Program Files\TiClientCore.exe
c:\windows\Downloaded Program Files\TIClient.ocx
O16 -: {C9E2242D-DC05-4C54-9483-A5C90653F7BC}
[You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\TIClient.inf
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\qguk1mq2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [You must be registered and logged in to see this link.]

**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-10 20:03:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\Softex\OmniPass\opxpgina.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Softex\OmniPass\omniServ.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
**************************************************************************
Completion time: 2008-12-10 20:09:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-11 01:09:45

Pre-Run: 6,993,747,968 bytes free
Post-Run: 7,225,520,128 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin

465 --- E O F --- 2008-11-20 14:34:42

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Thu Dec 11, 2008 1:44 am

Hello. Bad news I'm afraid.

Your computer has multiple infections, including a backdoor. A backdoor gives intruders complete control of your computer, logs your keystrokes, steal personal information, etc.

You are strongly advised to do the following:

  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).

Do NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

Due to its backdoor functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS). However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

To help you understand more, please take some time to read the following articles:

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Thu Dec 11, 2008 2:09 am

lets try to do a clean up. I am taking care of the bank information along with the other stuff. So what is step one?

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Thu Dec 11, 2008 4:45 pm

Hello.

Now open a new notepad file.
Input this into the notepad file:

Driver::
$sys$cor
$sys$crater
Viewpoint Manager Service
asbp2poa

File::
c:\windows\system32\Drivers\$sys$cor.sys
c:\windows\System32\$sys$filesystem\crater.sys
c:\windows\System32\qmqbodm.exe

Folder::
c:\windows\System32\$sys$filesystem

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f08aaa0-b349-11dd-a88d-0018f8b12db5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e933a0d2-b652-11dd-a89a-0018f8b12db5}]
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\b179fc54-b45c-41b3-a617-6cce8c2eff9c]

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Fri Dec 12, 2008 12:57 am

ComboFix 08-12-09.03 - Owner 2008-12-11 19:37:19.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1007 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFscript.txt
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\System32\$sys$filesystem\crater.sys
c:\windows\system32\Drivers\$sys$cor.sys
c:\windows\System32\qmqbodm.exe
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
c:\windows\System32\$sys$filesystem
c:\windows\System32\$sys$filesystem\$sys$parking
c:\windows\System32\$sys$filesystem\DbgHelp.dll
c:\windows\System32\$sys$filesystem\lim.sys
c:\windows\System32\$sys$filesystem\oct.sys
c:\windows\System32\$sys$filesystem\Unicows.dll
c:\windows\system32\Drivers\$sys$cor.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\Legacy_$SYS$COR
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_$sys$cor
-------\Service_$sys$crater
-------\Service_asbp2poa
-------\Service_Viewpoint Manager Service
((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
2008-12-09 22:41 . 2008-12-09 22:41 d-------- c:\program files\Trend Micro
2008-12-07 11:43 . 2008-12-11 19:33 d--h----- C:\$AVG8.VAULT$
2008-12-01 20:48 . 2008-12-01 20:48 d-------- c:\program files\Yahoo!
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\program files\iTunes
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\program files\iPod
2008-11-24 01:21 . 2008-11-24 01:21 d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-24 01:21 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-11-24 01:21 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-24 00:20 . 2008-11-24 00:21 d-------- c:\program files\QuickTime
2008-11-21 22:55 . 2008-11-21 22:55 d-------- c:\program files\Ventrilo
2008-11-21 22:55 . 2008-11-21 22:55 d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-21 22:55 . 2008-11-21 22:55 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-11-20 23:14 . 2008-11-20 23:14 d-------- c:\program files\CCleaner
2008-11-20 15:44 . 2008-11-20 15:44 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-11-20 09:37 . 2008-11-20 09:37 d-------- C:\Intel
2008-11-20 09:37 . 2004-08-20 15:50 159,744 --a------ c:\windows\system32\igfxres.dll
2008-11-19 17:05 . 2008-12-11 19:33 d-------- c:\windows\system32\drivers\Avg
2008-11-19 17:05 . 2008-11-19 17:05 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-19 17:05 . 2008-11-19 17:05 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-19 16:50 . 2008-05-09 05:53 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll
2008-11-19 16:50 . 2008-05-09 05:53 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll
2008-11-19 16:50 . 2008-05-08 06:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe
2008-11-19 16:50 . 2008-05-09 18:23 135,168 -----c--- c:\windows\system32\dllcache\wshom.ocx
2008-11-19 16:50 . 2008-05-07 04:07 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe
2008-11-19 16:50 . 2008-05-09 05:53 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll
2008-11-19 16:25 . 2008-10-03 12:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-19 16:25 . 2007-04-17 04:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-19 16:25 . 2007-03-08 00:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-19 16:25 . 2008-08-26 02:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-19 16:25 . 2008-08-26 02:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-19 16:25 . 2008-08-26 02:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-19 16:25 . 2008-08-26 02:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-19 16:25 . 2008-08-26 02:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-19 16:25 . 2008-08-25 03:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-19 15:36 . 2008-04-13 19:12 1,306,624 -----c--- c:\windows\system32\dllcache\msxml6.dll
2008-11-19 15:36 . 2008-04-13 12:27 79,872 -----c--- c:\windows\system32\dllcache\msxml6r.dll
2008-11-19 15:35 . 2006-12-28 14:01 19,569 --a------ c:\windows\003184_.tmp
2008-11-19 15:24 . 2008-09-08 05:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-19 15:24 . 2008-06-13 06:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-19 15:24 . 2008-08-14 05:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-11-19 15:23 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-19 15:23 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-19 15:23 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-19 15:23 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-19 15:23 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-11-19 15:23 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-19 15:23 . 2008-05-01 09:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-11-19 15:23 . 2008-05-08 09:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-11-19 15:22 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-19 15:22 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-19 15:21 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-19 14:11 . 2008-11-19 14:11 1,396 --a------ c:\windows\system32\wpa.bak
2008-11-19 13:57 . 2008-04-13 19:11 482,304 --a--c--- c:\windows\system32\dllcache\pintlgnt.ime
2008-11-19 13:56 . 2004-08-04 07:00 10,096,640 --a--c--- c:\windows\system32\dllcache\hwxcht.dll
2008-11-19 13:55 . 2004-08-04 07:00 480,256 --a--c--- c:\windows\system32\dllcache\cintsetp.exe
2008-11-19 13:54 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-19 13:52 . 2008-11-19 13:52 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-19 13:51 . 2004-08-04 07:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-11-19 13:44 . 2004-08-03 22:31 20,992 --a------ c:\windows\system32\drivers\RTL8139.sys
2008-11-19 13:37 . 2004-08-04 07:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-19 13:37 . 2004-08-04 07:00 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-19 13:37 . 2004-08-04 07:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-19 13:37 . 2004-08-04 07:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-11-19 13:36 . 2004-08-04 07:00 1,086,058 -ra------ c:\windows\SETC2.tmp
2008-11-19 13:36 . 2004-08-04 07:00 1,042,903 --a--c--- c:\windows\system32\dllcache\SP2.CAT
2008-11-19 13:36 . 2004-08-04 07:00 1,042,903 -ra------ c:\windows\SETBF.tmp
2008-11-19 13:36 . 2004-08-04 07:00 797,189 --a--c--- c:\windows\system32\dllcache\NT5IIS.CAT
2008-11-19 13:36 . 2004-08-04 07:00 399,645 --a--c--- c:\windows\system32\dllcache\MAPIMIG.CAT
2008-11-19 13:36 . 2004-08-04 07:00 37,484 --a--c--- c:\windows\system32\dllcache\MW770.CAT
2008-11-19 13:36 . 2004-08-04 07:00 13,753 -ra------ c:\windows\SETCE.tmp
2008-11-19 13:36 . 2004-08-04 07:00 13,472 --a--c--- c:\windows\system32\dllcache\HPCRDP.CAT
2008-11-19 13:36 . 2004-08-04 07:00 8,574 --a--c--- c:\windows\system32\dllcache\IASNT4.CAT
2008-11-19 13:36 . 2004-08-04 07:00 7,382 --a--c--- c:\windows\system32\dllcache\OEMBIOS.CAT
2008-11-19 13:36 . 2004-08-04 07:00 7,334 --a--c--- c:\windows\system32\dllcache\wmerrenu.cat
2008-11-19 11:50 . 2006-03-30 13:18 100,992 -ra------ c:\windows\system32\drivers\viamraid.sys
2008-11-19 11:49 . 2008-11-19 11:50 d-------- c:\program files\VIA
2008-11-19 11:49 . 2005-04-12 14:54 331,184 --a------ c:\windows\system32\difxapi.dll
2008-11-19 11:29 . 2008-11-19 12:31 d-------- c:\program files\ACW
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\scripting
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\en
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\system32\bits
2008-11-19 10:00 . 2008-11-19 10:00 d-------- c:\windows\l2schemas
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Sonic RecordNow!
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Sonic
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Common Files\SureThing Shared
2008-11-18 18:26 . 2008-11-18 18:26 d-------- c:\program files\Common Files\Sonic
2008-11-15 17:21 . 2008-11-15 17:21 d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-15 17:21 . 2008-11-15 17:21 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-14 00:54 . 2008-11-19 17:05 d-------- c:\documents and settings\All Users\Application Data\Avg8

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Fri Dec 12, 2008 12:57 am

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-12-12 00:35 --------- d-----w c:\documents and settings\Owner\Application Data\Xfire
2008-12-11 05:52 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-11 04:17 --------- d-----w c:\program files\IGN
2008-12-11 04:17 --------- d-----w c:\documents and settings\Owner\Application Data\IGN_DLM
2008-12-11 04:12 --------- d-----w c:\program files\BitTorrent
2008-12-11 03:58 --------- d-----w c:\documents and settings\Owner\Application Data\Skype
2008-12-10 02:09 --------- d-----w c:\program files\Steam
2008-12-10 02:00 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-07 16:37 --------- d-----w c:\program files\Xfire
2008-12-03 04:01 --------- d-----w c:\program files\Common Files\Adobe
2008-12-02 01:49 --------- d-----w c:\program files\Java
2008-11-24 06:21 --------- d-----w c:\program files\Common Files\Apple
2008-11-22 03:56 --------- d-----w c:\documents and settings\Owner\Application Data\Ventrilo
2008-11-09 09:11 --------- d-----w c:\documents and settings\Owner\Application Data\PlayFirst
2008-11-09 09:11 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-02-18 04:40 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2003-09-25 07:37 73,598 -c--a-w c:\program files\Uninst.isu
1999-11-29 23:20 116,938 -c--a-r c:\program files\BUYTUTOR.EXE
1999-11-18 17:02 79,649 -c--a-r c:\program files\playlab.exe
1999-08-29 23:20 126,896 -c--a-r c:\program files\WINTUTOR.EXE
1999-08-29 23:09 107,100 -c--a-r c:\program files\TRBTUTOR.EXE
1999-08-28 16:20 6,151,092 -c--a-r c:\program files\photo.flc
1999-08-27 19:48 174,850 -c--a-r c:\program files\BUY.EXE
1999-08-10 17:29 21,079 -c--a-r c:\program files\COURSLAB.HLP
1999-06-29 20:46 117,216 -c--a-r c:\program files\PHOTO.EXE
1999-06-29 20:03 142,338 -c--a-r c:\program files\WINDIRS.EXE
1999-06-29 19:40 330,550 -c--a-r c:\program files\MNU256.BMP
1999-06-29 19:39 330,550 -c--a-r c:\program files\MNU2-256.BMP
1999-06-29 19:39 164,854 -c--a-r c:\program files\MNU2-16.BMP
1999-06-29 19:38 221,302 -c--a-r c:\program files\MNUHELP.BMP
1999-06-29 19:38 164,854 -c--a-r c:\program files\MNU16.BMP
1999-06-29 19:10 196,608 -c--a-r c:\program files\BUY.MDB
1999-06-29 19:10 128 -c--a-r c:\program files\BUY.LDB
1999-06-15 16:57 29,733 -c--a-r c:\program files\photo.ecs
1999-05-07 21:08 983,094 -c--a-r c:\program files\DOG.BMP
1999-05-03 20:22 312,578 -c--a-r c:\program files\TROUBLE.EXE
1999-05-01 22:02 308,278 -c--a-r c:\program files\WINDIR3.BMP
1999-05-01 22:01 308,278 -c--a-r c:\program files\WINDIR2.BMP
1999-05-01 22:01 308,278 -c--a-r c:\program files\WINDIR1.BMP
1999-04-29 22:14 912,663 -c--a-r c:\program files\KEYS.EXE
1999-04-29 22:08 93,813 -c--a-r c:\program files\AD8.PCX
1999-04-29 22:08 86,941 -c--a-r c:\program files\AD7.PCX
1999-04-29 22:08 329,736 -c--a-r c:\program files\AD10.PCX
1999-04-29 22:08 245,722 -c--a-r c:\program files\AD3.PCX
1999-04-29 22:08 235,011 -c--a-r c:\program files\AD6.PCX
1999-04-29 22:08 214,141 -c--a-r c:\program files\AD9.PCX
1999-04-29 22:08 197,816 -c--a-r c:\program files\AD1.PCX
1999-04-29 22:08 189,627 -c--a-r c:\program files\AD4.PCX
1999-04-29 22:08 165,069 -c--a-r c:\program files\AD2.PCX
1999-04-29 22:08 143,740 -c--a-r c:\program files\AD5.PCX
1998-05-05 23:05 128 -c--a-w c:\program files\System.ldb
1997-12-31 20:00 140,525 -c--a-r c:\program files\HTML.EXE
1997-11-19 22:34 6,969 -c--a-r c:\program files\perot.jpg
1997-11-19 22:33 8,878 -c--a-r c:\program files\MIR.JPG
1997-11-19 22:33 12,231 -c--a-r c:\program files\DOG.JPG
1997-11-19 22:33 10,757 -c--a-r c:\program files\WATRFALL.jpg
1997-11-19 22:31 9,160 -c--a-r c:\program files\CITY.JPG
1997-11-03 21:20 20,928 -c-ha-r c:\program files\HISTORY.GID
1997-10-29 19:41 2,369 -c--a-r c:\program files\INCOME.XLS
1997-10-24 15:07 125,744 -c--a-r c:\program files\EMTUTOR.EXE
1997-10-08 18:34 16,143 -c--a-r c:\program files\SHUTTLE.EXE
1997-10-06 19:22 182,024 -c--a-r c:\program files\MMTUTOR.EXE
1997-10-06 18:12 174,829 -c--a-r c:\program files\MMSOFT.EXE
1997-10-06 15:58 129,228 -c--a-r c:\program files\HTMTUTOR.EXE
1997-10-06 15:45 7,643,752 -c--a-r c:\program files\SHUTTLE.FLC
1997-10-05 16:37 10,433 -c--a-r c:\program files\SHUT06.PAG
1997-10-05 16:35 10,647 -c--a-r c:\program files\SHUT11.PAG
1997-10-05 16:31 41,738 -c--a-r c:\program files\SHUT16.PAG
1997-10-05 16:26 11,039 -c--a-r c:\program files\SHUT13.PAG
1997-10-05 16:21 50,514 -c--a-r c:\program files\SHUT12.PAG
1997-10-05 16:19 56,380 -c--a-r c:\program files\SHUT09.PAG
1997-10-05 16:18 10,371 -c--a-r c:\program files\SHUT07.PAG
1997-10-05 16:17 44,480 -c--a-r c:\program files\SHUT05.PAG
1997-10-05 16:12 32,963 -c--a-r c:\program files\SHUT02.PAG
1997-10-05 00:04 117,646 -c--a-r c:\program files\HISTORY.EXE
1997-10-03 22:23 175,934 -c--a-r c:\program files\WPTUTOR.EXE
1997-10-02 21:21 3,639 -c--a-r c:\program files\FILM.GIF
1997-10-02 20:50 10,296 -c--a-r c:\program files\LINCOLN.GIF
1997-10-02 03:24 623 -c--a-r c:\program files\LIFTOFF.MID
1997-10-02 02:31 2,446 -c--a-r c:\program files\MMINTRO.MID
1997-10-02 02:04 613 -c--a-r c:\program files\GODOWN.MID
1997-10-02 02:01 802 -c--a-r c:\program files\PANEL.MID
1997-10-02 02:01 170,170 -c--a-r c:\program files\MMINTRO.BMP
1997-10-02 01:25 523,030 -c--a-r c:\program files\MMWAVE.WAV
1997-09-30 21:13 75,722 -c--a-r c:\program files\MMBMP05.BMP
1997-09-30 21:13 75,722 -c--a-r c:\program files\MMBMP04.BMP
1997-09-30 21:12 150,442 -c--a-r c:\program files\MMBMP03.BMP
1997-09-30 21:11 150,442 -c--a-r c:\program files\MMBMP02.BMP
1997-09-30 21:10 448,146 -c--a-r c:\program files\MMBMP01.BMP
1997-09-30 19:17 50,278 -c--a-r c:\program files\MMBMP.BMP
1997-09-30 17:44 3,984,666 -c--a-r c:\program files\MM3D.FLC
1997-09-30 17:02 152,506 -c--a-r c:\program files\SHUT01.PAG
1997-09-30 16:41 54,777 -c--a-r c:\program files\SHUT15.PAG
1997-09-30 16:22 9,401 -c--a-r c:\program files\SHUT04.PAG
1997-09-29 18:49 12,958 -c--a-r c:\program files\MMVECT.WMF
1997-09-29 03:13 843,318 -c--a-r c:\program files\SHSCH4.BMP
1997-09-29 03:13 1,219,230 -c--a-r c:\program files\SHSCH5.BMP
1997-09-29 03:12 541,978 -c--a-r c:\program files\SHSCH3.BMP
1997-09-29 03:12 305,278 -c--a-r c:\program files\SHSCH2.BMP
2007-06-21 23:38 30,280 ----a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-06-21 23:38 79,432 ----a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-06-21 23:38 71,240 ----a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-06-21 23:38 140,872 ----a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-06-21 23:39 38,472 ----a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-06-21 23:39 46,664 ----a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-06-21 23:39 34,376 ----a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-06-21 23:39 685,640 ----a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-21 23:40 30,280 ----a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Fri Dec 12, 2008 12:58 am

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-08-29 44032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nwiz"="nwiz.exe" [2006-11-17 c:\windows\system32\nwiz.exe]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
"LTMSG"="LTMSG.exe" [2003-07-14 c:\windows\ltmsg.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-12-18 8720384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 05:50 40960 c:\program files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
backup=c:\windows\pss\Image Transfer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=c:\windows\pss\spamsubtract.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
--a--c--- 2002-06-22 09:27 69632 c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
--a------ 2003-06-02 13:25 270336 c:\program files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a--c--- 2002-12-02 22:56 40960 c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2004-08-20 15:51 118784 c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-10-23 18:51 233472 c:\program files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 10:24 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2006-01-13 02:14 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a--c--- 1998-05-07 18:04 52736 c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
--a------ 2007-05-17 13:45 279912 c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2006-01-17 12:03 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-18 20:47 8720384 c:\program files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
--a------ 2002-10-16 17:57 81920 c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a--c--- 2002-09-13 23:42 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a--c--- 2002-04-17 19:42 69632 c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-09 19:05 1410296 c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
--a------ 2003-08-19 01:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 02:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-10-16 05:19 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
--a------ 2007-04-10 16:46 709992 c:\windows\vVX1000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-03 18:02 36352 c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-10-18 20:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
--a------ 2005-07-15 16:48 479232 c:\program files\Google\Gmail Notifier\gnotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
--a------ 2003-07-14 10:52 40960 c:\windows\ltmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2006-03-02 07:22 577536 c:\windows\soundman.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Steam\\steamapps\\sailormrc\\day of defeat\\hl.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Steam\\steamapps\\sailormrc\\team fortress classic\\hl.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-19 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-19 231704]
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\DRIVERS\rt2500usb.sys [2005-06-26 79616]
S3 XDva007;XDva007;\??\c:\windows\system32\XDva007.sys []

Contents of the 'Scheduled Tasks' folder

2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
------- Supplementary Scan -------
uStart Page = [You must be registered and logged in to see this link.]
mSearch Bar =
uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
[You must be registered and logged in to see this link.]

c:\windows\Downloaded Program Files\TiControlClient.dll - c:\windows\Downloaded Program Files\TiClientCore.exe
c:\windows\Downloaded Program Files\TIClient.ocx
O16 -: {C9E2242D-DC05-4C54-9483-A5C90653F7BC}
[You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\TIClient.inf
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\qguk1mq2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [You must be registered and logged in to see this link.]
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-11 19:42:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0
**************************************************************************
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\Softex\OmniPass\opxpgina.dll
------------------------ Other Running Processes ------------------------
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Softex\OmniPass\omniServ.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
**************************************************************************
Completion time: 2008-12-11 19:48:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-12 00:48:12
ComboFix2.txt 2008-12-11 06:00:22
ComboFix3.txt 2008-12-11 01:10:02

Pre-Run: 7,147,167,744 bytes free
Post-Run: 7,135,576,064 bytes free

445 --- E O F --- 2008-11-20 14:34:42

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Fri Dec 12, 2008 1:18 am

Looks clean now, what problems remain?

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:

  • Download the latest version of [You must be registered and logged in to see this link.].
  • Select the first option where it says "Java SE Runtime Environment (JRE) 6 Update 11".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add or Remove Programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    - Java 2 Runtime Environment, SE v1.4.2
    - J2SE Runtime Environment 5.0
    - J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe that you downloaded to install the newest version.
Please make sure the new version of Java is installed before you run JavaRa.

Please download JavaRa from [You must be registered and logged in to see this link.]

  • First, unzip it.
  • Then run JavaRa.
  • Select English from the drop down menu and press Select.
  • This will open JavaRa.
  • Press Remove older versions
  • Press yes to the prompt.
  • It will make a log file of what it's removed.
  • Copy and paste the log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Fri Dec 12, 2008 2:44 am

I have Java(TM) 6 Update 7 Should i remove that too?
Internet is loading fine. AVG is still working. Before the Resident Shield kept saying it was inactive.
No pop ups so far saying a virus or threats have been found.

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Fri Dec 12, 2008 4:50 pm

Hello.
Yes, remove all older versions including 6u7 and install 6u11.
Then run JavaRa.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Sat Dec 13, 2008 4:04 am

My spybot keeps showing registry entry changes.. do i keep denying them or allow the change? Should i turn this feature off since its from Spybot-SD Resident?

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Sat Dec 13, 2008 4:35 am

here is my log file
JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Fri Dec 12 23:33:33 2008

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Tue Dec 16, 2008 5:05 am

hello?
Was i forgotten?

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Tue Dec 16, 2008 6:08 pm

Hello.
No you haven't.
I have a busy life with college and can't answer straight away sometimes, so give me atleast 24hrs and you'll get a reply.

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.


Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to [You must be registered and logged in to see this link.] and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

[You must be registered and logged in to see this link.]
A tutorial on using Ad-Aware to remove spyware from your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using Spybot to remove spyware from your computer may be found [You must be registered and logged in to see this link.]. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

[You must be registered and logged in to see this link.]
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found [You must be registered and logged in to see this link.].

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
[You must be registered and logged in to see this link.]
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

5) Finally, consider maintaining a firewall. Some good free firewalls are [You must be registered and logged in to see this link.], or
[You must be registered and logged in to see this link.]
A tutorial on understanding and using firewalls may be found [You must be registered and logged in to see this link.].

Please also read Tony Klein's excellent article: [You must be registered and logged in to see this link.]

Hopefully this should take care of your problems! Good luck. Big Grin


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Wed Dec 17, 2008 2:25 am

Oh great. Thank you so much for all your help
If i have a question about my hijackthis log, can i post it here?
I was checking it out and it seemed i had a lot of unnecessary items but i didnt' want to fix anything since i dont know if its good or not.
Could I post it 1 more time?

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Wed Dec 17, 2008 2:45 pm

Sure.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Sat Dec 20, 2008 12:32 am

sorry for the delay. Here is my hijackthis log as of today and my uninstall programs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:19 PM, on 12/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LifeCam] "c:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Yahoo! Fleet - [You must be registered and logged in to see this link.]
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - [You must be registered and logged in to see this link.]
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {C9E2242D-DC05-4C54-9483-A5C90653F7BC} (TIClientControl Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - [You must be registered and logged in to see this link.]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
End of file - 8859 bytes

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Sat Dec 20, 2008 12:34 am

ABBYY FineReader 5.0 Sprint
Ad-Aware
Adobe Flash Player ActiveX
Adobe Reader 8.1.3
Adobe Shockwave Player
AIM 6
Apple Mobile Device Support
Apple Software Update
ArcSoft Picture Software
AVG Free 8.0
Bonjour
CCleaner (remove only)
Citrix Presentation Server Client - Web Only
Counter-Strike
Day of Defeat
Dell AIO Printer A920
Diet Analysis Plus 7.0.1
FaxTools
Google Gmail Notifier
HijackThis 2.0.2
hp deskjet 5600
HP Deskjet printer preloaded drivers
HP Digital Imaging Album Printing 1.0
HP Instant Support
HP Memories Disc
HP Photo and Imaging 1.2 - Photosmart Cameras
HP Photo and Imaging 2.0 - Deskjet Series
HP Photosmart printers preloaded drivers
hp print screen utility
Image Transfer
Intel(R) Extreme Graphics 2 Driver
InterActual Player
InterVideo WinDVD Player
iTunes
Java(TM) 6 Update 11
Lernout & Hauspie TruVoice American English TTS Engine
Linksys Wireless-G PCI Adapter
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft LifeCam
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch® Jukebox
MySpaceIM
New Perspectives Course Labs
NP on Microsoft Windows 2000 -- Level I MSD
NVIDIA Drivers
OmniPass
PC-Doctor for Windows
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QuickTime
RealPlayer
Realtek AC'97 Audio
S3Display
S3Gamma2
S3Info2
S3Overlay
ShowBiz DVD
Simple Backup for My Pictures
Simple Installer - Multilanguage Version
Skype™ 3.8
Sonic RecordNow!
Sonic Update Manager
Sony USB Driver
Spybot - Search & Destroy
SpywareGuard v2.2
Steam
Team Fortress Classic
toolkit
Updates from HP
Ventrilo Client
VIA Platform Device Manager
VideoLAN VLC media player 0.8.6
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WexTech AnswerWorks
Winamp
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinZip
WordPerfect Productivity Pack
Xfire (remove only)

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Belahzur on Sat Dec 20, 2008 12:43 am

Hello.
Okay, lets disable un-needed stuff from startup.

I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes. So please disable TeaTimer by doing the following:
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
You can reenable TeaTimer once your system is clean.

Please make sure Teatimer is disable before we do this, otherwise this fix will fail.

I see you have Viewpoint Manager installed, this is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". Read this article: [You must be registered and logged in to see this link.]

Additional info: [You must be registered and logged in to see this link.]

I suggest you remove the program now.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Adobe Reader 8.1.3 <== outdated, uninstall this and I will provide the new version link
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar


Download the new Abode Reader 9 from here:
[You must be registered and logged in to see this link.]
=====


  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe


  • Press "Fix Checked"
  • Close Hijack This.


Your startup should be noticeably faster.
Re-enable TeaTimer.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by SailorMRC on Sat Dec 20, 2008 2:31 am

thank you so so much for all your help.
I hope i do not get anymore problems and be virus-free
Again thank you for all your help
Happy Holidays!

SailorMRC
Novice
Novice

Status :
Online
Offline

Posts : 19
Joined : 2008-12-10
Gender : Female
OS : Windows XP

View user profile

Back to top Go down

Solved Re: Trojan.Zlob.G HELP please :(

Post by Doctor Inferno on Sat Jan 24, 2009 10:14 am

Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Status :
Online
Offline

Posts : 12017
Joined : 2007-12-26
Gender : Male
OS : Windows 7 Home Premium and Ultimate X64

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum