Win PC Antivirus

View previous topic View next topic Go down

Win PC Antivirus

Post by bronbron81 on Sun May 31, 2009 5:42 pm

I understand this is a rogue antivirus system that has infected my computer and I need some help getting rid of the program as well as the associated files.

Here is a Hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:46 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Melissa\Temporary Internet Files\Content.IE5\5E1ISUG0\HiJackThis[1].exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (no name) - {01E45C5E-5308-455E-8B01-F6A584957E69} - C:\WINDOWS\system32\urxdbrol.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WinInet Class - {39fc2065-c9c7-49cd-8942-44cc2dedc844} - C:\WINDOWS\ieocx.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {A500099D-A113-414D-A380-6A1AD5AB7F0A} - c:\windows\system32\llexrtn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVScan] C:\Documents and Settings\Melissa\Application Data\winav.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - [You must be registered and logged in to see this link.] Files\Elf Bowling 7 17 - The Last Insult\Images\stg_drm.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - [You must be registered and logged in to see this link.] Files\Elf Bowling 7 17 - The Last Insult\Images\armhelper.ocx
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ortkmcwh - C:\WINDOWS\SYSTEM32\llexrtn.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 13587 bytes

bronbron81
Intermediate
Intermediate

Posts Posts : 72
Joined Joined : 2009-03-02
OS OS : Window Xp Media center edition 2005
Points Points : 28626
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by Origin on Sun May 31, 2009 5:51 pm

WildTangent is a game software driver, some HP laptops come with it so users can play games, but in other cases, if no game are installed, uninstall the WildTangent Web Driver.

WildTangent uses pop-unders (not exactly pop-ups, but they both behave the same way).

The pop-unders themself may not be malicious, but this is considered adware, and plus clicking any pop-under leads the user to god knows where.

Please read here for more information about [You must be registered and logged in to see this link.]. Your choice if you want to remove it or not.

If you choose to follow my advice, please follow these instructions.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

  • WildTangent Web Driver




  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [You must be registered and logged in to see this link.]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = [You must be registered and logged in to see this link.]
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = [You must be registered and logged in to see this link.]
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,

    If you didnt set these host files fix them as well:

    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
    O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.download.com
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.pcmag.com
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.reevoo.com
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
    O1 - Hosts: 217.20.175.74 [You must be registered and logged in to see this link.]
    O1 - Hosts: 217.20.175.74 reviews.techradar.com

    O2 - BHO: (no name) - {01E45C5E-5308-455E-8B01-F6A584957E69} - C:\WINDOWS\system32\urxdbrol.dll
    O2 - BHO: (no name) - {A500099D-A113-414D-A380-6A1AD5AB7F0A} - c:\windows\system32\llexrtn.dll
    O20 - Winlogon Notify: ortkmcwh - C:\WINDOWS\SYSTEM32\llexrtn.dll
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe



  • Press "Fix Checked"
  • Close Hijack This.




1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See [You must be registered and logged in to see this link.] for how to disable your AV..

  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31483
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by bronbron81 on Mon Jun 01, 2009 7:04 pm

ComboFix 09-05-30.06 - Melissa 05/31/2009 22:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1.#QNAN.262 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Internet Explorer\msimg32.dll
c:\windows\IE4 Error Log.txt
c:\windows\ieocx.dll
c:\windows\system32\drivers\bnygwfzg.sys
c:\windows\system32\drivers\mbudccfv.sys
c:\windows\system32\drivers\UACkopargflxorwulk.sys
c:\windows\system32\llexrtn.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\rakzkld.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\UACbgdiviysapwwopw.log
c:\windows\system32\UACdhsjdefmshjhvmr.dll
c:\windows\system32\UACfdkmghbbtokamyc.log
c:\windows\system32\UAChnadufitipjduca.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACixrjoehiogkvsty.dll
c:\windows\system32\UAClltijtwykobmmra.log
c:\windows\system32\UACmyuktliqotrrprr.dat
c:\windows\system32\UACufcmqbtfqdtpcni.dll
c:\windows\system32\UACwsrjxboewsbgknp.dll
c:\windows\system32\urxdbrol.dll
c:\windows\Tasks\At1.job
D:\Autorun.inf
D:\Desktop.ini

----- BITS: Possible infected sites -----

[You must be registered and logged in to see this link.]
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys
-------\Legacy_MBUDCCFV
-------\Legacy_PKXHZVHS
-------\Service_mbudccfv
-------\Service_pkxhzvhs


((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.

2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\aebwsgmk
2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\documents and settings\Melissa\Application Data\asd.bat
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\docume~1\Melissa\APPLIC~1\asd.bat
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\documents and settings\Melissa\Application Data\winav.exe
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\docume~1\Melissa\APPLIC~1\winav.exe
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\documents and settings\Melissa\Application Data\LimeWire
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\LimeWire
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 01:30 . 2006-09-19 22:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-04-05 01:20 . 2007-11-05 23:10 -------- d--h--r- c:\documents and settings\All Users\Application Data\yahoo!
2009-04-05 01:20 . 2006-09-19 22:46 -------- d-----w- c:\program files\Yahoo!
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:31 . 2006-09-19 20:58 -------- d-----w- c:\program files\Java
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-08 08:34 . 2006-03-16 04:00 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2006-03-16 04:00 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2006-03-16 04:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2006-03-16 04:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2006-03-16 04:00 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2006-03-16 04:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2006-03-16 04:00 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2006-03-16 04:00 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2006-03-16 04:00 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2006-03-16 04:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-03-16 04:00 284160 ----a-w- c:\windows\system32\pdh.dll
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST
*NewlyCreated* - MBUDCCFV
*Deregistered* - mbudccfv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]

2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
- - - - ORPHANS REMOVED - - - -

BHO-{01E45C5E-5308-455E-8B01-F6A584957E69} - c:\windows\system32\urxdbrol.dll
BHO-{39fc2065-c9c7-49cd-8942-44cc2dedc844} - c:\windows\ieocx.dll
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-05-31 22:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????
scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1236)
c:\windows\system32\NTMARTA.DLL

- - - - - - - > 'explorer.exe'(4032)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\InstallShield\UpdateService\agent.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-01 22:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-01 02:58

Pre-Run: 36,952,145,920 bytes free
Post-Run: 38,129,074,176 bytes free

244 --- E O F --- 2009-05-14 02:59

bronbron81
Intermediate
Intermediate

Posts Posts : 72
Joined Joined : 2009-03-02
OS OS : Window Xp Media center edition 2005
Points Points : 28626
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by Belahzur on Mon Jun 01, 2009 7:15 pm

Hello.

I see that you are running Limewire.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

If Limewire is not removed, then I won't help you.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

  • Limewire 4.18.8

Now open a new notepad file.
Input this into the notepad file:

KILLALL::

Driver::
mbudccfv

File::
c:\documents and settings\Melissa\Application Data\asd.bat
c:\docume~1\Melissa\APPLIC~1\asd.bat
c:\documents and settings\Melissa\Application Data\winav.exe
c:\docume~1\Melissa\APPLIC~1\winav.exe

Folder::
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
c:\documents and settings\Melissa\Application Data\aebwsgmk
c:\docume~1\Melissa\APPLIC~1\aebwsgmk
c:\documents and settings\Melissa\Application Data\LimeWire
c:\docume~1\Melissa\APPLIC~1\LimeWire

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=-
"AntiVirusDisableNotify"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=-

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by bronbron81 on Sun Jun 14, 2009 11:43 pm

ComboFix 09-05-30.06 - Melissa 06/14/2009 19:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.173 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
"c:\docume~1\Melissa\APPLIC~1\asd.bat"
"c:\docume~1\Melissa\APPLIC~1\winav.exe"
"c:\documents and settings\Melissa\Application Data\asd.bat"
"c:\documents and settings\Melissa\Application Data\winav.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Melissa\APPLIC~1\aebwsgmk
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\profiles.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\docume~1\Melissa\APPLIC~1\asd.bat
c:\docume~1\Melissa\APPLIC~1\LimeWire
c:\docume~1\Melissa\APPLIC~1\LimeWire\active.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\certificate\limewire.keystore
c:\docume~1\Melissa\APPLIC~1\LimeWire\createtimes.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\downloads.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.bak
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\filters.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\gnutella.net
c:\docume~1\Melissa\APPLIC~1\LimeWire\installation.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\library.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\limewire.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\mojito.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\passive.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.backup
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.data
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.lck
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.log
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.properties
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.script
c:\docume~1\Melissa\APPLIC~1\LimeWire\questions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\responses.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\simpp.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\spam.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\tables.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme.lwtp
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\01_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\02_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\03_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\04_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\05_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\chat.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill_on.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\question.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\theme.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\version.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\warning.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttrees.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttroot.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\version.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\versions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\audio.sxml2
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\video.sxml2
c:\docume~1\Melissa\APPLIC~1\winav.exe
c:\documents and settings\Melissa\Application Data\aebwsgmk\profiles.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\documents and settings\Melissa\Application Data\asd.bat
c:\documents and settings\Melissa\Application Data\LimeWire\active.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Melissa\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Melissa\Application Data\LimeWire\downloads.dat
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Melissa\Application Data\LimeWire\filters.props
c:\documents and settings\Melissa\Application Data\LimeWire\gnutella.net
c:\documents and settings\Melissa\Application Data\LimeWire\installation.props
c:\documents and settings\Melissa\Application Data\LimeWire\library.dat
c:\documents and settings\Melissa\Application Data\LimeWire\limewire.props
c:\documents and settings\Melissa\Application Data\LimeWire\mojito.props
c:\documents and settings\Melissa\Application Data\LimeWire\passive.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Melissa\Application Data\LimeWire\questions.props
c:\documents and settings\Melissa\Application Data\LimeWire\responses.cache
c:\documents and settings\Melissa\Application Data\LimeWire\simpp.xml
c:\documents and settings\Melissa\Application Data\LimeWire\spam.dat
c:\documents and settings\Melissa\Application Data\LimeWire\tables.props
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Melissa\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Melissa\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Melissa\Application Data\LimeWire\version.xml
c:\documents and settings\Melissa\Application Data\LimeWire\versions.props
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Melissa\Application Data\winav.exe
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\urlclassifier3.sqlite
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\XPC.mfl

bronbron81
Intermediate
Intermediate

Posts Posts : 72
Joined Joined : 2009-03-02
OS OS : Window Xp Media center edition 2005
Points Points : 28626
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by bronbron81 on Sun Jun 14, 2009 11:44 pm

((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))
.

2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:34 . 2009-05-16 00:34 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2098-01-01 05:00 . 2007-12-25 15:18 9096 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\LUTPReg.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\WP20.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\IV20.dll
2098-01-01 05:00 . 2007-08-22 21:45 9048 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\FWLUReg.dll
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:29 . 2009-04-05 00:29 152576 ----a-w- c:\documents and settings\Melissa\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-14 23:26 . 2009-06-14 23:26 16384 c:\windows\temp\Perflib_Perfdata_4b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
*Deregistered* - YahooAUService

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]

2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-06-14 19:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????
scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4084)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-14 19:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-14 23:37
ComboFix2.txt 2009-06-01 02:59

Pre-Run: 37,993,279,488 bytes free
Post-Run: 37,949,100,032 bytes free

342 --- E O F --- 2009-05-14 02:59

bronbron81
Intermediate
Intermediate

Posts Posts : 72
Joined Joined : 2009-03-02
OS OS : Window Xp Media center edition 2005
Points Points : 28626
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win PC Antivirus

Post by Belahzur on Sun Jun 14, 2009 11:50 pm

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u



This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum