Page 1 of 3 123 LastLast
Results 1 to 10 of 21

Thread: Help!! Infected laptop

  1. #1
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default Help!! Infected laptop

    Unfortunatley, I used my thumb drive to transfer my english work from the computer at my university- to my personal laptop- bad idea I guess... I cannot update or download any type of A/v or ssd...When I try to have Spybot update automatically- It gives me an error. Every time I try to get to the safer-networking.net website, or any A/V related site- I get a connection error- both through firefox and IE. I am not farmilliar with treating any mallware... Please help- I will need pleanty of instructions-Sorry!

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi there,

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.


    Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default

    Here are the logs

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/25/2006 12:27:21 PM
    System Uptime: 9/8/2009 10:38:01 PM (1 hours ago)

    Motherboard: Wistron | | 30B5
    Processor: AMD Turion(tm) 64 X2 | U1 | 1607/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 75 GiB total, 20.598 GiB free.
    D: is CDROM ()
    E: is CDROM (CDFS)
    F: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    µTorrent
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.3
    Adobe Shockwave Player
    Apple Mobile Device Support
    Apple Software Update
    AutoUpdate
    Broadcom 802.11 Wireless LAN Adapter
    BufferChm
    Conexant HD Audio
    D1300
    D1300_Help
    Dell Printer Software Uninstall
    DeviceManagementQFolder
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    EdNet
    eSupportQFolder
    Gopher 2003
    HDAUDIO Soft Data Fax Modem with SmartCP
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Imaging Device Functions 7.0
    HP Photosmart and Deskjet 7.0 Software
    HP Photosmart Essential
    HP Product Assistant
    HP Quick Launch Buttons 6.10 A2
    HP Solution Center 7.0
    HP Update
    HP Wireless Assistant 2.00 H1
    hph_ProductContext
    hph_readme
    hph_software
    hph_software_req
    HPPhotoSmartExpress
    HPProductAssistant
    InterBase 6.0
    iTunes
    Java(TM) 6 Update 11
    Java(TM) 6 Update 4
    K-Lite Codec Pack 2.71 Full
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft English TTS Engine
    Microsoft Office Professional Edition 2003
    Microsoft Streets & Trips 2007
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.13)
    MSN
    Netflix Movie Viewer
    NVIDIA Drivers
    PeerGuardian 2.0
    PowerDVD
    QuickTime
    RunAlyzer
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    SolutionCenter
    Spybot - Search & Destroy
    Status
    Synaptics Pointing Device Driver
    Toolbox
    TrayApp
    TTS Wrapper
    Unload
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver

    ==== Event Viewer Messages From Past Week ========

    9/5/2009 7:51:43 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    9/5/2009 7:09:19 PM, error: PlugPlayManager [12] - The device 'HL-DT-ST DVDRAM GSA-4084N' (IDE\CdRomHL-DT-ST_DVDRAM_GSA-4084N_______________KQ09____\304b363245373433303120302020202020202020) disappeared from the system without first being prepared for removal.
    9/5/2009 7:00:09 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the ddnsfilter service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    9/5/2009 6:59:09 PM, error: Service Control Manager [7031] - The ddnsfilter service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    9/4/2009 12:08:00 PM, error: Service Control Manager [7022] - The ddnsfilter service hung on starting.
    9/4/2009 12:07:42 PM, error: Service Control Manager [7023] - The Update Center service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    9/4/2009 12:07:42 PM, error: Service Control Manager [7000] - The HP Pci Information service failed to start due to the following error: The system cannot find the file specified.
    9/4/2009 11:47:36 AM, error: Service Control Manager [7028] - The helpService Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
    9/4/2009 11:36:25 AM, error: NetDDE [206] - Listen failed: 15:
    9/4/2009 11:36:13 AM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.
    9/4/2009 11:13:40 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    9/1/2009 9:52:05 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    ==== End Of File ====================





    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Erik at 23:50:13.44 on Tue 09/08/2009
    Internet Explorer: 6.0.2900.5512
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.515 [GMT -5:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k eapsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k dot3svc
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibserver.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Documents and Settings\Erik\Application Data\U3\000015424C60AC4C\LaunchPad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Erik\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [nwiz] nwiz.exe /install
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    StartupFolder: c:\documents and settings\all users\start menu\programs\startup\HP Digital Imaging Monitor.lnk.disabled
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\erik\applic~1\mozilla\firefox\profiles\zmynrlwf.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: network.proxy.http - none
    FF - prefs.js: network.proxy.type - 1

    ============= SERVICES / DRIVERS ===============

    R1 Filter;Filter;c:\windows\system32\drivers\Filter.sys [2009-8-31 37760]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-3-16 24652]
    S2 helpService;Update Center;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
    S2 pciinfo;HP Pci Information;\??\c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys --> c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys [?]
    S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\drivers\cbpmp50.sys --> c:\windows\system32\drivers\CBPMp50.sys [?]
    S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [2008-10-5 27072]

    =============== Created Last 30 ================

    2009-09-05 23:00 <DIR> --d----- c:\docume~1\erik\applic~1\Malwarebytes
    2009-09-05 23:00 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-05 23:00 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-09-05 23:00 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-09-05 23:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-09-05 20:34 <DIR> --d----- c:\program files\Safer Networking
    2009-09-05 19:57 127 a------- c:\windows\wininit.ini
    2009-09-05 18:59 128 a------- c:\windows\system32\drivers\kgpfr2.cfg
    2009-09-05 18:58 688 a------- c:\windows\system32\drivers\kgpcpy.cfg
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SITEguard
    2009-09-05 18:52 <DIR> --d----- c:\program files\common files\iS3
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
    2009-08-31 22:51 1 ----h--- c:\windows\ex23567.dat
    2009-08-31 22:51 1 a------- c:\windows\fdgg34353edfgdfdf
    2009-08-31 22:50 37,760 a------- c:\windows\system32\drivers\Filter.sys
    2009-08-31 22:50 <DIR> --d----- c:\program files\DDnsFilter
    2009-08-31 22:50 2 a------- c:\windows\0535251103110107106.yux
    2009-08-31 22:50 2 a------- c:\windows\0101120101464950.xe
    2009-08-31 22:50 1 ----h--- c:\windows\mmsmark2.dat
    2009-08-31 22:50 2 a------- c:\windows\0101120101464954.xe
    2009-08-31 22:48 2 a------- c:\windows\010112010146101105.te
    2009-08-16 16:17 <DIR> --d----- c:\docume~1\erik\applic~1\HpUpdate
    2009-08-16 16:17 <DIR> --d----- c:\windows\Hewlett-Packard

    ==================== Find3M ====================

    2008-12-10 19:44 3,340 a------- c:\program files\uninstal.log
    2009-03-16 21:11 108,544 a--shr-- c:\windows\system32\ulncaqh.dll

    ============= FINISH: 23:50:47.68 ===============






    *** I cannot get to the hyperlinked GMER site - I just get the same error in loading the page...

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent


    I'd like you to read this thread.

    Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).



    After that:


    Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
    • Run Spybot-S&D in Advanced Mode
    • If it is not already set to do this, go to the Mode menu
      select
      Advanced Mode
    • On the left hand side, click on Tools
    • Then click on the Resident icon in the list
    • Uncheck
      Resident TeaTimer
      and OK any prompts.
    • Restart your computer



    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds.txt log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default ComboFix reports

    ComboFix 09-09-09.04 - Erik 09/09/2009 20:37.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.580 [GMT -5:00]
    Running from: c:\documents and settings\Erik\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\DDnsFilter
    c:\windows\010112010146101105.te
    c:\windows\0101120101464950.xe
    c:\windows\0101120101464954.xe
    c:\windows\Installer\10a6e5.msi

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SfX


    ((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
    .

    2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\Erik\Application Data\Malwarebytes
    2009-09-06 04:00 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-06 04:00 . 2009-09-06 04:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-09-06 04:00 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-09-06 01:34 . 2009-09-06 01:34 -------- d-----w- c:\program files\Safer Networking
    2009-09-05 23:52 . 2009-09-06 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
    2009-09-05 23:52 . 2009-09-06 00:30 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
    2009-09-05 23:52 . 2009-09-05 23:52 -------- d-----w- c:\program files\Common Files\iS3
    2009-09-01 03:51 . 2009-09-01 03:51 1 ---h--w- c:\windows\ex23567.dat
    2009-09-01 03:50 . 2009-09-01 03:50 37760 ----a-w- c:\windows\system32\drivers\Filter.sys
    2009-09-01 03:50 . 2009-09-01 03:50 1 ---h--w- c:\windows\mmsmark2.dat
    2009-08-16 21:17 . 2009-08-16 21:18 -------- d-----w- c:\documents and settings\Erik\Application Data\HpUpdate
    2009-08-16 21:17 . 2009-08-16 21:17 -------- d-----w- c:\windows\Hewlett-Packard

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-10 01:01 . 2009-06-06 14:50 -------- d-----w- c:\documents and settings\Erik\Application Data\uTorrent
    2009-09-09 03:40 . 2006-12-06 00:46 -------- d-----w- c:\documents and settings\Erik\Application Data\U3
    2009-09-06 01:12 . 2008-03-27 23:30 -------- d-----w- c:\program files\LimeWire
    2009-09-06 01:04 . 2008-03-27 23:32 -------- d-----w- c:\documents and settings\Erik\Application Data\LimeWire
    2009-09-06 00:52 . 2006-12-01 08:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
    2009-09-06 00:32 . 2009-01-07 22:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-06 00:00 . 2009-09-05 23:58 688 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
    2009-09-05 23:59 . 2009-09-05 23:59 128 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
    2009-08-16 21:18 . 2007-03-19 19:39 -------- d-----w- c:\program files\HP
    2008-12-11 00:44 . 2008-12-11 00:44 3340 ----a-w- c:\program files\uninstal.log
    2009-03-17 02:11 . 2009-03-17 02:11 108544 --sha-r- c:\windows\system32\ulncaqh.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-15 7573504]
    "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-08-12 380928]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-07 136600]
    "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-15 1519616]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk.disabled [2007-3-19 1808]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
    "HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "39386:TCP"= 39386:TCP:DebugService 64Definitions
    "55520:UDP"= 55520:UDP:DebugService DistributionGallery
    "54561:UDP"= 54561:UDP:DebugService HelpProgram
    "14057:TCP"= 14057:TCP:DebugService SoftwareComponents
    "7213:TCP"= 7213:TCP:DebugService MobileLogs
    "26771:UDP"= 26771:UDP:DebugService ModemNET
    "50823:TCP"= 50823:TCP:DebugService InstallerSecurity
    "24867:UDP"= 24867:UDP:DebugService AgentApp
    "30444:UDP"= 30444:UDP:DebugService IMEReports
    "47434:TCP"= 47434:TCP:DebugService MicrosoftNET
    "27975:UDP"= 27975:UDP:DebugService AgentPLA
    "53939:TCP"= 53939:TCP:DebugService JavaOffline
    "30872:TCP"= 30872:TCP:DebugService PublishUS
    "30181:UDP"= 30181:UDP:DebugService WebUS
    "60788:UDP"= 60788:UDP:DebugService msdownldSoftware
    "18443:TCP"= 18443:TCP:DebugService PhotoGames
    "60935:TCP"= 60935:TCP:DebugService ZxTasks
    "52414:UDP"= 52414:UDP:DebugService JavaPages
    "33124:UDP"= 33124:UDP:DebugService ExplorerGlobalization
    "4306:TCP"= 4306:TCP:DebugService IntelIME
    "54609:TCP"= 54609:TCP:DebugService Softwareassembly
    "39544:UDP"= 39544:UDP:DebugService DebugExplorer
    "8085:TCP"= 8085:TCP:ddnsfilter
    "56495:UDP"= 56495:UDP:DebugService Serviceen
    "44629:TCP"= 44629:TCP:DebugService SecurityGames

    R1 Filter;Filter;c:\windows\system32\drivers\Filter.sys [8/31/2009 10:50 PM 37760]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/16/2007 10:28 AM 24652]
    S2 helpService;Update Center;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 12:56 AM 14336]
    S2 pciinfo;HP Pci Information;\??\c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
    S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
    S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [10/5/2008 4:36 PM 27072]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    ddnsfilter REG_MULTI_SZ ddnsfilter

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    helpService
    .
    Contents of the 'Scheduled Tasks' folder

    2009-09-06 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]

    2009-09-06 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-07 20:31]

    2009-09-06 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-01-07 20:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Erik\Application Data\Mozilla\Firefox\Profiles\zmynrlwf.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-SITEguard - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-09 20:44
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpService]
    "ServiceDll"="c:\windows\system32\ulncaqh.dll"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1177238915-1060284298-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(908)
    c:\windows\System32\BCMLogon.dll

    - - - - - - - > 'explorer.exe'(2768)
    c:\windows\system32\nview.dll
    c:\windows\system32\nvwddi.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\rundll32.exe
    c:\windows\system32\netdde.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\progra~1\borland\INTERB~1\Bin\ibguard.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\msiexec.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\progra~1\borland\INTERB~1\Bin\ibserver.exe
    c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
    c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-10 20:46 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-10 01:46

    Pre-Run: 22,014,828,544 bytes free
    Post-Run: 22,004,781,056 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
    [spybotsd]
    timeout.old=30

    185 --- E O F --- 2009-02-16 04:43

  6. #6
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default New dds logs

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/25/2006 12:27:21 PM
    System Uptime: 9/9/2009 8:43:27 PM (0 hours ago)

    Motherboard: Wistron | | 30B5
    Processor: AMD Turion(tm) 64 X2 | U1 | 1607/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 75 GiB total, 20.522 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 9/9/2009 8:34:57 PM - System Checkpoint

    ==== Installed Programs ======================

    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.3
    Adobe Shockwave Player
    Apple Mobile Device Support
    Apple Software Update
    AutoUpdate
    Broadcom 802.11 Wireless LAN Adapter
    BufferChm
    Conexant HD Audio
    D1300
    D1300_Help
    Dell Printer Software Uninstall
    DeviceManagementQFolder
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    EdNet
    eSupportQFolder
    Gopher 2003
    HDAUDIO Soft Data Fax Modem with SmartCP
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Imaging Device Functions 7.0
    HP Photosmart and Deskjet 7.0 Software
    HP Photosmart Essential
    HP Product Assistant
    HP Quick Launch Buttons 6.10 A2
    HP Solution Center 7.0
    HP Update
    HP Wireless Assistant 2.00 H1
    hph_ProductContext
    hph_readme
    hph_software
    hph_software_req
    HPPhotoSmartExpress
    HPProductAssistant
    InterBase 6.0
    iTunes
    Java(TM) 6 Update 11
    Java(TM) 6 Update 4
    K-Lite Codec Pack 2.71 Full
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft English TTS Engine
    Microsoft Office Professional Edition 2003
    Microsoft Streets & Trips 2007
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.13)
    MSN
    Netflix Movie Viewer
    NVIDIA Drivers
    PeerGuardian 2.0
    PowerDVD
    QuickTime
    RunAlyzer
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    SolutionCenter
    Spybot - Search & Destroy
    Status
    Synaptics Pointing Device Driver
    Toolbox
    TrayApp
    TTS Wrapper
    Unload
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver

    ==== Event Viewer Messages From Past Week ========

    9/9/2009 8:44:20 PM, error: Service Control Manager [7000] - The HP Pci Information service failed to start due to the following error: The system cannot find the path specified.
    9/9/2009 8:37:22 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    9/9/2009 8:35:16 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
    9/9/2009 8:35:16 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    9/5/2009 7:51:43 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    9/5/2009 7:09:19 PM, error: PlugPlayManager [12] - The device 'HL-DT-ST DVDRAM GSA-4084N' (IDE\CdRomHL-DT-ST_DVDRAM_GSA-4084N_______________KQ09____\304b363245373433303120302020202020202020) disappeared from the system without first being prepared for removal.
    9/5/2009 7:00:09 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the ddnsfilter service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    9/5/2009 6:59:09 PM, error: Service Control Manager [7031] - The ddnsfilter service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    9/5/2009 6:33:50 PM, error: Service Control Manager [7022] - The ddnsfilter service hung on starting.
    9/5/2009 6:32:27 PM, error: Service Control Manager [7023] - The Update Center service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    9/5/2009 6:32:27 PM, error: Service Control Manager [7000] - The HP Pci Information service failed to start due to the following error: The system cannot find the file specified.
    9/4/2009 11:47:36 AM, error: Service Control Manager [7028] - The helpService Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
    9/4/2009 11:36:25 AM, error: NetDDE [206] - Listen failed: 15:
    9/4/2009 11:36:13 AM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.
    9/4/2009 11:13:40 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

    ==== End Of File ===========================




    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Erik at 20:51:56.09 on Wed 09/09/2009
    Internet Explorer: 6.0.2900.5512
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.583 [GMT -5:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k eapsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k dot3svc
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibserver.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Erik\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [nwiz] nwiz.exe /install
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    StartupFolder: c:\documents and settings\all users\start menu\programs\startup\HP Digital Imaging Monitor.lnk.disabled
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\erik\applic~1\mozilla\firefox\profiles\zmynrlwf.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

    ============= SERVICES / DRIVERS ===============

    R1 Filter;Filter;c:\windows\system32\drivers\Filter.sys [2009-8-31 37760]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-3-16 24652]
    S2 helpService;Update Center;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
    S2 pciinfo;HP Pci Information;\??\c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys --> c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys [?]
    S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\drivers\cbpmp50.sys --> c:\windows\system32\drivers\CBPMp50.sys [?]
    S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [2008-10-5 27072]

    =============== Created Last 30 ================

    2009-09-09 20:36 <DIR> a-dshr-- C:\cmdcons
    2009-09-09 20:34 230,912 a------- c:\windows\PEV.exe
    2009-09-09 20:34 161,792 a------- c:\windows\SWREG.exe
    2009-09-09 20:34 98,816 a------- c:\windows\sed.exe
    2009-09-05 23:00 <DIR> --d----- c:\docume~1\erik\applic~1\Malwarebytes
    2009-09-05 23:00 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-05 23:00 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-09-05 23:00 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-09-05 23:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-09-05 20:34 <DIR> --d----- c:\program files\Safer Networking
    2009-09-05 19:57 127 a------- c:\windows\wininit.ini
    2009-09-05 18:59 128 a------- c:\windows\system32\drivers\kgpfr2.cfg
    2009-09-05 18:58 688 a------- c:\windows\system32\drivers\kgpcpy.cfg
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SITEguard
    2009-09-05 18:52 <DIR> --d----- c:\program files\common files\iS3
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
    2009-08-31 22:51 1 ----h--- c:\windows\ex23567.dat
    2009-08-31 22:51 1 a------- c:\windows\fdgg34353edfgdfdf
    2009-08-31 22:50 37,760 a------- c:\windows\system32\drivers\Filter.sys
    2009-08-31 22:50 2 a------- c:\windows\0535251103110107106.yux
    2009-08-31 22:50 1 ----h--- c:\windows\mmsmark2.dat
    2009-08-16 16:17 <DIR> --d----- c:\docume~1\erik\applic~1\HpUpdate
    2009-08-16 16:17 <DIR> --d----- c:\windows\Hewlett-Packard

    ==================== Find3M ====================

    2008-12-10 19:44 3,340 a------- c:\program files\uninstal.log
    2009-03-16 21:11 108,544 a--shr-- c:\windows\system32\ulncaqh.dll

    ============= FINISH: 20:52:16.25 ===============

  7. #7
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Are you familiar with these firewall port openings:
    "39386:TCP"= 39386:TCP:DebugService 64Definitions
    "55520:UDP"= 55520:UDP:DebugService DistributionGallery
    "54561:UDP"= 54561:UDP:DebugService HelpProgram
    "14057:TCP"= 14057:TCP:DebugService SoftwareComponents
    "7213:TCP"= 7213:TCP:DebugService MobileLogs
    "26771:UDP"= 26771:UDP:DebugService ModemNET
    "50823:TCP"= 50823:TCP:DebugService InstallerSecurity
    "24867:UDP"= 24867:UDP:DebugService AgentApp
    "30444:UDP"= 30444:UDP:DebugService IMEReports
    "47434:TCP"= 47434:TCP:DebugService MicrosoftNET
    "27975:UDP"= 27975:UDP:DebugService AgentPLA
    "53939:TCP"= 53939:TCP:DebugService JavaOffline
    "30872:TCP"= 30872:TCP:DebugService PublishUS
    "30181:UDP"= 30181:UDP:DebugService WebUS
    "60788:UDP"= 60788:UDP:DebugService msdownldSoftware
    "18443:TCP"= 18443:TCP:DebugService PhotoGames
    "60935:TCP"= 60935:TCP:DebugService ZxTasks
    "52414:UDP"= 52414:UDP:DebugService JavaPages
    "33124:UDP"= 33124:UDP:DebugService ExplorerGlobalization
    "4306:TCP"= 4306:TCP:DebugService IntelIME
    "54609:TCP"= 54609:TCP:DebugService Softwareassembly
    "39544:UDP"= 39544:UDP:DebugService DebugExplorer
    "56495:UDP"= 56495:UDP:DebugService Serviceen
    "44629:TCP"= 44629:TCP:DebugService SecurityGames


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    http://forums.spybot.info/showthread.php?p=335070#post335070
    Driver::
    Filter
    helpService
    Collect::
    c:\windows\ex23567.dat
    c:\windows\system32\drivers\Filter.sys
    c:\windows\mmsmark2.dat
    c:\windows\system32\ulncaqh.dll
    c:\windows\fdgg34353edfgdfdf
    c:\windows\0535251103110107106.yux
    Folder::
    c:\documents and settings\Erik\Application Data\uTorrent
    c:\program files\LimeWire
    c:\documents and settings\Erik\Application Data\LimeWire
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8085:TCP"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    "ddnsfilter"=-
    NetSvc::
    helpService

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. You'll be asked to submit samples.
    Then post the resultant log.


    Get update 8.1.6 for Adobe Reader here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Uninstall your current Adobe shockwave player and get the fresh one here if needed.

    Check here to see if your Flash is up-to-date (do it separately with each of your browsers). If not, uninstall vulnerable versions by following instructions here. Fresh version can be obtained here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 16.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u16-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.




    Download ATF (Atribune Temp File) Cleanerİ by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #8
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default New comboFix Reports

    ComboFix 09-09-10.03 - Erik 09/11/2009 7:01.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.553 [GMT -5:00]
    Running from: c:\documents and settings\Erik\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Erik\Desktop\CFScript.txt

    file zipped: c:\windows\ex23567.dat
    file zipped: c:\windows\fdgg34353edfgdfdf
    file zipped: c:\windows\mmsmark2.dat
    file zipped: c:\windows\system32\drivers\Filter.sys
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Erik\Application Data\LimeWire
    c:\documents and settings\Erik\Application Data\LimeWire\.NetworkShare\LimeWireWin4.16.6.exe
    c:\documents and settings\Erik\Application Data\LimeWire\bugs.data
    c:\documents and settings\Erik\Application Data\LimeWire\createtimes.cache
    c:\documents and settings\Erik\Application Data\LimeWire\fileurns.bak
    c:\documents and settings\Erik\Application Data\LimeWire\fileurns.cache
    c:\documents and settings\Erik\Application Data\LimeWire\filters.props
    c:\documents and settings\Erik\Application Data\LimeWire\gnutella.net
    c:\documents and settings\Erik\Application Data\LimeWire\installation.props
    c:\documents and settings\Erik\Application Data\LimeWire\library.dat
    c:\documents and settings\Erik\Application Data\LimeWire\limewire.props
    c:\documents and settings\Erik\Application Data\LimeWire\mojito.props
    c:\documents and settings\Erik\Application Data\LimeWire\questions.props
    c:\documents and settings\Erik\Application Data\LimeWire\responses.cache
    c:\documents and settings\Erik\Application Data\LimeWire\simpp.xml
    c:\documents and settings\Erik\Application Data\LimeWire\spam.dat
    c:\documents and settings\Erik\Application Data\LimeWire\tables.props
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme.lwtp
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\01_star.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\02_star.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\03_star.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\04_star.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\05_star.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\chat.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\dir_closed.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\dir_open.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\forward_dn.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\forward_up.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\kill.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\kill_on.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\lime.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\logo.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\notsearching.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\pause_dn.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\pause_up.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\play_dn.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\play_up.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\question.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\rewind_dn.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\rewind_up.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\searching.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\stop_dn.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\stop_up.gif
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\theme.txt
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\version.txt
    c:\documents and settings\Erik\Application Data\LimeWire\themes\limewirePro_theme\warning.gif
    c:\documents and settings\Erik\Application Data\LimeWire\ttrees.cache
    c:\documents and settings\Erik\Application Data\LimeWire\ttroot.cache
    c:\documents and settings\Erik\Application Data\LimeWire\version.xml
    c:\documents and settings\Erik\Application Data\LimeWire\xml\data\audio.sxml
    c:\documents and settings\Erik\Application Data\uTorrent
    c:\documents and settings\Erik\Application Data\uTorrent\dht.dat
    c:\documents and settings\Erik\Application Data\uTorrent\dht.dat.old
    c:\documents and settings\Erik\Application Data\uTorrent\resume.dat
    c:\documents and settings\Erik\Application Data\uTorrent\resume.dat.old
    c:\documents and settings\Erik\Application Data\uTorrent\rss.dat
    c:\documents and settings\Erik\Application Data\uTorrent\rss.dat.old
    c:\documents and settings\Erik\Application Data\uTorrent\settings.dat
    c:\documents and settings\Erik\Application Data\uTorrent\settings.dat.old
    c:\documents and settings\Erik\Application Data\uTorrent\utorrent.lng
    c:\documents and settings\Erik\Application Data\uTorrent\Winrar 3.80 Professional [blaze69].torrent
    c:\program files\LimeWire
    c:\program files\LimeWire\Thumbs.db
    c:\windows\0535251103110107106.yux
    c:\windows\ex23567.dat
    c:\windows\fdgg34353edfgdfdf
    c:\windows\mmsmark2.dat
    c:\windows\system32\drivers\Filter.sys
    c:\windows\system32\ulncaqh.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_FILTER
    -------\Legacy_HELPSERVICE
    -------\Service_Filter
    -------\Service_helpService


    ((((((((((((((((((((((((( Files Created from 2009-08-11 to 2009-09-11 )))))))))))))))))))))))))))))))
    .

    2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\Erik\Application Data\Malwarebytes
    2009-09-06 04:00 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-06 04:00 . 2009-09-06 04:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-06 04:00 . 2009-09-06 04:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-09-06 04:00 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-09-06 01:34 . 2009-09-06 01:34 -------- d-----w- c:\program files\Safer Networking
    2009-09-05 23:52 . 2009-09-06 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
    2009-09-05 23:52 . 2009-09-06 00:30 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
    2009-09-05 23:52 . 2009-09-05 23:52 -------- d-----w- c:\program files\Common Files\iS3
    2009-08-16 21:17 . 2009-08-16 21:18 -------- d-----w- c:\documents and settings\Erik\Application Data\HpUpdate
    2009-08-16 21:17 . 2009-08-16 21:17 -------- d-----w- c:\windows\Hewlett-Packard

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-10 12:59 . 2009-01-07 22:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-09 03:40 . 2006-12-06 00:46 -------- d-----w- c:\documents and settings\Erik\Application Data\U3
    2009-09-06 00:52 . 2006-12-01 08:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
    2009-09-06 00:00 . 2009-09-05 23:58 688 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
    2009-09-05 23:59 . 2009-09-05 23:59 128 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
    2009-08-16 21:18 . 2007-03-19 19:39 -------- d-----w- c:\program files\HP
    2008-12-11 00:44 . 2008-12-11 00:44 3340 ----a-w- c:\program files\uninstal.log
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-09-10_01.44.28 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-09-11 12:09 . 2009-09-11 12:09 16384 c:\windows\temp\Perflib_Perfdata_198.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-15 7573504]
    "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-08-12 380928]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-07 136600]
    "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-15 1519616]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk.disabled [2007-3-19 1808]

    SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
    @="Driver Group"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
    @="DiskDrive"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
    @="Hdc"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
    @="Keyboard"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
    @="Mouse"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
    @="System"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
    @="Volume"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
    "HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "39386:TCP"= 39386:TCP:DebugService 64Definitions
    "55520:UDP"= 55520:UDP:DebugService DistributionGallery
    "54561:UDP"= 54561:UDP:DebugService HelpProgram
    "14057:TCP"= 14057:TCP:DebugService SoftwareComponents
    "7213:TCP"= 7213:TCP:DebugService MobileLogs
    "26771:UDP"= 26771:UDP:DebugService ModemNET
    "50823:TCP"= 50823:TCP:DebugService InstallerSecurity
    "24867:UDP"= 24867:UDP:DebugService AgentApp
    "30444:UDP"= 30444:UDP:DebugService IMEReports
    "47434:TCP"= 47434:TCP:DebugService MicrosoftNET
    "27975:UDP"= 27975:UDP:DebugService AgentPLA
    "53939:TCP"= 53939:TCP:DebugService JavaOffline
    "30872:TCP"= 30872:TCP:DebugService PublishUS
    "30181:UDP"= 30181:UDP:DebugService WebUS
    "60788:UDP"= 60788:UDP:DebugService msdownldSoftware
    "18443:TCP"= 18443:TCP:DebugService PhotoGames
    "60935:TCP"= 60935:TCP:DebugService ZxTasks
    "52414:UDP"= 52414:UDP:DebugService JavaPages
    "33124:UDP"= 33124:UDP:DebugService ExplorerGlobalization
    "4306:TCP"= 4306:TCP:DebugService IntelIME
    "54609:TCP"= 54609:TCP:DebugService Softwareassembly
    "39544:UDP"= 39544:UDP:DebugService DebugExplorer
    "56495:UDP"= 56495:UDP:DebugService Serviceen
    "44629:TCP"= 44629:TCP:DebugService SecurityGames

    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/16/2007 10:28 AM 24652]
    S2 pciinfo;HP Pci Information;\??\c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Erik\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
    S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
    S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [10/5/2008 4:36 PM 27072]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-09-06 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]

    2009-09-10 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-07 20:31]

    2009-09-06 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-01-07 20:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Erik\Application Data\Mozilla\Firefox\Profiles\zmynrlwf.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-11 07:09
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1177238915-1060284298-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(904)
    c:\windows\System32\BCMLogon.dll

    - - - - - - - > 'explorer.exe'(3456)
    c:\windows\system32\nview.dll
    c:\windows\system32\nvwddi.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\rundll32.exe
    c:\windows\system32\netdde.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\progra~1\borland\INTERB~1\Bin\ibguard.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\msiexec.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\progra~1\borland\INTERB~1\Bin\ibserver.exe
    c:\windows\system32\wscntfy.exe
    c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
    c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    c:\windows\SoftwareDistribution\Download\bf65315470cb5ca5b60a434e42ef37a4\update\update.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-11 7:12 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-11 12:12
    ComboFix2.txt 2009-09-10 01:46

    Pre-Run: 22,001,467,392 bytes free
    Post-Run: 21,896,511,488 bytes free

    255 --- E O F --- 2009-02-16 04:43

  9. #9
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Did ComboFix show you instructions to submit malware samples during its run?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #10
    Junior Member
    Join Date
    Sep 2009
    Location
    Illinois
    Posts
    11

    Default

    I did not see any instructions on how to display samples...
    Here are the requested dds logs and the KAS log.




    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/25/2006 12:27:21 PM
    System Uptime: 9/11/2009 9:16:16 AM (5 hours ago)

    Motherboard: Wistron | | 30B5
    Processor: AMD Turion(tm) 64 X2 | U1 | 1607/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 75 GiB total, 20.081 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 9/9/2009 8:34:57 PM - System Checkpoint
    RP2: 9/11/2009 8:17:35 AM - System Checkpoint
    RP3: 9/11/2009 9:26:06 AM - Removed Java(TM) 6 Update 4

    ==== Installed Programs ======================

    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.3
    Apple Mobile Device Support
    Apple Software Update
    AutoUpdate
    Broadcom 802.11 Wireless LAN Adapter
    BufferChm
    Conexant HD Audio
    D1300
    D1300_Help
    Dell Printer Software Uninstall
    DeviceManagementQFolder
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    EdNet
    eSupportQFolder
    Google Toolbar for Internet Explorer
    Gopher 2003
    HDAUDIO Soft Data Fax Modem with SmartCP
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Imaging Device Functions 7.0
    HP Photosmart and Deskjet 7.0 Software
    HP Photosmart Essential
    HP Product Assistant
    HP Quick Launch Buttons 6.10 A2
    HP Solution Center 7.0
    HP Update
    HP Wireless Assistant 2.00 H1
    hph_ProductContext
    hph_readme
    hph_software
    hph_software_req
    HPPhotoSmartExpress
    HPProductAssistant
    InterBase 6.0
    iTunes
    Java(TM) 6 Update 11
    K-Lite Codec Pack 2.71 Full
    Malwarebytes' Anti-Malware
    McAfee Security Scan
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft English TTS Engine
    Microsoft Office Professional Edition 2003
    Microsoft Streets & Trips 2007
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.13)
    MSN
    Netflix Movie Viewer
    NVIDIA Drivers
    PeerGuardian 2.0
    PowerDVD
    QuickTime
    RunAlyzer
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    SolutionCenter
    Spybot - Search & Destroy
    Status
    Synaptics Pointing Device Driver
    Toolbox
    TrayApp
    TTS Wrapper
    Unload
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver

    ==== Event Viewer Messages From Past Week ========

    9/9/2009 8:44:20 PM, error: Service Control Manager [7000] - The HP Pci Information service failed to start due to the following error: The system cannot find the path specified.
    9/9/2009 8:37:22 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    9/9/2009 8:35:16 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
    9/9/2009 8:35:16 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    9/5/2009 8:12:07 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    9/5/2009 8:04:20 PM, error: Service Control Manager [7023] - The Update Center service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    9/5/2009 8:04:20 PM, error: Service Control Manager [7000] - The HP Pci Information service failed to start due to the following error: The system cannot find the file specified.
    9/5/2009 7:09:19 PM, error: PlugPlayManager [12] - The device 'HL-DT-ST DVDRAM GSA-4084N' (IDE\CdRomHL-DT-ST_DVDRAM_GSA-4084N_______________KQ09____\304b363245373433303120302020202020202020) disappeared from the system without first being prepared for removal.
    9/5/2009 7:00:09 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the ddnsfilter service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    9/5/2009 6:59:09 PM, error: Service Control Manager [7031] - The ddnsfilter service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    9/5/2009 6:58:30 PM, error: Service Control Manager [7022] - The ddnsfilter service hung on starting.
    9/4/2009 11:47:36 AM, error: Service Control Manager [7028] - The helpService Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
    9/4/2009 11:36:25 AM, error: NetDDE [206] - Listen failed: 15:
    9/4/2009 11:36:13 AM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.
    9/4/2009 11:13:40 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    9/11/2009 7:07:30 AM, error: PlugPlayManager [11] - The device Root\LEGACY_FILTER\0000 disappeared from the system without first being prepared for removal.

    ==== End Of File ===========================





    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Erik at 14:13:38.82 on Fri 09/11/2009
    Internet Explorer: 6.0.2900.5512
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.715 [GMT -5:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k eapsvcs
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k dot3svc
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\PROGRA~1\borland\INTERB~1\Bin\ibserver.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\DllHost.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Documents and Settings\Erik\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [nwiz] nwiz.exe /install
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /Get1noarp
    StartupFolder: c:\documents and settings\all users\start menu\programs\startup\HP Digital Imaging Monitor.lnk.disabled
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\erik\applic~1\mozilla\firefox\profiles\zmynrlwf.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\documents and settings\erik\application data\mozilla\firefox\profiles\zmynrlwf.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll

    ============= SERVICES / DRIVERS ===============

    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-3-16 24652]
    S2 pciinfo;HP Pci Information;\??\c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys --> c:\docume~1\erik\locals~1\temp\hpispz\hpdom\pciinfo.sys [?]
    S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\drivers\cbpmp50.sys --> c:\windows\system32\drivers\CBPMp50.sys [?]
    S3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [2008-10-5 27072]
    S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-4 14336]

    =============== Created Last 30 ================

    2009-09-11 07:49 <DIR> --d----- c:\documents and settings\erik\.SunDownloadManager
    2009-09-11 07:31 <DIR> --d----- c:\program files\McAfee Security Scan
    2009-09-11 07:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
    2009-09-09 20:36 <DIR> a-dshr-- C:\cmdcons
    2009-09-09 20:34 230,912 a------- c:\windows\PEV.exe
    2009-09-09 20:34 161,792 a------- c:\windows\SWREG.exe
    2009-09-09 20:34 98,816 a------- c:\windows\sed.exe
    2009-09-05 23:00 <DIR> --d----- c:\docume~1\erik\applic~1\Malwarebytes
    2009-09-05 23:00 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-05 23:00 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-09-05 23:00 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-09-05 23:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-09-05 20:34 <DIR> --d----- c:\program files\Safer Networking
    2009-09-05 19:57 127 a------- c:\windows\wininit.ini
    2009-09-05 18:59 128 a------- c:\windows\system32\drivers\kgpfr2.cfg
    2009-09-05 18:58 688 a------- c:\windows\system32\drivers\kgpcpy.cfg
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SITEguard
    2009-09-05 18:52 <DIR> --d----- c:\program files\common files\iS3
    2009-09-05 18:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
    2009-08-16 16:17 <DIR> --d----- c:\docume~1\erik\applic~1\HpUpdate
    2009-08-16 16:17 <DIR> --d----- c:\windows\Hewlett-Packard

    ==================== Find3M ====================

    2008-12-10 19:44 3,340 a------- c:\program files\uninstal.log

    ============= FINISH: 14:14:33.40 ===============




    KAS RESULTS:





    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Friday, September 11, 2009
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Friday, September 11, 2009 15:16:22
    Records in database: 2777257
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\

    Scan statistics:
    Objects scanned: 41945
    Threats found: 7
    Infected objects found: 7
    Suspicious objects found: 0
    Scan duration: 02:40:23


    File name / Threat / Threats count
    C:\Documents and Settings\Erik\Desktop\Unused Desktop Shortcuts\mstre21.exe Infected: Net-Worm.Win32.Koobface.blp 1
    C:\Documents and Settings\Erik\Desktop\Unused Desktop Shortcuts\pp11.exe Infected: Trojan.Win32.Small.ccd 1
    C:\Documents and Settings\Erik\Desktop\Unused Desktop Shortcuts\Setup.exe Infected: Backdoor.Win32.IRCBot.aro 1
    C:\Documents and Settings\Erik\Desktop\Unused Desktop Shortcuts\srpira1251777044.eXE Infected: Trojan-PSW.Win32.LdPinch.dis 1
    C:\Program Files\Mozilla Firefox\ftemp.exe Infected: Trojan-PSW.Win32.Koobface.a 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ulncaqh.dll.vir Infected: Trojan-Downloader.Win32.Kido.az 1
    C:\Qoobox\Quarantine\[4]-Submit_2009-09-11_07.01.35.zip Infected: Trojan.Win32.Agent.cvqo 1

    Selected area has been scanned.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •