|
|
|||||||
| Register | Projects | Blogs | FAQ | Search | Today's Posts | Mark Forums Read |
|
|
#31 |
|
Member
Join Date: Oct 2009
Posts: 35
|
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report Monday, November 2, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, November 02, 2009 22:52:39 Records in database: 3115681 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 76259 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:24:54 No threats found. Scanned area is clean. Selected area has been scanned. |
|
|
|
|
#32 |
|
Member
Join Date: Oct 2009
Posts: 35
|
DDS (Ver_09-10-26.01) - NTFSx86
Run by The Earl at 19:57:25.68 on Mon 11/02/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3838.2703 [GMT -6:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\AskBarDis\bar\bin\AskService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\MozyHome\mozybackup.exe C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\DellTPad\HidFind.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Dell\Dell Mobile Broadband\systray.exe C:\Program Files\DellTPad\Apntex.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\MozyHome\mozystat.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\DllHost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Java\jre6\bin\java.exe C:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\The Earl.LAPPY\My Documents\Download\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.drudgereport.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/ uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.32.0\gears.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: ZoneAlarm Spy Blocker Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [systray] c:\program files\dell\dell mobile broadband\systray.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [KADxMain] c:\windows\system32\KADxMain.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\theear~1.lap\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mozyho~1.lnk - c:\program files\mozyhome\mozystat.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - c:\program files\ultimatebet\UltimateBet.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.32.0\gears.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\theear~1.lap\applic~1\mozilla\firefox\profiles\7jk76vlv.default\ FF - prefs.js: browser.startup.homepage - www.drudgereport.com FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\google\google gears\firefox\lib\ff30\gears.dll FF - component: c:\program files\mozilla firefox\components\1328874.dll FF - plugin: c:\documents and settings\the earl.lappy\application data\mozilla\firefox\profiles\7jk76vlv.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-3-31 64288] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-14 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-14 108552] R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-9-30 54776] R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-8-24 464264] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-15 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-15 297752] R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [2008-8-5 92288] R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [2008-8-5 92288] S2 gupdate1c98be4da0db7ca;Google Update Service (gupdate1c98be4da0db7ca);c:\program files\google\update\GoogleUpdate.exe [2009-2-10 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1170768] S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\postgresql\8.3\bin\pg_ctl.exe [2008-6-9 65536] S3 ADM851X;ADM851X USB To Fast Ethernet Adapter; [x] S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-11 14336] S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2008-8-24 2077840] =============== Created Last 30 ================ 2009-11-03 00:04:51 1386496 ----a-w- c:\windows\system\MSVBVM60.DLL 2009-11-03 00:00:49 73728 ----a-w- c:\windows\system32\javacpl.cpl 2009-11-03 00:00:49 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-11-02 17:07:28 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan 2009-10-28 20:08:09 0 d-sha-r- C:\cmdcons 2009-10-28 20:05:58 98816 ----a-w- c:\windows\sed.exe 2009-10-28 20:05:58 77312 ----a-w- c:\windows\MBR.exe 2009-10-28 20:05:58 236544 ----a-w- c:\windows\PEV.exe 2009-10-28 20:05:58 161792 ----a-w- c:\windows\SWREG.exe 2009-10-26 18:39:13 47066 ----a-w- c:\windows\system32\ksc.nls 2009-10-26 18:38:57 57398 ----a-w- c:\windows\system32\dllcache\imjpdadm.exe 2009-10-25 19:18:20 0 d-----w- c:\program files\Trend Micro 2009-10-25 19:00:16 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-10-25 18:39:42 77312 ----a-w- c:\windows\system32\ztvunace26.dll 2009-10-25 18:39:42 75264 ----a-w- c:\windows\system32\unacev2.dll 2009-10-25 18:39:42 69632 ----a-w- c:\windows\system32\ztvcabinet.dll 2009-10-25 18:39:42 162304 ----a-w- c:\windows\system32\ztvunrar36.dll 2009-10-25 18:39:42 153088 ----a-w- c:\windows\system32\UNRAR3.dll 2009-10-25 18:39:40 0 d-----w- c:\program files\Trojan Remover 2009-10-25 18:39:40 0 d-----w- c:\docume~1\theear~1.lap\applic~1\Simply Super Software 2009-10-25 18:39:40 0 d-----w- c:\docume~1\alluse~1\applic~1\Simply Super Software 2009-10-19 16:12:01 24576 ----a-w- c:\windows\ACP50GUID.exe ==================== Find3M ==================== 2009-11-02 23:57:40 102684 ----a-w- c:\windows\system32\nvModes.dat 2009-10-26 18:36:45 4682183 ----a-w- c:\windows\fonts\HDZB_36.TTF 2009-09-23 12:55:23 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-09-14 18:04:28 54776 ----a-w- c:\windows\system32\drivers\mozy.sys 2009-09-11 14:03:37 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-11 14:03:37 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll 2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-04 20:45:26 58880 ------w- c:\windows\system32\dllcache\msasn1.dll 2009-09-03 09:17:47 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-08-29 08:08:21 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-08-29 08:08:17 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-08-28 10:28:59 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe 2009-08-28 10:28:59 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe 2009-08-27 05:18:44 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe 2009-08-27 05:18:41 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll 2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-26 08:16:37 247326 ------w- c:\windows\system32\dllcache\strmdll.dll 2009-08-24 18:33:08 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-08-18 04:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-15 19:23:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{F2F974A1-F546-4E82-A281-0E7F7650768E}.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{E9FA206A-ECB3-4D66-9D23-CD2D05D3F426}.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{A079443A-797B-4770-8568-9A14AB12E99D}.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{7CD7AAFF-55DF-45C7-917D-8392834DCA28}.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{6B17DE66-FFD5-4113-A398-941E5E61CEBB}.dll 2009-08-14 08:15:09 196608 ----a-w- C:\{43F97D4E-D4F7-466C-8E59-2B56E75CEB08}.dll 2009-08-13 15:16:05 512000 ----a-w- c:\windows\system32\dllcache\jscript.dll 2009-08-10 04:06:31 51716 ----a-w- c:\windows\system32\pdf995mon.dll 2009-08-10 04:06:31 249856 ----a-w- c:\windows\system32\pdfmona.dll 2009-08-07 01:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-08-07 01:23:46 215920 ----a-w- c:\windows\system32\muweb.dll 2009-08-07 00:24:18 327896 ----a-w- c:\windows\system32\dllcache\wucltui.dll 2009-08-07 00:24:18 209632 ----a-w- c:\windows\system32\dllcache\wuweb.dll 2009-08-07 00:24:10 35552 ----a-w- c:\windows\system32\dllcache\wups.dll 2009-08-07 00:24:06 53472 ----a-w- c:\windows\system32\dllcache\wuauclt.exe 2009-08-07 00:24:04 96480 ----a-w- c:\windows\system32\dllcache\cdm.dll 2009-08-07 00:23:54 575704 ----a-w- c:\windows\system32\dllcache\wuapi.dll 2009-08-07 00:23:46 1929952 ----a-w- c:\windows\system32\dllcache\wuaueng.dll 2009-08-05 23:55:44 192512 ----a-w- C:\{D2AFDFB0-FF1A-4E40-BBC3-030D4C568442}.dll 2009-08-05 23:55:22 86016 ----a-w- C:\{C7F0503A-FD83-45F4-B5CA-036018C2D351}.dll 2009-08-05 23:35:44 118784 ----a-w- C:\{DFFC1932-B3A2-4D62-996D-8A8D38CD9F4D}.dll 2009-08-05 23:35:38 77824 ----a-w- C:\{FDF70C8E-F9BC-4D4E-9400-659A4522642E}.dll 2009-08-05 09:11:47 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-05 09:11:47 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll ============= FINISH: 19:57:41.20 =============== -------------------- UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-10-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 8/14/2008 6:54:49 PM System Uptime: 11/2/2009 6:19:36 PM (1 hours ago) Motherboard: Dell Inc. | | 0HX767 Processor: Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz | Microprocessor | 1794/200mhz Processor: Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz | Microprocessor | 1794/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 109 GiB total, 74.682 GiB free. D: is FIXED (NTFS) - 112 GiB total, 111.709 GiB free. E: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP205: 8/26/2009 12:34:46 AM - System Checkpoint RP206: 8/26/2009 2:42:47 PM - Software Distribution Service 3.0 RP207: 8/29/2009 12:22:57 AM - Software Distribution Service 3.0 RP208: 8/30/2009 1:29:58 AM - System Checkpoint RP209: 8/31/2009 9:27:08 AM - System Checkpoint RP210: 8/31/2009 1:59:32 PM - Software Distribution Service 3.0 RP211: 9/1/2009 4:37:05 PM - System Checkpoint RP212: 9/3/2009 11:33:32 PM - System Checkpoint RP213: 9/5/2009 1:20:44 PM - Software Distribution Service 3.0 RP214: 9/6/2009 7:02:04 PM - System Checkpoint RP215: 9/7/2009 10:03:08 PM - System Checkpoint RP216: 9/8/2009 10:48:52 PM - System Checkpoint RP217: 9/13/2009 9:32:26 AM - System Checkpoint RP218: 9/13/2009 10:39:37 AM - Software Distribution Service 3.0 RP219: 9/14/2009 10:00:56 PM - System Checkpoint RP220: 9/15/2009 10:10:25 PM - Software Distribution Service 3.0 RP221: 9/19/2009 12:44:58 PM - System Checkpoint RP222: 9/21/2009 8:40:32 AM - System Checkpoint RP223: 9/21/2009 11:05:02 AM - Installed MozyHome Remote Backup RP224: 9/23/2009 9:36:30 AM - System Checkpoint RP225: 9/23/2009 9:03:08 PM - Software Distribution Service 3.0 RP226: 9/26/2009 9:42:12 PM - System Checkpoint RP227: 9/27/2009 10:54:58 PM - System Checkpoint RP228: 9/29/2009 2:12:49 PM - System Checkpoint RP229: 10/2/2009 12:14:34 AM - Software Distribution Service 3.0 RP230: 10/3/2009 1:41:43 AM - System Checkpoint RP231: 10/4/2009 6:10:52 PM - System Checkpoint RP232: 10/5/2009 10:03:28 AM - Avg8 Update RP233: 10/5/2009 10:04:35 AM - Avg8 Update RP234: 10/7/2009 11:04:54 AM - Avg8 Update RP235: 10/7/2009 11:31:32 AM - Software Distribution Service 3.0 RP236: 10/11/2009 7:29:48 PM - System Checkpoint RP237: 10/12/2009 10:20:47 PM - System Checkpoint RP238: 10/15/2009 7:13:11 PM - Software Distribution Service 3.0 RP239: 10/17/2009 2:12:21 PM - Avg8 Update RP240: 10/17/2009 9:28:15 PM - Software Distribution Service 3.0 RP241: 10/18/2009 9:33:37 PM - Software Distribution Service 3.0 RP242: 10/19/2009 11:11:56 AM - Removed TARGUS ACP50 RP243: 10/21/2009 11:02:59 AM - Avg8 Update RP244: 10/22/2009 1:20:48 PM - System Checkpoint RP245: 10/24/2009 12:30:17 AM - Software Distribution Service 3.0 RP246: 10/25/2009 11:56:14 AM - System Checkpoint RP247: 10/25/2009 4:13:34 PM - Software Distribution Service 3.0 RP248: 10/26/2009 9:21:04 PM - System Checkpoint RP249: 10/27/2009 10:27:02 PM - System Checkpoint RP250: 10/28/2009 9:35:09 AM - Software Distribution Service 3.0 RP251: 11/1/2009 2:51:47 AM - System Checkpoint RP252: 11/2/2009 4:09:23 PM - Removed Adobe Reader 8.1.0 RP253: 11/2/2009 4:14:47 PM - Installed Adobe Reader 9.2. RP254: 11/2/2009 4:18:04 PM - Removed Acrobat.com RP255: 11/2/2009 4:19:28 PM - Removed Adobe Reader 9.2. RP256: 11/2/2009 4:20:02 PM - Removed Java(TM) 6 Update 7 RP257: 11/2/2009 4:20:43 PM - Removed Java(TM) 6 Update 5 RP258: 11/2/2009 4:21:32 PM - Removed Java(TM) 6 Update 4 RP259: 11/2/2009 4:28:34 PM - Installed Adobe Reader 9.2. RP260: 11/2/2009 7:00:23 PM - Installed Java(TM) 6 Update 16 ==== Installed Programs ====================== Acrobat.com Ad-Aware Adobe AIR Adobe Download Manager Adobe Flash Player 10 Plugin Adobe Reader 9.2 AVG Free 8.5 Broadcom Management Programs Browser Address Error Redirector CCleaner (remove only) Compatibility Pack for the 2007 Office system Conexant HDA D330 MDC V.92 Modem Critical Update for Windows Media Player 11 (KB959772) Dell Mobile Broadband Card Utility Dell Support Center Dell Touchpad Digital Line Detect EPSON Printer Software ERUNT 1.1j Google Gears Google Talk (remove only) Google Update Helper GTA San Andreas High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Holdem Manager Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB908673) Hotfix for Windows XP (KB909095) Hotfix for Windows XP (KB909394) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB934428-v2) Hotfix for Windows XP (KB935448) Hotfix for Windows XP (KB937930) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) IntelliSonic Speech Enhancement Java(TM) 6 Update 16 MediaDirect Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft ActiveSync Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Corporation Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Basic 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Mikogo Modem Diagnostic Tool Mozilla Firefox (3.0.15) MozyHome Remote Backup MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) NetWaiting NVIDIA Drivers OpenOffice.org 3.0 OutlookAddinSetup Pdf995 PokerStars PostgreSQL 8.3 QuickSet RealPlayer Roxio Activation Module Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler 3 Roxio Update Manager SAMSUNG Mobile Modem Driver Set Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Skype™ 3.8 Sonic CinePlayer Decoder Pack Titan Quest Titan Quest Immortal Throne Trojan Remover 6.8.1 UltimateBet Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Outlook 2007 Junk Email Filter (KB974810) Update for Windows XP (KB894391) Update for Windows XP (KB896256) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) VC 9.0 Runtime Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WIDCOMM Bluetooth Software Windows Genuine Advantage Notifications (KB905474) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Live installer Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885855 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 XML Paper Specification Shared Components Pack 1.0 ZoneAlarm ZoneAlarm Spy Blocker Toolbar ==== Event Viewer Messages From Past Week ======== 11/2/2009 3:52:54 PM, error: Service Control Manager [7034] - The atisvc_vmuducuje service terminated unexpectedly. It has done this 1 time(s). 10/30/2009 9:45:45 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00226894CFB7. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 10/29/2009 6:43:18 PM, error: PSched [14103] - QoS [Adapter {E45B9DD2-7F6C-4436-9145-61070C7FEFC1}]: The netcard driver failed the query for OID_GEN_LINK_SPEED. 10/29/2009 11:02:06 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code. 10/28/2009 3:33:44 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired. 10/28/2009 3:10:08 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 10/28/2009 3:02:11 PM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 4 time(s). 10/28/2009 3:02:05 PM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 3 time(s). 10/28/2009 3:00:08 PM, error: Service Control Manager [7034] - The MozyHome Backup Service service terminated unexpectedly. It has done this 1 time(s). 10/28/2009 2:59:03 PM, error: Service Control Manager [7031] - The Bluetooth Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 10/28/2009 2:58:48 PM, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 10/28/2009 2:58:42 PM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 2 time(s). 10/28/2009 11:54:02 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG Free8 E-mail Scanner service to connect. 10/28/2009 11:54:02 AM, error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/28/2009 11:53:58 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 10/28/2009 11:53:58 AM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 10/27/2009 8:40:00 PM, error: Dhcp [1002] - The IP address lease 192.168.2.101 for the Network Card with network address 001D09DEF8B8 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message). ==== End Of File =========================== |
|
|
|
|
#33 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Hi,
Please look for a zip file that name begins as [4]-Submit in c:\qoobox\quarantine folder. Upload it here. Kindly include a link to this topic in the message.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#34 |
|
Member
Join Date: Oct 2009
Posts: 35
|
Uploaded.
|
|
|
|
|
#35 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Thanks for the submission.
Upload these files to Virustotal too and post back the results: c:\windows\system32\iepjb\Cache\S-1-5-21-3327107384-3502411607-1004678042-1005\Default\5672_432227921_1.cdf c:\windows\system32\iepjb\Cache\S-1-5-21-3327107384-3502411607-1004678042-1005\Default\5672_432227937_2.cdf c:\windows\system32\iepjb\Cache\S-1-5-21-3327107384-3502411607-1004678042-1005\Default\5224_432199703_368.cdf Do you still have same issues with IE?
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#36 |
|
Member
Join Date: Oct 2009
Posts: 35
|
Thank you very much for your help. IE does not appear to be starting itself anymore.
Here are the results from VirusTotal: File 5672_432227921_1.cdf received on 2009.11.03 20:36:54 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information... Your file is queued in position: 1. Estimated start time is between 43 and 62 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.41 2009.11.03 - AhnLab-V3 5.0.0.2 2009.11.03 - AntiVir 7.9.1.53 2009.11.03 - Antiy-AVL 2.0.3.7 2009.11.03 - Authentium 5.1.2.4 2009.11.03 - Avast 4.8.1351.0 2009.11.03 - AVG 8.5.0.423 2009.11.03 - BitDefender 7.2 2009.11.03 - CAT-QuickHeal 10.00 2009.11.03 - ClamAV 0.94.1 2009.11.03 - Comodo 2828 2009.11.03 - DrWeb 5.0.0.12182 2009.11.03 - eSafe 7.0.17.0 2009.11.03 - eTrust-Vet 35.1.7099 2009.11.03 - F-Prot 4.5.1.85 2009.11.03 - F-Secure 9.0.15370.0 2009.10.30 - Fortinet 3.120.0.0 2009.11.03 - GData 19 2009.11.03 - Ikarus T3.1.1.72.0 2009.11.03 - Jiangmin 11.0.800 2009.11.03 - K7AntiVirus 7.10.887 2009.11.03 - Kaspersky 7.0.0.125 2009.11.03 - McAfee 5791 2009.11.03 - McAfee+Artemis 5791 2009.11.03 - McAfee-GW-Edition 6.8.5 2009.11.03 - Microsoft 1.5202 2009.11.03 - NOD32 4570 2009.11.03 - Norman 6.03.02 2009.11.03 - nProtect 2009.1.8.0 2009.11.03 - Panda 10.0.2.2 2009.11.03 - PCTools 7.0.3.5 2009.11.03 - Prevx 3.0 2009.11.03 - Rising 21.54.14.00 2009.11.03 - Sophos 4.47.0 2009.11.03 - Sunbelt 3.2.1858.2 2009.11.02 - Symantec 1.4.4.12 2009.11.03 - TheHacker 6.5.0.2.059 2009.11.03 - TrendMicro 8.950.0.1094 2009.11.03 - VBA32 3.12.10.11 2009.11.03 - ViRobot 2009.11.3.2019 2009.11.03 - VirusBuster 4.6.5.0 2009.11.03 - Additional information File size: 936 bytes MD5...: 3840345df45c0af7e79ddbc424cf8364 SHA1..: a4ca0f8cca7db0989c36b286ff2cfb2a24af7492 SHA256: c1cac2310f083c7905f41b7262a3f5053d4eeb8b0abad4546f474435e1eceb1d ssdeep: 24:JzH96kDUNqUrB1fTRmo1BjxqAPZASt/lZgA:JzH9pIqM+CxhAmzl PEiD..: - PEInfo: - RDS...: NSRL Reference Data Set - pdfid.: - trid..: Unknown! sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned File 5672_432227937_2.cdf received on 2009.11.03 20:39:30 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information... Your file is queued in position: 1. Estimated start time is between 43 and 62 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.41 2009.11.03 - AhnLab-V3 5.0.0.2 2009.11.03 - AntiVir 7.9.1.53 2009.11.03 - Antiy-AVL 2.0.3.7 2009.11.03 - Authentium 5.1.2.4 2009.11.03 - Avast 4.8.1351.0 2009.11.03 - AVG 8.5.0.423 2009.11.03 - BitDefender 7.2 2009.11.03 - CAT-QuickHeal 10.00 2009.11.03 - ClamAV 0.94.1 2009.11.03 - Comodo 2828 2009.11.03 - DrWeb 5.0.0.12182 2009.11.03 - eSafe 7.0.17.0 2009.11.03 - eTrust-Vet 35.1.7099 2009.11.03 - F-Prot 4.5.1.85 2009.11.03 - F-Secure 9.0.15370.0 2009.10.30 - Fortinet 3.120.0.0 2009.11.03 - GData 19 2009.11.03 - Ikarus T3.1.1.72.0 2009.11.03 - Jiangmin 11.0.800 2009.11.03 - K7AntiVirus 7.10.887 2009.11.03 - Kaspersky 7.0.0.125 2009.11.03 - McAfee 5791 2009.11.03 - McAfee+Artemis 5791 2009.11.03 - McAfee-GW-Edition 6.8.5 2009.11.03 - Microsoft 1.5202 2009.11.03 - NOD32 4570 2009.11.03 - Norman 6.03.02 2009.11.03 - nProtect 2009.1.8.0 2009.11.03 - Panda 10.0.2.2 2009.11.03 - PCTools 7.0.3.5 2009.11.03 - Prevx 3.0 2009.11.03 - Rising 21.54.14.00 2009.11.03 - Sophos 4.47.0 2009.11.03 - Sunbelt 3.2.1858.2 2009.11.02 - Symantec 1.4.4.12 2009.11.03 - TheHacker 6.5.0.2.059 2009.11.03 - TrendMicro 8.950.0.1094 2009.11.03 - VBA32 3.12.10.11 2009.11.03 - ViRobot 2009.11.3.2019 2009.11.03 - VirusBuster 4.6.5.0 2009.11.03 - Additional information File size: 800 bytes MD5...: 2d014b836cb52dfc05871c8ca379b7af SHA1..: 765f01d0836bf9c637b3c7fdce69c09b55019cec SHA256: 86d7fdedcb9c3b79e812e8476129fd736184371466d4742059186ab505b2d028 ssdeep: 24:JzH96kDx298mlRzDuvmihDr/ktrkSUsxEvtR9v:JzH9pU2m/EhXktrDUsivB PEiD..: - PEInfo: - RDS...: NSRL Reference Data Set - pdfid.: - sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned trid..: Unknown! File 5224_432199703_368.cdf received on 2009.11.03 20:41:39 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information... Your file is queued in position: 2. Estimated start time is between 52 and 75 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.41 2009.11.03 - AhnLab-V3 5.0.0.2 2009.11.03 - AntiVir 7.9.1.53 2009.11.03 - Antiy-AVL 2.0.3.7 2009.11.03 - Authentium 5.1.2.4 2009.11.03 - Avast 4.8.1351.0 2009.11.03 - AVG 8.5.0.423 2009.11.03 - BitDefender 7.2 2009.11.03 - CAT-QuickHeal 10.00 2009.11.03 - ClamAV 0.94.1 2009.11.03 - Comodo 2828 2009.11.03 - DrWeb 5.0.0.12182 2009.11.03 - eSafe 7.0.17.0 2009.11.03 - eTrust-Vet 35.1.7099 2009.11.03 - F-Prot 4.5.1.85 2009.11.03 - F-Secure 9.0.15370.0 2009.10.30 - Fortinet 3.120.0.0 2009.11.03 - GData 19 2009.11.03 - Ikarus T3.1.1.72.0 2009.11.03 - Jiangmin 11.0.800 2009.11.03 - K7AntiVirus 7.10.887 2009.11.03 - Kaspersky 7.0.0.125 2009.11.03 - McAfee 5791 2009.11.03 - McAfee+Artemis 5791 2009.11.03 - McAfee-GW-Edition 6.8.5 2009.11.03 - Microsoft 1.5202 2009.11.03 - NOD32 4570 2009.11.03 - Norman 6.03.02 2009.11.03 - nProtect 2009.1.8.0 2009.11.03 - Panda 10.0.2.2 2009.11.03 - PCTools 7.0.3.5 2009.11.03 - Prevx 3.0 2009.11.03 - Rising 21.54.14.00 2009.11.03 - Sophos 4.47.0 2009.11.03 - Sunbelt 3.2.1858.2 2009.11.02 - Symantec 1.4.4.12 2009.11.03 - TheHacker 6.5.0.2.059 2009.11.03 - TrendMicro 8.950.0.1094 2009.11.03 - VBA32 3.12.10.11 2009.11.03 - ViRobot 2009.11.3.2019 2009.11.03 - VirusBuster 4.6.5.0 2009.11.03 - Additional information File size: 1080 bytes MD5...: 1a2c067ab2c22086a0809a34e497f897 SHA1..: 8170079456551690227a491b2f71ae0e85313cae SHA256: 3a7033a0c7e9895499cb68a3211a47f934f3ca9ae0e07a67b492a017b33d2789 ssdeep: 24:JzH96kDUNtgyWN6xLrCZs8Lm8A2yZrBWXbzKZirGPsB:JzH9pIihNCy/LfyZr Y/1SPsB PEiD..: - PEInfo: - RDS...: NSRL Reference Data Set - pdfid.: - trid..: Unknown! sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned |
|
|
|
|
#37 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Hi,
Delete c:\windows\system32\iepjb folder. Then let's see the final steps ![]() THESE STEPS ARE VERY IMPORTANT Let's reset system restore Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK. NOTE: only do this ONCE,NOT on a regular basis Now lets uninstall ComboFix:
Please download OTC and save it to desktop.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so. UPDATING WINDOWS AND INTERNET EXPLORER IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates. If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update. Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options. Click once on the Security tab Click once on the Internet icon so it becomes highlighted. Click once on the Custom Level button. Change the Download signed ActiveX controls to Prompt Change the Download unsigned ActiveX controls to Disable Change the Initialize and script ActiveX controls not marked as safe to Disable Change the Installation of desktop items to Prompt Change the Launching programs and files in an IFRAME to Prompt Change the Navigate sub-frames across different domains to Prompt When all these settings have been made, click on the OK button. If it prompts you as to whether or not you want to save the settings, press the Yes button. Next press the Apply button and then the OK to exit the Internet Properties page. The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
Just a final reminder for you. I am trying to stress these two points. UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks. Make sure all of your security programs are up to date. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates. Once again, please post and tell me how things are going with your system... problems etc. Have a great day, Blade
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#38 |
|
Member
Join Date: Oct 2009
Posts: 35
|
Thank you very much. I will let you know if I run into any more problems.
|
|
|
|
|
#39 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
You're welcome
![]() I'll leave the topic open for a few days.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#40 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.
![]() Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
| Thread Tools | |
| Display Modes | |
|
|