|
|
|||||||
| Register | Projects | Blogs | FAQ | Search | Today's Posts | Mark Forums Read |
|
|
#11 |
|
Junior Member
Join Date: Mar 2010
Posts: 8
|
Hi - here is the ComboFix log:
ComboFix 10-03-29.04 - P***** 03/31/2010 22:36:27.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.459 [GMT -4:00] Running from: c:\documents and settings\P******\Desktop\payzer2.exe AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} . ((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 ))))))))))))))))))))))))))))))) . 2010-03-31 03:41 . 2010-03-31 03:41 -------- d-----w- C:\HelpAsst_backup 2010-03-30 00:57 . 2010-03-30 00:57 5918720 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2010-03-21 14:46 . 2010-03-21 14:46 -------- d-----w- c:\program files\Trend Micro 2010-03-21 02:37 . 2010-03-21 02:38 -------- d-----w- c:\program files\ERUNT 2010-03-20 21:21 . 2010-03-20 21:21 -------- d--h--w- c:\windows\PIF 2010-03-10 02:22 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-31 02:55 . 2008-02-16 00:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-03-30 00:59 . 2010-01-15 18:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-29 19:24 . 2010-01-15 18:34 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-29 19:24 . 2010-01-15 18:34 20824 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-28 20:35 . 2006-12-15 14:33 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS 2010-03-10 03:18 . 2009-08-15 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-02-25 06:24 . 2006-04-30 06:56 916480 ----a-w- c:\windows\system32\wininet.dll 2010-02-24 14:16 . 2009-10-04 18:53 181632 ------w- c:\windows\system32\MpSigStub.exe 2010-02-08 02:28 . 2007-01-29 03:59 -------- d-----w- c:\program files\QuickTime 2010-02-07 02:24 . 2010-02-07 02:24 -------- d-----w- c:\documents and settings\P*****\Application Data\Intel 2010-02-07 02:23 . 2010-02-07 02:23 -------- d-----w- c:\program files\Intel 2010-02-07 02:23 . 2010-02-07 02:23 -------- d-----w- c:\program files\Common Files\Intel 2010-02-07 02:23 . 2010-02-07 02:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel 2010-02-06 17:46 . 2007-01-29 04:00 -------- d-----w- c:\documents and settings\P*****\Application Data\Apple Computer 2010-02-06 17:15 . 2010-02-06 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-06 17:15 . 2008-02-22 23:11 -------- d-----w- c:\program files\iTunes 2010-02-06 17:14 . 2010-02-06 17:14 -------- d-----w- c:\program files\iPod 2010-02-06 17:14 . 2008-02-14 01:54 -------- d-----w- c:\program files\Common Files\Apple 2010-02-06 16:59 . 2010-02-06 16:59 72488 ------w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-04 02:10 . 2010-02-04 02:10 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee 2010-02-04 02:09 . 2010-02-04 01:37 -------- d-----w- c:\program files\McAfee Security Scan 2010-02-04 01:37 . 2006-12-22 15:16 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2010-02-04 01:37 . 2010-02-04 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan 2010-01-20 03:39 . 2010-01-20 03:39 159112 ------w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-01-15 18:21 . 2010-01-15 18:21 69232 -c----w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT . ((((((((((((((((((((((((((((( SnapShot@2010-03-29_23.09.45 ))))))))))))))))))))))))))))))))))))))))) . + 2010-04-01 01:28 . 2010-04-01 01:28 16384 c:\windows\Temp\Perflib_Perfdata_1e0.dat - 2007-08-13 23:54 . 2009-12-21 19:14 55296 c:\windows\system32\msfeedsbs.dll + 2007-08-13 23:54 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll - 2006-04-30 06:55 . 2009-12-21 19:14 25600 c:\windows\system32\jsproxy.dll + 2006-04-30 06:55 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll + 2009-06-10 02:14 . 2010-02-25 06:24 12800 c:\windows\system32\dllcache\xpshims.dll - 2009-06-10 02:14 . 2009-12-21 19:14 12800 c:\windows\system32\dllcache\xpshims.dll + 2007-11-28 01:53 . 2010-02-25 06:24 55296 c:\windows\system32\dllcache\msfeedsbs.dll - 2007-11-28 01:53 . 2009-12-21 19:14 55296 c:\windows\system32\dllcache\msfeedsbs.dll - 2006-12-15 14:12 . 2009-12-21 19:14 25600 c:\windows\system32\dllcache\jsproxy.dll + 2006-12-15 14:12 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll + 2010-03-31 03:05 . 2009-12-21 19:14 12800 c:\windows\ie8updates\KB980182-IE8\xpshims.dll + 2010-03-31 03:05 . 2009-12-21 19:14 55296 c:\windows\ie8updates\KB980182-IE8\msfeedsbs.dll + 2010-03-31 03:05 . 2009-12-21 19:14 25600 c:\windows\ie8updates\KB980182-IE8\jsproxy.dll - 2006-04-30 06:55 . 2009-12-21 19:14 206848 c:\windows\system32\occache.dll + 2006-04-30 06:55 . 2010-02-25 06:24 206848 c:\windows\system32\occache.dll + 2006-04-30 06:55 . 2010-02-25 06:24 611840 c:\windows\system32\mstime.dll - 2006-04-30 06:55 . 2009-03-08 08:32 611840 c:\windows\system32\mstime.dll + 2007-08-13 23:54 . 2010-02-25 06:24 594432 c:\windows\system32\msfeeds.dll - 2007-08-13 23:54 . 2009-12-21 19:14 594432 c:\windows\system32\msfeeds.dll - 2006-04-30 06:55 . 2009-12-21 19:14 184320 c:\windows\system32\iepeers.dll + 2006-04-30 06:55 . 2010-02-25 06:24 184320 c:\windows\system32\iepeers.dll + 2006-04-30 06:55 . 2010-02-25 06:24 387584 c:\windows\system32\iedkcs32.dll - 2006-04-30 06:55 . 2009-12-21 19:14 387584 c:\windows\system32\iedkcs32.dll - 2006-04-30 06:55 . 2009-12-21 13:19 173056 c:\windows\system32\ie4uinit.exe + 2006-04-30 06:55 . 2010-02-24 09:54 173056 c:\windows\system32\ie4uinit.exe - 2006-12-15 14:12 . 2009-12-21 19:14 916480 c:\windows\system32\dllcache\wininet.dll + 2006-12-15 14:12 . 2010-02-25 06:24 916480 c:\windows\system32\dllcache\wininet.dll + 2007-08-13 23:44 . 2010-02-25 06:24 206848 c:\windows\system32\dllcache\occache.dll - 2007-08-13 23:44 . 2009-12-21 19:14 206848 c:\windows\system32\dllcache\occache.dll + 2006-12-15 14:12 . 2010-02-25 06:24 611840 c:\windows\system32\dllcache\mstime.dll - 2006-12-15 14:12 . 2009-03-08 08:32 611840 c:\windows\system32\dllcache\mstime.dll - 2007-11-28 01:53 . 2009-12-21 19:14 594432 c:\windows\system32\dllcache\msfeeds.dll + 2007-11-28 01:53 . 2010-02-25 06:24 594432 c:\windows\system32\dllcache\msfeeds.dll + 2009-06-10 02:14 . 2010-02-25 06:24 247808 c:\windows\system32\dllcache\ieproxy.dll + 2006-12-15 14:12 . 2010-02-25 06:24 184320 c:\windows\system32\dllcache\iepeers.dll - 2006-12-15 14:12 . 2009-12-21 19:14 184320 c:\windows\system32\dllcache\iepeers.dll + 2007-08-13 23:39 . 2010-02-25 06:24 387584 c:\windows\system32\dllcache\iedkcs32.dll - 2007-08-13 23:39 . 2009-12-21 19:14 387584 c:\windows\system32\dllcache\iedkcs32.dll + 2007-08-13 23:39 . 2010-02-24 09:54 173056 c:\windows\system32\dllcache\ie4uinit.exe - 2007-08-13 23:39 . 2009-12-21 13:19 173056 c:\windows\system32\dllcache\ie4uinit.exe + 2010-03-31 03:05 . 2009-12-21 19:14 916480 c:\windows\ie8updates\KB980182-IE8\wininet.dll + 2010-03-31 03:05 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\spuninst\updspapi.dll + 2010-03-31 03:05 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst\spuninst.exe + 2010-03-31 03:05 . 2009-12-21 19:14 206848 c:\windows\ie8updates\KB980182-IE8\occache.dll + 2010-03-31 03:05 . 2009-03-08 08:32 611840 c:\windows\ie8updates\KB980182-IE8\mstime.dll + 2010-03-31 03:05 . 2009-12-21 19:14 594432 c:\windows\ie8updates\KB980182-IE8\msfeeds.dll + 2010-03-31 03:05 . 2009-12-21 19:14 246272 c:\windows\ie8updates\KB980182-IE8\ieproxy.dll + 2010-03-31 03:05 . 2009-12-21 19:14 184320 c:\windows\ie8updates\KB980182-IE8\iepeers.dll + 2010-03-31 03:05 . 2009-12-21 19:14 387584 c:\windows\ie8updates\KB980182-IE8\iedkcs32.dll + 2010-03-31 03:05 . 2009-12-21 13:19 173056 c:\windows\ie8updates\KB980182-IE8\ie4uinit.exe + 2006-04-30 06:56 . 2010-02-25 06:24 1209344 c:\windows\system32\urlmon.dll + 2006-04-30 06:55 . 2010-02-25 06:24 5944832 c:\windows\system32\mshtml.dll + 2007-08-13 23:34 . 2010-02-25 06:24 1985536 c:\windows\system32\iertutil.dll - 2007-08-13 23:34 . 2009-12-21 19:14 1985536 c:\windows\system32\iertutil.dll + 2006-12-15 14:12 . 2010-02-25 06:24 1209344 c:\windows\system32\dllcache\urlmon.dll + 2006-12-15 14:12 . 2010-02-25 06:24 5944832 c:\windows\system32\dllcache\mshtml.dll + 2007-11-28 01:53 . 2010-02-25 06:24 1985536 c:\windows\system32\dllcache\iertutil.dll - 2007-11-28 01:53 . 2009-12-21 19:14 1985536 c:\windows\system32\dllcache\iertutil.dll + 2010-03-31 03:05 . 2009-12-21 19:14 1208832 c:\windows\ie8updates\KB980182-IE8\urlmon.dll + 2010-03-31 03:05 . 2009-12-21 19:14 5942784 c:\windows\ie8updates\KB980182-IE8\mshtml.dll + 2010-03-31 03:05 . 2009-12-21 19:14 1985536 c:\windows\ie8updates\KB980182-IE8\iertutil.dll + 2007-08-13 23:54 . 2010-02-25 15:54 11070976 c:\windows\system32\ieframe.dll + 2007-11-28 01:53 . 2010-02-25 15:54 11070976 c:\windows\system32\dllcache\ieframe.dll + 2010-03-31 03:05 . 2009-12-21 19:14 11070464 c:\windows\ie8updates\KB980182-IE8\ieframe.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2006-12-15 14:04 . 2005-05-20 00:11 925696 c:\program files\Analog Devices\Core\bak\smax4pnp.exe 2006-12-15 14:15 . 2005-05-06 23:06 716800 c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe 2006-05-10 19:12 . 2006-05-10 19:12 90112 c:\program files\ATI Technologies\ATI.ACE\bak\CLIStart.exe 2004-07-28 00:50 . 2004-07-28 00:50 81920 c:\program files\Common Files\Installshield\UpdateService\bak\issch.exe 2004-07-28 00:50 . 2004-07-28 00:50 221184 c:\program files\Common Files\Installshield\UpdateService\bak\ISUSPM.exe 2006-07-15 02:05 . 2006-07-15 02:05 503808 c:\program files\Common Files\Lenovo\Scheduler\bak\scheduler_proxy.exe 2007-04-07 01:26 . 2007-04-07 01:26 185896 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe 2006-05-19 00:24 . 2006-05-19 00:24 196696 c:\program files\Diskeeper Corporation\Diskeeper\bak\DkIcon.exe 2006-05-18 20:24 . 2006-05-18 20:24 196696 c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe 2007-01-28 20:44 . 2007-07-30 03:50 1836544 c:\program files\Google\Google Desktop Search\bak\GoogleDesktop.exe 2004-09-13 20:49 . 2004-09-13 20:49 49152 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe 2006-12-24 17:07 . 2004-03-12 23:24 106496 c:\program files\IBM\acp\ERTS0749\bak\ERTS0749.exe 2008-02-19 18:10 . 2008-02-19 18:10 267048 c:\program files\iTunes\bak\iTunesHelper.exe 2010-01-23 00:16 . 2010-01-23 00:16 141608 c:\program files\iTunes\iTunesHelper.exe 2007-10-26 23:44 . 2007-09-25 05:11 132496 c:\program files\Java\jre1.6.0_03\bin\bak\jusched.exe 2006-08-17 08:00 . 2006-10-19 07:08 69632 c:\program files\Lenovo\AwayTask\bak\AwaySch.EXE 2006-07-15 02:13 . 2006-07-15 02:13 2341632 c:\program files\Lenovo\Client Security Solution\bak\cssauth.exe 2006-08-03 01:27 . 2006-10-02 15:19 94208 c:\program files\Lenovo\PkgMgr\HOTKEY\bak\TPHKMGR.exe 2007-02-12 19:00 . 2006-11-17 18:39 136768 c:\program files\McAfee\Common Framework\bak\UdaterUI.exe 2009-08-25 21:00 . 2009-08-25 21:00 136512 c:\program files\McAfee\Common Framework\UdaterUI.exe 2006-03-15 23:07 . 2006-03-15 23:07 421888 c:\program files\Picasa2\bak\PicasaMediaDetector.exe 2008-08-21 01:18 . 2008-08-21 01:18 443968 c:\program files\Picasa2\PicasaMediaDetector.exe 2006-10-25 23:58 . 2006-10-25 23:58 282624 c:\program files\QuickTime\bak\qttask.exe 2006-12-24 20:38 . 2008-01-28 16:43 2097488 c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe 2009-05-10 16:58 . 2009-03-05 20:07 2260480 c:\program files\Spybot - Search & Destroy\TeaTimer.exe 2006-12-15 14:13 . 2006-02-14 05:16 512000 c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe 2008-02-25 00:45 . 2008-07-04 04:10 1323008 c:\program files\Synaptics\SynTP\SynTPEnh.exe 2006-12-15 14:13 . 2006-02-14 05:17 110592 c:\program files\Synaptics\SynTP\bak\SynTPLpr.exe 2008-02-25 00:45 . 2008-07-04 04:17 118784 c:\program files\Synaptics\SynTP\SynTPLpr.exe 2006-12-15 14:32 . 2006-08-26 08:22 409600 c:\program files\ThinkPad\ConnectUtilities\bak\ACTray.exe 2006-12-15 14:32 . 2006-08-26 08:17 110592 c:\program files\ThinkPad\ConnectUtilities\bak\ACWLIcon.exe 2006-12-15 14:13 . 2006-02-23 17:22 237568 c:\program files\ThinkPad\Utilities\bak\EzEjMnAp.Exe 2006-12-15 14:13 . 2006-06-03 06:00 856064 c:\program files\ThinkPad\Utilities\bak\TpKmapAp.exe 2006-12-15 14:23 . 2005-11-14 06:23 487424 c:\program files\ThinkVantage\AMSG\bak\amsg.exe 2006-12-15 14:22 . 2006-07-04 16:11 110592 c:\program files\ThinkVantage\PrdCtr\bak\LPMGR.exe 2006-10-19 00:05 . 2006-10-19 00:05 204288 c:\program files\Windows Media Player\bak\WMPNSCFG.exe 2006-04-30 06:56 . 2004-08-04 12:00 15360 c:\windows\system32\bak\ctfmon.exe 2006-04-30 06:56 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe 2006-12-15 14:25 . 2006-02-02 13:20 122940 c:\windows\system32\DLA\bak\DLACTRLW.EXE . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-16 68856] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552] "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896] "TpShocks"="TpShocks.exe" [2006-03-16 106496] "TP4EX"="tp4ex.exe" [2005-10-17 65536] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-04 118784] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-04 1323008] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-08-25 136512] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-10-23 124240] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [N/A] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608] "DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-15 24576] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify] [BU] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify] 2006-08-16 17:07 49152 ------w- c:\program files\Lenovo\AwayTask\AwayNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon] [BU] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus] 2006-04-26 03:20 40448 ------w- c:\windows\system32\psqlpwd.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2] 2005-07-06 04:45 28672 ------w- c:\windows\system32\notifyf2.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey] 2005-11-30 11:16 24576 ------w- c:\windows\system32\tphklock.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli psqlpwd [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\iTunes\\iTunes.exe"= R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [10/22/2009 9:07 PM 21256] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [1/15/2010 5:01 PM 70728] R2 smi2;smi2;c:\program files\SMI2\smi2.sys [7/14/2006 7:55 PM 3968] R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [4/25/2006 11:00 PM 3456] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/16/2010 2:38 PM 135664] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [1/15/2010 5:01 PM 65448] . Contents of the 'Scheduled Tasks' folder 2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-04-01 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-07 02:49] 2010-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-16 18:38] 2010-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-16 18:38] 2010-04-01 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] 2010-04-01 c:\windows\Tasks\PMTask.job - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-12-15 16:13] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-31 22:42 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1196) c:\windows\system32\Ati2evxx.dll c:\windows\system32\psqlpwd.dll c:\program files\ThinkVantage Fingerprint Software\infra.dll c:\program files\ThinkVantage Fingerprint Software\homefus2.dll c:\windows\system32\biologon.dll c:\program files\ThinkVantage Fingerprint Software\homepass.dll c:\program files\ThinkVantage Fingerprint Software\bio.dll c:\program files\ThinkVantage Fingerprint Software\remote.dll c:\program files\ThinkVantage Fingerprint Software\ps2css.dll c:\windows\system32\tphklock.dll c:\program files\ThinkVantage Fingerprint Software\crypto.dll c:\program files\Lenovo\AwayTask\AwayNotify.dll c:\windows\system32\notifyf2.dll - - - - - - - > 'lsass.exe'(1252) c:\windows\system32\psqlpwd.dll c:\program files\ThinkVantage Fingerprint Software\infra.dll c:\program files\ThinkVantage Fingerprint Software\homefus2.dll - - - - - - - > 'explorer.exe'(3676) c:\windows\system32\WININET.dll c:\windows\system32\PROCHLP.DLL c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\progra~1\WINDOW~1\wmpband.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2010-03-31 22:45:20 ComboFix-quarantined-files.txt 2010-04-01 02:45 Pre-Run: 13,849,165,824 bytes free Post-Run: 13,796,130,816 bytes free - - End Of File - - 19B61AA4CDAAAF3B5FDB394B56684572 |
|
|
|
|
#12 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Hi again,
Uninstall old Adobe Reader versions and get the latest one (9.3 + update 9.3.1) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version... Updating Java:
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop. Double-click ATF Cleaner.exe to open it Under Main choose: Windows Temp Current User Temp All Users Temp Cookies Temporary Internet Files Prefetch Java Cache *The other boxes are optional* Then click the Empty Selected button. If you use Firefox: Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. If you use Opera: Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. Click Exit on the Main menu to close the program. Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here. Post back its report & a fresh dds.txt log. How's the system running?
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#13 |
|
Junior Member
Join Date: Mar 2010
Posts: 8
|
Hi,
I updated Adobe and Java. I started Kaspersky's online scan but I'm not sure if it ever finished; last time I checked, it was at around 37% (after ~2 hours) then a few minutes later it wasn't scanning any longer and the status had changed to "null". The system seems to be running generally fine. I still sometimes get a message at start-up that virus scanner is not running but that message always goes away after a minute. The system is still a little slow at start up but improves after about five minutes. My USB ports and sound card seem to be working again. Here are the logs: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Friday, April 2, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, April 02, 2010 20:34:08 Records in database: 3913801 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 120346 Threats found: 4 Infected objects found: 5 Suspicious objects found: 0 Scan duration: 03:13:20 File name / Threat / Threats count C:\Documents and Settings\Payman Mazaheri\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-4b6b4b9a Infected: Trojan-Downloader.Java.Agent.ab 1 C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-4b6b4b9a Infected: Trojan-Downloader.Java.Agent.ab 1 C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Local Settings\Temporary Internet Files\Content.IE5\4CPW3X7R\oHff8ab741V0100f080006R5fdaf484102Tb42bcf49201l0409317[1].pdf Infected: Exploit.JS.Pdfka.bta 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\6to4v32.dll.vir Infected: Backdoor.Win32.Agent.anlr 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\curslib.dll.vir Infected: Backdoor.Win32.Agent.anuj 1 Selected area has been scanned. DDS Log: DDS (Ver_10-03-17.01) - NTFSx86 Run by Payman Mazaheri at 21:33:43.65 on Fri 04/02/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.589 [GMT -4:00] AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Intel\WiFi\bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\IPSSVC.EXE C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\mfevtps.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe C:\WINDOWS\system32\svchost.exe -k imgsvc c:\program files\lenovo\system update\suservice.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\TpShocks.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\McAfee\Common Framework\udaterui.exe C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Common Files\Lenovo\Logger\logmon.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Java\jre6\bin\java.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Payman Mazaheri\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: rsion - No File BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TpShocks] TpShocks.exe mRun: [TP4EX] tp4ex.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [DiskeeperSystray] "c:\program files\diskeeper corporation\diskeeper\DkIcon.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {DA320635-F48C-4613-8325-D75A933C549E} - c:\program files\lenovo\system update\sulauncher.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxps://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: AwayNotify - c:\program files\lenovo\awaytask\AwayNotify.dll Notify: psfus - psqlpwd.dll Notify: tpfnf2 - notifyf2.dll Notify: tphotkey - tphklock.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll LSA: Notification Packages = scecli psqlpwd ============= SERVICES / DRIVERS =============== P2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2009-10-22 146448] R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-1-15 343664] R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\EngineServer.exe [2009-10-22 21256] R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2009-8-25 103744] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2009-10-22 66896] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-1-15 70728] R2 smi2;smi2;c:\program files\smi2\smi2.sys [2006-7-14 3968] R2 smihlp;SMI helper driver;c:\program files\thinkvantage fingerprint software\smihlp.sys [2006-4-25 3456] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-1-15 91672] S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-1-15 43288] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-1-15 65448] S4 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?] =============== Created Last 30 ================ 2010-04-02 03:17:20 73728 ----a-w- c:\windows\system32\javacpl.cpl 2010-04-02 03:17:20 411368 ----a-w- c:\windows\system32\deploytk.dll 2010-03-31 03:41:24 0 d-----w- C:\HelpAsst_backup 2010-03-29 23:01:51 0 d-sha-r- C:\cmdcons 2010-03-21 14:46:05 0 d-----w- c:\program files\Trend Micro 2010-03-20 21:21:14 0 d--h--w- c:\windows\PIF 2010-03-10 02:22:07 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe ==================== Find3M ==================== 2010-03-29 19:24:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-29 19:24:46 20824 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-28 20:35:28 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS 2010-03-12 22:02:38 261632 ----a-w- c:\windows\PEV.exe 2010-02-25 15:54:36 11070976 ------w- c:\windows\system32\dllcache\ieframe.dll 2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe 2010-02-24 09:54:25 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe 2008-08-27 21:15:11 32768 -csh--w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082720080828\index.dat ============= FINISH: 21:34:38.37 =============== |
|
|
|
|
#14 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Hi,
Delete this file: C:\Documents and Settings\Payman Mazaheri\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-4b6b4b9a and folder: C:\HelpAsst_backup You may check hints for making system performance better here. THESE STEPS ARE VERY IMPORTANT Let's reset system restore Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK. NOTE: only do this ONCE,NOT on a regular basis Now lets uninstall ComboFix:
Please download OTC and save it to desktop.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so. UPDATING WINDOWS AND INTERNET EXPLORER IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates. If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update. Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options. Click once on the Security tab Click once on the Internet icon so it becomes highlighted. Click once on the Custom Level button. Change the Download signed ActiveX controls to Prompt Change the Download unsigned ActiveX controls to Disable Change the Initialize and script ActiveX controls not marked as safe to Disable Change the Installation of desktop items to Prompt Change the Launching programs and files in an IFRAME to Prompt Change the Navigate sub-frames across different domains to Prompt When all these settings have been made, click on the OK button. If it prompts you as to whether or not you want to save the settings, press the Yes button. Next press the Apply button and then the OK to exit the Internet Properties page. The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
Just a final reminder for you. I am trying to stress these two points. UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks. Make sure all of your security programs are up to date. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates. Once again, please post and tell me how things are going with your system... problems etc. Have a great day, Blade
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#15 |
|
Junior Member
Join Date: Mar 2010
Posts: 8
|
Hi Blade,
I have made all the recommended changes and the system seems to be running fine. Is there anything else I need to do? Thanks for all your help! |
|
|
|
|
#16 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
No, that was all
![]() Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
| Thread Tools | |
| Display Modes | |
|
|