View Full Version : Virtumonde infection... and others
matthill
2008-04-07, 16:59
I've had a lot of funky stuff going on with this over the last couple of days and found your forum. Thank goodness! I hope you can help. I've read and completed all the steps from the "BEFORE you POST" thread. Search & Destroy now says that everything is clear, so I'm really not sure if I still have Virtumonde or not... yet Kaspersky found 11 virii. Anyway, here's the logs, I hope you can assist (Note: I had Microsoft OneCare installed during that scan (yeah, yeah, I know....;) !) but I've since removed it as it slowed my computer right down).
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:09:43, on 07/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
D:\WINDOWS\Mixer.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Last.fm\LastFMHelper.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O20 - Winlogon Notify: hgghfdc - hgghfdc.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: wampapache - Apache Software Foundation - D:\Program Files\wamp\apache2\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - D:\Program Files\wamp\mysql\bin\mysqld-nt.exe
--
End of file - 10775 bytes
Rorschach112
2008-04-07, 18:53
Hello
Please download ComboFix from Here (http://subs.geekstogo.com/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Please, never rename Combofix unless instructed.
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Click on this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
-----------------------------------------------------------
Close any open browsers.
WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
-----------------------------------------------------------
Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
matthill
2008-04-07, 19:35
Thank you for you help. :-) Here is the ComboFix log. I'll put the HJT log in the next reply.
ComboFix 08-04-06.1 - Matt 2008-04-07 17:10:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.259 [GMT 1:00]
Running from: D:\Documents and Settings\Matt\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\WINDOWS\BMcf8246e3.xml
D:\WINDOWS\pskt.ini
D:\WINDOWS\system32\aveemlab.ini
D:\WINDOWS\system32\cfhkj.ini
D:\WINDOWS\system32\cfhkj.ini2
D:\WINDOWS\system32\crlgrbuf.ini
D:\WINDOWS\system32\wvvwa.ini
D:\WINDOWS\system32\wvvwa.ini2
.
((((((((((((((((((((((((( Files Created from 2008-03-07 to 2008-04-07 )))))))))))))))))))))))))))))))
.
2008-04-07 17:18 . 2008-04-07 17:18 <DIR> d-------- D:\Temp\WPDNSE
2008-04-07 17:18 . 2008-04-07 17:18 53,248 --a------ D:\Temp\catchme.dll
2008-04-07 11:36 . 2008-04-07 11:36 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-04-07 11:36 . 2008-04-07 11:36 1,409 --a------ D:\WINDOWS\QTFont.for
2008-04-07 11:15 . 2008-04-07 13:52 <DIR> d-------- D:\Temp\hsperfdata_Matt
2008-04-07 09:36 . 2008-04-07 09:36 <DIR> d-------- D:\Program Files\Trend Micro
2008-04-07 08:47 . 2008-04-07 08:47 <DIR> d-------- D:\Temp\WinSSTemp
2008-04-06 16:37 . 2008-04-06 16:37 <DIR> d-------- D:\WINDOWS\system32\Kaspersky Lab
2008-04-06 16:37 . 2008-04-06 16:37 <DIR> d-------- D:\Temp\KAV Updater update files
2008-04-06 16:37 . 2008-04-06 16:37 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-06 15:18 . 2008-04-07 17:18 <DIR> d-------- D:\Temp\outlook logging
2008-04-06 14:19 . 2008-04-06 14:19 <DIR> d-------- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-06 13:42 . 2007-07-30 19:19 271,224 --a------ D:\WINDOWS\system32\mucltui.dll
2008-04-06 13:42 . 2007-07-30 19:19 207,736 --a------ D:\WINDOWS\system32\muweb.dll
2008-04-06 13:42 . 2007-07-30 19:19 30,072 --a------ D:\WINDOWS\system32\mucltui.dll.mui
2008-04-06 13:07 . 2007-03-29 13:56 409,600 -----c--- D:\WINDOWS\system32\dllcache\qmgr.dll
2008-04-06 13:07 . 2007-03-29 13:56 18,944 -----c--- D:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-04-06 13:07 . 2007-03-29 13:56 8,192 -----c--- D:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 -----c--- D:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 -----c--- D:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 --a------ D:\WINDOWS\system32\bitsprx4.dll
2008-04-06 12:48 . 2008-04-07 17:18 <DIR> d-------- D:\Temp\MPSampleSubmit
2008-04-06 05:46 . 2008-04-07 08:40 <DIR> d-------- D:\Program Files\Windows Live Safety Center
2008-04-06 05:38 . 2008-04-07 17:19 13,588 --a------ D:\WINDOWS\system32\wpa.dbl
2008-04-06 05:24 . 2008-04-06 05:24 <DIR> d-------- D:\Program Files\Safer Networking
2008-04-06 05:07 . 2008-04-06 05:07 294 --ahs---- D:\WINDOWS\system32\aefbdspl.ini
2008-04-06 04:06 . 2008-04-06 04:09 264 --a------ D:\WINDOWS\wininit.ini
2008-04-06 03:20 . 2008-04-06 03:20 <DIR> d-------- D:\Program Files\Spybot - Search & Destroy
2008-04-06 03:20 . 2008-04-06 03:31 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-06 03:03 . 2008-04-06 03:18 <DIR> d-------- D:\Program Files\Security Task Manager
2008-04-06 03:03 . 2008-04-06 13:35 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-04-06 00:46 . 2008-04-06 00:46 <DIR> d--hs---- D:\Temp\Temporary Internet Files
2008-04-06 00:46 . 2008-04-06 00:46 <DIR> d--hs---- D:\Temp\History
2008-04-06 00:46 . 2008-04-07 17:18 <DIR> d--hs---- D:\Temp\Cookies
2008-04-04 16:02 . 2008-04-04 17:32 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2008-04-01 23:50 . 2008-04-01 23:55 <DIR> d-------- D:\Program Files\ProFantasy Software Ltd
2008-04-01 23:45 . 2008-04-01 23:55 <DIR> d-------- D:\Program Files\cc2
2008-03-21 13:40 . 2008-03-24 17:34 <DIR> d-------- D:\Program Files\X-Fonter
2008-03-21 13:24 . 2008-03-21 13:25 <DIR> d-------- D:\Program Files\FontViewer
2008-03-21 04:58 . 2008-04-03 11:57 <DIR> d-------- D:\_misc
2008-03-19 17:04 . 2008-03-31 22:03 <DIR> d-------- D:\Program Files\Unlocker
2008-03-19 03:36 . 2004-03-29 18:23 90,112 --a------ D:\WINDOWS\unvise32.exe
2008-03-19 03:34 . 2008-03-19 03:37 <DIR> d-------- D:\Program Files\DAZ
2008-03-19 03:34 . 2008-03-19 03:34 <DIR> d-------- D:\Program Files\Common Files\DAZ
2008-03-18 21:13 . 2008-03-18 21:13 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-03-14 20:45 . 2008-03-14 20:45 <DIR> d-------- D:\Program Files\qml-edit2
2008-03-13 04:34 . 2008-03-13 04:34 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-13 04:31 . 2008-04-06 14:03 <DIR> d-------- D:\Program Files\NCH Swift Sound
2008-03-13 04:31 . 2008-03-13 04:31 <DIR> d-------- D:\Documents and Settings\Matt\Application Data\NCH Swift Sound
2008-03-12 23:43 . 2008-03-12 23:43 <DIR> d-------- D:\_iso
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-07 14:26 --------- d-----w D:\Program Files\DC++
2008-04-07 08:51 10,263 ----a-w D:\WINDOWS\system32\drivers\fwdrv.err
2008-04-06 13:03 --------- d-----w D:\Program Files\Nokia
2008-04-06 13:00 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-04-06 12:57 --------- d-----w D:\Program Files\Google
2008-04-03 23:18 --------- d-----w D:\Program Files\Opera922
2008-03-27 15:40 --------- d-----w D:\Program Files\Common Files\Macromedia
2008-03-27 15:39 --------- d-----w D:\Program Files\Macromedia
2008-03-27 15:38 --------- d-----w D:\Program Files\QuickTime Alternative
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Medium.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Medium Italic.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Light.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Light Italic.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Extra Bold.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Bold.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Bold Italic.pfm
2008-03-21 01:01 --------- d-----w D:\Program Files\Windows Grep
2008-02-13 10:54 --------- d-----w D:\Program Files\Duplicate File Finder
2008-02-06 22:51 409,600 ----a-w D:\WINDOWS\system32\wrap_oal.dll
2008-02-06 22:51 114,688 ----a-w D:\WINDOWS\system32\OpenAL32.dll
2006-07-01 00:45 421,888 ----a-w D:\Program Files\putty.exe
.
<pre>
----a-w 996,038 2008-03-18 18:58:55 D:\_DVD\Software\Graphics & Animation\Poser,DAZ3D,Bryce\Santa's Gift - Daz 3D Poser - Victoria's Classic Pinup Poses .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2001-12-07 16:24 1216512 D:\WINDOWS\Mixer.exe]
"ccApp"="D:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 12:47 71328]
"Symantec NetDriver Monitor"="D:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-07-08 00:03 100056]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2005-04-01 17:16 5562368]
"nwiz"="nwiz.exe" [2005-04-01 17:16 1495040 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray.dll" [2005-04-01 17:16 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
D:\Documents and Settings\Matt\Start Menu\Programs\Startup\
Last.fm Helper.lnk - D:\Program Files\Last.fm\LastFMHelper.exe [2007-07-01 15:00:20 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgghfdc]
hgghfdc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.WMV3"= wmv9vcm.dll
"msacm.lameacm"= LameACM.acm
"VIDC.FPS1"= frapsvid.dll
"VIDC.ZMBV"= zmbv.dll
"VIDC.D263"= xl_x263dec.dll
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=D:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=D:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^broadband medic.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\broadband medic.lnk
backup=D:\WINDOWS\pss\broadband medic.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG311T Smart Wizard.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311T Smart Wizard.lnk
backup=D:\WINDOWS\pss\NETGEAR WG311T Smart Wizard.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^Matt^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=D:\Documents and Settings\Matt\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=D:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Matt^Start Menu^Programs^Startup^Ubisoft register.lnk]
path=D:\Documents and Settings\Matt\Start Menu\Programs\Startup\Ubisoft register.lnk
backup=D:\WINDOWS\pss\Ubisoft register.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 03:12 483328 D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2003-10-02 02:20 81920 D:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 06:31 208952 D:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-04 06:32 455168 D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-04 06:32 455168 D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-12-15 04:23 75520 D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ascadio"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 pnpshark;pnpshark;D:\WINDOWS\system32\DRIVERS\pnpshark.sys [2003-10-02 03:16]
R0 st3shark;st3shark;D:\WINDOWS\system32\DRIVERS\st3shark.sys [2003-09-27 14:37]
R1 fwdrv;Firewall Driver;D:\WINDOWS\system32\drivers\fwdrv.sys [2005-09-26 11:05]
R1 khips;Kerio HIPS Driver;D:\WINDOWS\system32\drivers\khips.sys [2005-09-26 11:05]
S3 Faypicuuanect;Faypicuuanect;D:\WINDOWS\system32\drivers\sffdisk.sys [2004-08-04 06:59]
S3 SaiH0109;SaiH0109;D:\WINDOWS\system32\DRIVERS\SaiH0109.sys [2004-07-26 12:54]
S3 SaiU0109;SaiU0109;D:\WINDOWS\system32\DRIVERS\SaiU0109.sys [2004-07-26 12:54]
S3 wampapache;wampapache;"D:\Program Files\wamp\apache2\bin\Apache.exe" -k runservice []
S3 wampmysqld;wampmysqld;"D:\Program Files\wamp\mysql\bin\mysqld-nt.exe" "--defaults-file=D:\Program Files\wamp\mysql\my.ini" wampmysqld []
*Newly Created Service* - ELBYCDIO
.
Contents of the 'Scheduled Tasks' folder
"2008-04-07 16:26:00 D:\WINDOWS\Tasks\Symantec NetDetect.job"
- D:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2008-04-07 07:09:41 D:\WINDOWS\Tasks\User_Feed_Synchronization-{7129372D-DDA7-4859-9DBB-50154F694549}.job"
- D:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 17:18:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: D:\WINDOWS\explorer.exe
-> D:\Program Files\TortoiseSVN\iconv\_tbl_simple.so
-> D:\Program Files\TortoiseSVN\iconv\windows-1252.so
-> D:\Program Files\TortoiseSVN\iconv\utf-8.so
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\Program Files\Messenger\msmsgs.exe
D:\WINDOWS\System32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-04-07 17:27:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-07 16:27:24
Pre-Run: 1,439,277,056 bytes free
Post-Run: 1,364,623,360 bytes free
.
2008-04-06 13:28:20 --- E O F ---
matthill
2008-04-07, 19:36
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:35:15, on 07/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
D:\WINDOWS\Mixer.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Last.fm\LastFMHelper.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O20 - Winlogon Notify: hgghfdc - hgghfdc.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: wampapache - Apache Software Foundation - D:\Program Files\wamp\apache2\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - D:\Program Files\wamp\mysql\bin\mysqld-nt.exe
--
End of file - 10567 bytes
Rorschach112
2008-04-07, 20:08
Hello
1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):
O20 - Winlogon Notify: hgghfdc - hgghfdc.dll (file missing)
2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.
1. Close any open browsers.
2. Open notepad and copy/paste the text in the quotebox below into it:
KillAll::
RenV::
----a-w 996,038 2008-03-18 18:58:55 D:\_DVD\Software\Graphics & Animation\Poser,DAZ3D,Bryce\Santa's Gift - Daz 3D Poser - Victoria's Classic Pinup Poses .exe
Save this as CFScript.txt, in the same location as ComboFix.exe
http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Reboot and post a new HijackThis log
matthill
2008-04-07, 20:50
OK, thankyou, here's the next HJT log file after doing those actions:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:43:29, on 07/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\WINDOWS\Mixer.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Last.fm\LastFMHelper.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - D:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "D:\Program Files\Fiddler\Fiddler.exe" (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: wampapache - Apache Software Foundation - D:\Program Files\wamp\apache2\bin\Apache.exe
O23 - Service: wampmysqld - Unknown owner - D:\Program Files\wamp\mysql\bin\mysqld-nt.exe
--
End of file - 10587 bytes
Rorschach112
2008-04-07, 20:51
Can you post the ComboFix log as well
And do this
Please do an online scan with Kaspersky WebScanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html)
Click on Kaspersky Online Scanner and click Accept
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan:Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
matthill
2008-04-07, 20:54
I did the scan yesterday and it took five hours.... can I post the log from that, or do I need to do a new one?
matthill
2008-04-07, 21:20
ComboFix 08-04-06.1 - Matt 2008-04-07 18:24:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT 1:00]
Running from: D:\Documents and Settings\Matt\Desktop\ComboFix.exe
Command switches used :: D:\Documents and Settings\Matt\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-07 to 2008-04-07 )))))))))))))))))))))))))))))))
.
2008-04-07 18:32 . 2008-04-07 18:32 <DIR> d-------- D:\Temp\WPDNSE
2008-04-07 18:32 . 2008-04-07 18:32 53,248 --a------ D:\Temp\catchme.dll
2008-04-07 17:28 . 2008-04-07 18:33 <DIR> d-------- D:\Temp
2008-04-07 11:36 . 2008-04-07 11:36 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-04-07 11:36 . 2008-04-07 11:36 1,409 --a------ D:\WINDOWS\QTFont.for
2008-04-07 09:36 . 2008-04-07 09:36 <DIR> d-------- D:\Program Files\Trend Micro
2008-04-06 16:37 . 2008-04-06 16:37 <DIR> d-------- D:\WINDOWS\system32\Kaspersky Lab
2008-04-06 16:37 . 2008-04-06 16:37 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-06 14:19 . 2008-04-06 14:19 <DIR> d-------- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-06 13:42 . 2007-07-30 19:19 271,224 --a------ D:\WINDOWS\system32\mucltui.dll
2008-04-06 13:42 . 2007-07-30 19:19 207,736 --a------ D:\WINDOWS\system32\muweb.dll
2008-04-06 13:42 . 2007-07-30 19:19 30,072 --a------ D:\WINDOWS\system32\mucltui.dll.mui
2008-04-06 13:07 . 2007-03-29 13:56 409,600 -----c--- D:\WINDOWS\system32\dllcache\qmgr.dll
2008-04-06 13:07 . 2007-03-29 13:56 18,944 -----c--- D:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-04-06 13:07 . 2007-03-29 13:56 8,192 -----c--- D:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 -----c--- D:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 -----c--- D:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-04-06 13:07 . 2007-03-29 13:56 7,168 --a------ D:\WINDOWS\system32\bitsprx4.dll
2008-04-06 05:46 . 2008-04-07 08:40 <DIR> d-------- D:\Program Files\Windows Live Safety Center
2008-04-06 05:38 . 2008-04-07 18:33 13,588 --a------ D:\WINDOWS\system32\wpa.dbl
2008-04-06 05:24 . 2008-04-06 05:24 <DIR> d-------- D:\Program Files\Safer Networking
2008-04-06 05:07 . 2008-04-06 05:07 294 --ahs---- D:\WINDOWS\system32\aefbdspl.ini
2008-04-06 04:06 . 2008-04-06 04:09 264 --a------ D:\WINDOWS\wininit.ini
2008-04-06 03:20 . 2008-04-06 03:20 <DIR> d-------- D:\Program Files\Spybot - Search & Destroy
2008-04-06 03:20 . 2008-04-06 03:31 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-06 03:03 . 2008-04-06 03:18 <DIR> d-------- D:\Program Files\Security Task Manager
2008-04-06 03:03 . 2008-04-06 13:35 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-04-04 16:02 . 2008-04-04 17:32 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2008-04-01 23:50 . 2008-04-01 23:55 <DIR> d-------- D:\Program Files\ProFantasy Software Ltd
2008-04-01 23:45 . 2008-04-01 23:55 <DIR> d-------- D:\Program Files\cc2
2008-03-21 13:40 . 2008-03-24 17:34 <DIR> d-------- D:\Program Files\X-Fonter
2008-03-21 13:24 . 2008-03-21 13:25 <DIR> d-------- D:\Program Files\FontViewer
2008-03-21 04:58 . 2008-04-03 11:57 <DIR> d-------- D:\_misc
2008-03-19 17:04 . 2008-03-31 22:03 <DIR> d-------- D:\Program Files\Unlocker
2008-03-19 03:36 . 2004-03-29 18:23 90,112 --a------ D:\WINDOWS\unvise32.exe
2008-03-19 03:34 . 2008-03-19 03:37 <DIR> d-------- D:\Program Files\DAZ
2008-03-19 03:34 . 2008-03-19 03:34 <DIR> d-------- D:\Program Files\Common Files\DAZ
2008-03-18 21:13 . 2008-03-18 21:13 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-03-14 20:45 . 2008-03-14 20:45 <DIR> d-------- D:\Program Files\qml-edit2
2008-03-13 04:34 . 2008-03-13 04:34 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-13 04:31 . 2008-04-06 14:03 <DIR> d-------- D:\Program Files\NCH Swift Sound
2008-03-13 04:31 . 2008-03-13 04:31 <DIR> d-------- D:\Documents and Settings\Matt\Application Data\NCH Swift Sound
2008-03-12 23:43 . 2008-03-12 23:43 <DIR> d-------- D:\_iso
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-07 14:26 --------- d-----w D:\Program Files\DC++
2008-04-07 08:51 10,263 ----a-w D:\WINDOWS\system32\drivers\fwdrv.err
2008-04-06 13:03 --------- d-----w D:\Program Files\Nokia
2008-04-06 13:00 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-04-06 12:57 --------- d-----w D:\Program Files\Google
2008-04-03 23:18 --------- d-----w D:\Program Files\Opera922
2008-03-27 15:40 --------- d-----w D:\Program Files\Common Files\Macromedia
2008-03-27 15:39 --------- d-----w D:\Program Files\Macromedia
2008-03-27 15:38 --------- d-----w D:\Program Files\QuickTime Alternative
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Medium.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Medium Italic.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Light.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Light Italic.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Extra Bold.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Bold.pfm
2008-03-24 16:22 0 ----a-w D:\WINDOWS\Fonts\Memphis LT Bold Italic.pfm
2008-03-21 01:01 --------- d-----w D:\Program Files\Windows Grep
2008-02-13 10:54 --------- d-----w D:\Program Files\Duplicate File Finder
2008-02-06 22:51 409,600 ----a-w D:\WINDOWS\system32\wrap_oal.dll
2008-02-06 22:51 114,688 ----a-w D:\WINDOWS\system32\OpenAL32.dll
2006-07-01 00:45 421,888 ----a-w D:\Program Files\putty.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2001-12-07 16:24 1216512 D:\WINDOWS\Mixer.exe]
"ccApp"="D:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 12:47 71328]
"Symantec NetDriver Monitor"="D:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-07-08 00:03 100056]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2005-04-01 17:16 5562368]
"nwiz"="nwiz.exe" [2005-04-01 17:16 1495040 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray.dll" [2005-04-01 17:16 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
D:\Documents and Settings\Matt\Start Menu\Programs\Startup\
Last.fm Helper.lnk - D:\Program Files\Last.fm\LastFMHelper.exe [2007-07-01 15:00:20 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.WMV3"= wmv9vcm.dll
"msacm.lameacm"= LameACM.acm
"VIDC.FPS1"= frapsvid.dll
"VIDC.ZMBV"= zmbv.dll
"VIDC.D263"= xl_x263dec.dll
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=D:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=D:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^broadband medic.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\broadband medic.lnk
backup=D:\WINDOWS\pss\broadband medic.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG311T Smart Wizard.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311T Smart Wizard.lnk
backup=D:\WINDOWS\pss\NETGEAR WG311T Smart Wizard.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^Matt^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=D:\Documents and Settings\Matt\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=D:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Matt^Start Menu^Programs^Startup^Ubisoft register.lnk]
path=D:\Documents and Settings\Matt\Start Menu\Programs\Startup\Ubisoft register.lnk
backup=D:\WINDOWS\pss\Ubisoft register.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 03:12 483328 D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2003-10-02 02:20 81920 D:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 06:31 208952 D:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-04 06:32 455168 D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-04 06:32 455168 D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-12-15 04:23 75520 D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ascadio"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 pnpshark;pnpshark;D:\WINDOWS\system32\DRIVERS\pnpshark.sys [2003-10-02 03:16]
R0 st3shark;st3shark;D:\WINDOWS\system32\DRIVERS\st3shark.sys [2003-09-27 14:37]
R1 fwdrv;Firewall Driver;D:\WINDOWS\system32\drivers\fwdrv.sys [2005-09-26 11:05]
R1 khips;Kerio HIPS Driver;D:\WINDOWS\system32\drivers\khips.sys [2005-09-26 11:05]
S3 Faypicuuanect;Faypicuuanect;D:\WINDOWS\system32\drivers\sffdisk.sys [2004-08-04 06:59]
S3 SaiH0109;SaiH0109;D:\WINDOWS\system32\DRIVERS\SaiH0109.sys [2004-07-26 12:54]
S3 SaiU0109;SaiU0109;D:\WINDOWS\system32\DRIVERS\SaiU0109.sys [2004-07-26 12:54]
S3 wampapache;wampapache;"D:\Program Files\wamp\apache2\bin\Apache.exe" -k runservice []
S3 wampmysqld;wampmysqld;"D:\Program Files\wamp\mysql\bin\mysqld-nt.exe" "--defaults-file=D:\Program Files\wamp\mysql\my.ini" wampmysqld []
*Newly Created Service* - ELBYCDIO
.
Contents of the 'Scheduled Tasks' folder
"2008-04-07 17:36:00 D:\WINDOWS\Tasks\Symantec NetDetect.job"
- D:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2008-04-07 07:09:41 D:\WINDOWS\Tasks\User_Feed_Synchronization-{7129372D-DDA7-4859-9DBB-50154F694549}.job"
- D:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 18:32:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: D:\WINDOWS\explorer.exe
-> D:\Program Files\TortoiseSVN\iconv\_tbl_simple.so
-> D:\Program Files\TortoiseSVN\iconv\windows-1252.so
-> D:\Program Files\TortoiseSVN\iconv\utf-8.so
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\TortoiseSVN\bin\TSVNCache.exe
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Program Files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2008-04-07 18:40:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-07 17:40:16
ComboFix2.txt 2008-04-07 16:27:47
Pre-Run: 1,379,061,760 bytes free
Post-Run: 1,365,237,760 bytes free
.
2008-04-06 13:28:20 --- E O F ---
matthill
2008-04-07, 21:48
The virus scan will take about 5 hours; I'll post that up tomorrow. Thanks for your help so far. :)
matthill
2008-04-08, 10:17
OK, here's the Kaspersky report:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 08, 2008 8:15:04 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/04/2008
Kaspersky Anti-Virus database records: 688898
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
I:\
L:\
X:\
Y:\
Scan Statistics:
Total number of scanned objects: 336038
Number of viruses found: 17
Number of infected objects: 52
Number of suspicious objects: 2
Duration of the scan process: 03:51:33
Infected Object Name / Virus Name / Last Action
C:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-07_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\cert8.db Object is locked skipped
D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\history.dat Object is locked skipped
D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\key3.db Object is locked skipped
D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\parent.lock Object is locked skipped
D:\Documents and Settings\Matt\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Last.fm\Client\lastfmhelper.log Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_001_ Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_002_ Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_003_ Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_MAP_ Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Matt\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\Matt\NTUSER.DAT.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\PST Files\matthew.pst/Matthew's PST/Inbox/Shopping & Services/Paypal/15 Mar 2003 06:31 from PayPal Business Bulletin:March Business B.html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
D:\Documents and Settings\PST Files\matthew.pst Mail MS Mail: suspicious - 1 skipped
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\debug.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\debug.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\error.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\error.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\hips.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\hips.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\ids.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\ids.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\network.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\network.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\system.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\system.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\warning.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\warning.log.idx Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\web.log Object is locked skipped
D:\Program Files\Kerio\Personal Firewall 4\logs\web.log.idx Object is locked skipped
D:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
D:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
D:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip ZIP: infected - 3 skipped
D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip CryptFF: infected - 3 skipped
D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe/data0007 Infected: Trojan-Clicker.Win32.Agent.gy skipped
D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe/data0008 Infected: Trojan-Downloader.Win32.Zlob.jl skipped
D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe NSIS: infected - 2 skipped
D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe UPX: infected - 2 skipped
D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe CryptFF: infected - 2 skipped
D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip ZIP: infected - 3 skipped
D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip CryptFF: infected - 3 skipped
D:\Program Files\Norton AntiVirus\Quarantine\7D525279/BaaaaBaa.class Infected: Exploit.Java.Gimsh.a skipped
D:\Program Files\Norton AntiVirus\Quarantine\7D525279 ZIP: infected - 1 skipped
D:\Program Files\Norton AntiVirus\Quarantine\7D525279 CryptFF: infected - 1 skipped
D:\Program Files\SnadBoy's Revelation v2\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
D:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP512\A0110980.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111052.exe Infected: Trojan-Downloader.Win32.Zlob.is skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111053.exe Infected: Trojan-Downloader.Win32.Zlob.iz skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111054.exe Infected: Trojan-Downloader.Win32.Small.cqs skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP514\A0111061.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP514\A0111062.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP516\A0111180.dll Infected: Packed.Win32.Monder skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP516\A0111181.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mxi skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe/data0000.cab/toolbar.exe Infected: Packed.Win32.Monder skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe/data0000.cab Infected: Packed.Win32.Monder skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe Rsrc-Package: infected - 2 skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe/data0000.cab/toolbar.exe Infected: Packed.Win32.Monder skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe/data0000.cab Infected: Packed.Win32.Monder skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe Rsrc-Package: infected - 2 skipped
D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
D:\WINDOWS\SchedLgU.Txt Object is locked skipped
D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
D:\WINDOWS\Sti_Trace.log Object is locked skipped
D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\default Object is locked skipped
D:\WINDOWS\system32\config\default.LOG Object is locked skipped
D:\WINDOWS\system32\config\Internet.evt Object is locked skipped
D:\WINDOWS\system32\config\SAM Object is locked skipped
D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\SECURITY Object is locked skipped
D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
D:\WINDOWS\system32\config\software Object is locked skipped
D:\WINDOWS\system32\config\software.LOG Object is locked skipped
D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\system Object is locked skipped
D:\WINDOWS\system32\config\system.LOG Object is locked skipped
D:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
D:\WINDOWS\system32\h323log.txt Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
D:\WINDOWS\wiadebug.log Object is locked skipped
D:\WINDOWS\wiaservc.log Object is locked skipped
D:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\_DVD\Software\Internet\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
D:\_DVD\Software\Internet\mirc616.exe mIRC: infected - 1 skipped
D:\_DVD\Software\Internet\mirc62.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
D:\_DVD\Software\Internet\mirc62.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
D:\_DVD\Software\Internet\mirc62.exe NSIS: infected - 2 skipped
D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe WiseSFX: infected - 2 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108158.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108158.exe mIRC: infected - 1 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe NSIS: infected - 2 skipped
E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
F:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
Scan process completed.
Rorschach112
2008-04-08, 19:24
Hello
1. Close any open browsers.
2. Open notepad and copy/paste the text in the quotebox below into it:
File::
D:\WINDOWS\system32\aefbdspl.ini
D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q
Folder::
D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q
Save this as CFScript.txt, in the same location as ComboFix.exe
http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Also tell me how your PC is running
matthill
2008-04-08, 20:45
Hi, this didn't work. The ComboFix cmd window popped up briefly, no messages appeared, then it closed again. No new report has been generated.
matthill
2008-04-08, 20:55
Aslso, other than this problem with ComboFix, my PC is running fine at the moment. No code injection warnings and all the weird stuff I was having before has stopped. I'm aware I still need to run a virus check to remove those listed by Kaspersky in my report above, but I thought I'd best wait for your instructions regarding that. :)
Rorschach112
2008-04-08, 21:05
Do this instead
Please download the OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe).
Save it to your desktop.
Please double-click OTMoveIt2.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
[kill explorer]
D:\WINDOWS\system32\aefbdspl.ini
D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q
purity
[start explorer]
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
Click the red Moveit! button.
A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Reboot and tell me how your PC is running
matthill
2008-04-08, 21:33
Hi, thank you for the update. Here's the log from OTMoveit2. The PC seems to be running very well. :)
Explorer killed successfully
D:\WINDOWS\system32\aefbdspl.ini moved successfully.
D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q moved successfully.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04082008_191347
Rorschach112
2008-04-08, 21:40
Your logs are clean ! We need to do a few things
Follow these steps to uninstall Combofix and tools used in the removal of malware
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
Make sure you have an Internet Connection.
Double-click OTMoveIt2.exe to run it.
Click on the CleanUp! button
A list of tool components used in the Cleanup of malware will be downloaded.
If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
Click Yes to beging the Cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
You now need to update your Java and remove your older versions.
Please follow these steps to remove older version Java components.
* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.
Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here (http://java.sun.com/javase/downloads/index.jsp)
Below I have included a number of recommendations for how to protect your computer against malware infections.
* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html) protects against bad ActiveX
IE-SPYAD (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe) puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)
* SpywareGuard (http://www.javacoolsoftware.com/sgdownload.html) offers realtime protection from spyware installation attempts.
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here (http://www.mozilla.org/products/firefox/)
* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here (http://forums.spywareinfo.com/index.php?showtopic=60955)
Thank you for your patience, and performing all of the procedures requested.
matthill
2008-04-08, 23:02
Excellent! Thank you very much for all your help! :bigthumb: Now, I am going to get rid of Norton (it didn't find the source of the infection) and buy a better anti-virus!
I owe you a guinness or two! :)
Rorschach112
2008-04-09, 01:19
Sounds like a plan :)
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.
Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.