Page 1 of 2 12 LastLast
Results 1 to 10 of 19

Thread: Search Results redirected

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    9

    Default Search Results redirected

    Hey guys, having a bit of trouble hunting down an infection.

    The search results for google and bing are being redirected to seemingly random (probably not good) websites instead of the actual result.

    This happens in IE, Firefox & Opera so i think its system wide rather than just tied to one browser.

    Malware Bytes doesnt seem to find anything malicious.

    Spybot finds a couple of things which it then removes but they re-appear again when the system is rebooted.

    I cant for the life of me see anything malicious looking in the logs though :p

    Here is my HJT Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:14:56, on 30/08/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Wakoopa\Wakoopa.exe
    C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\stunnel\stunnel.exe
    C:\Program Files\RealVNC\VNC4\WinVNC4.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Java\jre6\bin\java.exe
    E:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Advertising Cookie Opt-out - {8E425EB4-ADBD-4816-B1E8-49BB9DECF034} - C:\Program Files\Google\Advertising Cookie Opt-out\opt_out.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
    O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
    O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O4 - HKCU\..\Run: [Wakoopa] C:\Program Files\Wakoopa\Wakoopa.exe
    O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O8 - Extra context menu item: Download with &FD - C:\Program Files\FreshDevices\FreshDownload\fdiectx.htm
    O8 - Extra context menu item: StumbleUpon: &Blog This - res://StumbleUponIEBar.dll/blogimage
    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O15 - Trusted Zone: *.stumbleupon.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1223924430421
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: stunnel - Unknown owner - C:\Program Files\stunnel\stunnel.exe
    O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
    O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
    O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
    O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
    O23 - Service: wampapache - Apache Software Foundation - C:\Program Files\WAMP\bin\apache\apache2.2.6\bin\httpd.exe
    O23 - Service: wampmysqld - Unknown owner - C:\Program Files\WAMP\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

    --
    End of file - 5688 bytes



    Thanks

  2. #2
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Hello and welcome to Safer Networking.

    My name is km2357 and I will be helping you to remove any infection(s) that you may have.

    I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

    If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

    Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

    Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

    I will be back as soon as possible with your first instructions!
    Malware Removal University Master
    Member of ASAP & UNITE

  3. #3
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Looking over your log, it seems you don't have any evidence of an anti-virus software.

    Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these vendors NOW:

    1)Antivir PersonalEdition Classic
    2)avast! 4 Home Edition

    Download and install only one!



    Step # 1 Download and run DDS

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.




    Step # 2: Download and Run Gmer

    Please download gmer.zip from Gmer and save it to your desktop.

    ***Please close any open programs ***

    Double-click gmer.exe. The program will begin to run.

    **Caution**
    These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst


    If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click No.
    • Once the scan is complete, you may receive another notice about rootkit activity.
    • Click OK.
    • GMER will produce a log. Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.

    If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
    • Click the Scan button and let the program do its work. GMER will produce a log.
    • Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.


    DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

    Please post the results from the GMER scan in your reply.


    In your next post/reply, I need to see the following:

    1. The two DDS logs (DDS and attach.txt)
    2. The GMER Log
    Malware Removal University Master
    Member of ASAP & UNITE

  4. #4
    Junior Member
    Join Date
    Aug 2009
    Posts
    9

    Default

    Thanks for the reply, here are the logs:

    DDS.txt


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Colin at 14:35:57.75 on 03/09/2009
    Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1515 [GMT 1:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Wakoopa\Wakoopa.exe
    C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\stunnel\stunnel.exe
    C:\Program Files\RealVNC\VNC4\WinVNC4.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    E:\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyServer = 127.0.0.1:8080
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Advertising Cookie Opt-out: {8e425eb4-adbd-4816-b1e8-49bb9decf034} - c:\program files\google\advertising cookie opt-out\opt_out.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Tunebite_WebRipPlugin Class: {aa102584-3b97-47e7-b9bc-75d54c110a7d} - c:\program files\rapidsolution\tunebite\plugins\ie\TB_WebRipIePlugin.dll
    BHO: IE DOM Explorer: {cc7e636d-39aa-49b6-b511-65413da137a1} - c:\program files\internet explorer developer toolbar\IEDevToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.30.0\gears.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll
    TB: Developer Toolbar: {cc962137-2e78-4f94-975e-fc0c07dbd78f} - c:\program files\internet explorer developer toolbar\IEDevToolbar.dll
    EB: IE DOM Explorer: {a202b231-ef71-4a08-bdb9-4ce5ae8bde0a} - c:\program files\internet explorer developer toolbar\IEDevToolbar.dll
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [Wakoopa] c:\program files\wakoopa\Wakoopa.exe
    uRun: [Taskbar Shuffle] c:\program files\taskbar shuffle\taskbarshuffle.exe
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    uPolicies-explorer: MaxRecentDocs = 1 (0x1)
    uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
    IE: Download with &FD - c:\program files\freshdevices\freshdownload\fdiectx.htm
    IE: StumbleUpon: &Blog This - StumbleUponIEBar.dll/blogimage
    IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.30.0\gears.dll
    IE: {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - {CC962137-2E78-4F94-975E-FC0C07DBD78F} - c:\program files\internet explorer developer toolbar\IEDevToolbar.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: digitalriver.com
    Trusted Zone: stumbleupon.com
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223924430421
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SSODL: EnhancedDialog - {6D972050-A934-44D7-AC67-7C9E0B264220} - c:\program files\stardock\object desktop\enhanceddialog\enhdlginit.dll
    SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll
    LSA: Authentication Packages = msv1_0 relog_ap

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\colin\applic~1\mozilla\firefox\profiles\uiyu3vyl.default\
    FF - component: c:\program files\google\google gears\firefox\lib\ff30\gears.dll
    FF - component: c:\program files\rapidsolution\tunebite\plugins\geckobased\tunebite-firefox-surf-and-catch-extension@audials.com\components\TB_WebRipFFPlugin.dll
    FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\rapidsolution\tunebite\plugins\geckobased\tunebite-firefox-surf-and-catch-extension@audials.com\plugins\np_TB_OgloPlugin.dll
    FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2008-10-12 40464]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-3 335240]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-9-3 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-3 108552]
    R1 NetBurn;Paragon NetBurning Driver;c:\windows\system32\drivers\NetBurn.sys [2008-6-7 84752]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-9-3 908056]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-9-3 297752]
    R2 SocketLock;Raw Socket Lock Driver;c:\windows\system32\socketlock.sys [2008-10-12 3712]
    S3 DOSMEMIO;MEMIO;\??\j:\memio.sys --> j:\MEMIO.SYS [?]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
    S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2007-4-23 83208]
    S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [2007-4-23 15112]
    S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [2007-4-23 108680]
    S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [2007-4-23 100488]
    S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [2007-4-23 98568]
    S3 vmserverdWin32;VMware Registration Service;c:\program files\vmware\vmware server\vmserverdWin32.exe [2008-5-9 1650781]
    S3 wimmount;wimmount;c:\windows\system32\drivers\wimmount.sys [2008-12-12 20232]
    S4 gupdate1c97cc432b80608;Google Update Service (gupdate1c97cc432b80608);c:\program files\google\update\GoogleUpdate.exe [2009-7-25 133104]
    S4 NetBurnerService;Net Burner iSCSI Service;c:\program files\paragon software\drive backup 9 professional\net burner service\NetBurnerService.exe [2008-6-7 223248]
    S4 TeamViewer4;TeamViewer 4;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2009-5-18 185640]

    =============== Created Last 30 ================

    2009-09-03 14:34 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
    2009-09-03 14:34 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-09-03 14:34 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-09-03 14:34 <DIR> --d----- c:\windows\system32\drivers\Avg
    2009-09-03 14:34 <DIR> --d----- c:\program files\AVG
    2009-09-03 14:34 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
    2009-09-03 14:29 <DIR> --d----- c:\docume~1\colin\applic~1\AVG8
    2009-08-30 15:05 <DIR> --d----- c:\program files\SpywareBlaster
    2009-08-30 12:46 <DIR> --d----- c:\documents and settings\colin\.thumb
    2009-08-30 12:46 <DIR> --d----- c:\program files\DVDStyler
    2009-08-20 17:25 <DIR> --d----- c:\program files\Hasbro
    2009-08-20 17:24 20,818,736 a------- c:\docume~1\colin\applic~1\Monopoly 2008.exe
    2009-08-20 17:18 <DIR> --d----- c:\program files\Image Grabber II
    2009-08-20 13:46 <DIR> --d----- c:\program files\Virtual Earth 3D
    2009-08-09 09:52 <DIR> --d----- c:\docume~1\colin\applic~1\Free Download Manager
    2009-08-09 09:52 <DIR> --d----- c:\program files\Free Download Manager
    2009-08-09 09:50 <DIR> --d----- c:\program files\FreshDevices
    2009-08-09 09:39 <DIR> --d----- c:\program files\FlashGet
    2009-08-08 19:17 <DIR> --d----- c:\docume~1\colin\applic~1\VisualWget
    2009-08-08 19:15 <DIR> --d----- c:\program files\VisualWget
    2009-08-08 19:02 <DIR> --d----- c:\docume~1\colin\applic~1\NeoDownloader
    2009-08-05 12:49 <DIR> --d----- c:\docume~1\colin\applic~1\MACiOZO
    2009-08-05 12:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\MACiOZO
    2009-08-05 12:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Trymedia
    2009-08-05 12:48 <DIR> --d----- c:\program files\LEGO Fever

    ==================== Find3M ====================

    2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-24 12:15 67,072 a------- c:\windows\system32\drivers\vsfocemqlrgwru.sys
    2009-07-14 22:09 9,216 a------- c:\windows\nvapi.dll
    2009-07-14 22:07 410,984 a------- c:\windows\system32\deploytk.dll
    2007-02-12 19:10 2,682,880 -------- c:\documents and settings\all users\VCREDI~3.EXE
    2006-05-03 10:06 163,328 a--shr-- c:\windows\system32\flvDX.dll
    2007-02-21 11:47 31,232 a--shr-- c:\windows\system32\msfDX.dll
    2007-12-17 13:43 27,648 a--sh--- c:\windows\system32\Smab0.dll

    ============= FINISH: 14:37:23.31 ===============


    Gmer.txt


    GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
    Rootkit quick scan 2009-09-03 14:49:36
    Windows 5.1.2600 Service Pack 3


    ---- System - GMER 1.0.15 ----

    Code 89FDB880 ZwEnumerateKey
    Code 8A033590 ZwFlushInstructionCache
    Code 89FFB546 ZwSaveKey
    Code 8A010906 ZwSaveKeyEx
    Code 89FBB296 IofCallDriver
    Code 89F38296 IofCompleteRequest

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 8A9721F8

    AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

    Device \Driver\Tcpip \Device\Ip socketlock.sys

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Tcpip \Device\Tcp socketlock.sys

    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Tcpip \Device\Udp socketlock.sys

    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Tcpip \Device\RawIp socketlock.sys

    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\kbiwkmomkamxxm.sys (*** hidden *** ) [SYSTEM] kbiwkmesqgicqa <-- ROOTKIT !!!

    ---- EOF - GMER 1.0.15 ----


    Attach.txt is in the attached zip file.


    Thanks

  5. #5
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Attach.txt is in the attached zip file.
    I get an error when trying to unzip attach.zip.

    Go ahead and just post the contents of Attach.txt in your next post/reply.

    Thanks.
    Malware Removal University Master
    Member of ASAP & UNITE

  6. #6
    Junior Member
    Join Date
    Aug 2009
    Posts
    9

    Default

    Attach.txt


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12/10/2008 13:05:55
    System Uptime: 09/03/2009 14:22:21 (4272 hours ago)

    Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7125
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket 939 | 2010/201mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 50 GiB total, 13.522 GiB free.
    D: is FIXED (NTFS) - 50 GiB total, 6.747 GiB free.
    E: is FIXED (NTFS) - 133 GiB total, 89.157 GiB free.
    F: is FIXED (NTFS) - 932 GiB total, 578.314 GiB free.
    G: is FIXED (NTFS) - 932 GiB total, 50.123 GiB free.
    H: is FIXED (NTFS) - 932 GiB total, 390.792 GiB free.
    I: is CDROM ()
    J: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
    Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_058C1462&REV_15\4&14AECDB0&0&0060
    Manufacturer: Marvell
    Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
    PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_058C1462&REV_15\4&14AECDB0&0&0060
    Service: yukonwxp

    ==== System Restore Points ===================

    RP260: 20/08/2009 15:18:48 - System Checkpoint
    RP261: 20/08/2009 15:18:48 - System Checkpoint
    RP262: 20/08/2009 15:18:48 - Installed HDD Regenerator.
    RP263: 20/08/2009 15:18:48 - System Checkpoint
    RP264: 20/08/2009 15:18:48 - System Checkpoint
    RP265: 20/08/2009 15:18:48 - System Checkpoint
    RP266: 20/08/2009 15:18:48 - System Checkpoint
    RP267: 20/08/2009 15:18:48 - System Checkpoint
    RP268: 20/08/2009 15:18:48 - System Checkpoint
    RP269: 20/08/2009 15:18:49 - System Checkpoint
    RP270: 20/08/2009 15:18:49 - System Checkpoint
    RP271: 20/08/2009 15:18:49 - System Checkpoint
    RP272: 20/08/2009 15:18:49 - System Checkpoint
    RP273: 20/08/2009 15:18:49 - System Checkpoint
    RP274: 20/08/2009 15:18:49 - System Checkpoint

    ==== Installed Programs ======================

    ACDSee
    Acronis*True*Image
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop CS
    Adobe Reader 8.1.4
    Adobe Shockwave Player 11
    Application Suite
    ATI Display Driver (Omega 3.8.442)
    Audiosurf
    AVG Free 8.5
    Bing Maps 3D
    Bioshock
    CCleaner (remove only)
    Chartcross GPSTest
    Choice Guard
    Color Cop
    Counter-Strike: Source
    Crazy Browser
    Dell Driver Download Manager
    Driving Theory Test Professional
    Ducati World Championship
    DVD Decrypter
    DVD Shrink
    DVDStyler v1.7.3
    FileZilla Client
    FlashBoot
    Free Download Manager 2.0
    Free&Easy Font Viewer
    Garry's Mod
    GetBot
    GetDataBack for FAT and GetDataBack for NTFS
    Google Advertising Cookie Opt-out
    Google Gears
    Google Update Helper
    Half-Life 2
    Half-Life 2: Deathmatch
    Half-Life 2: Lost Coast
    Hard Disk Low Level Format Tool
    HDD Capacity Restore
    HDD Regenerator
    HijackThis 2.0.2
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP USB Disk Storage Format Tool
    Huawei Modems
    I-Fluid
    Image Grabber II
    ImgBurn
    Impulse
    Intel(R) Processor ID Utility
    Internet Explorer Collection 1.4.0.0
    Internet Explorer Developer Toolbar
    Java(TM) 6 Update 14
    K-Lite Mega Codec Pack
    LEGO Fever (remove only)
    Live Usb Helper
    LiveReg (Symantec Corporation)
    LiveUpdate 1.80 (Symantec Corporation)
    Malwarebytes' Anti-Malware
    Messenger Plus! Live
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft .NET Framework 3.0 Service Pack 1
    Microsoft .NET Framework 3.5
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office FrontPage 2003
    Microsoft Office Live Add-in 1.3
    Microsoft Office Professional Edition 2003
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Mozilla Firefox (3.0.13)
    MSConfig CleanUp
    MSVCRT
    MSXML 6.0 Parser
    Nero 7 Ultra Edition
    NVIDIA Drivers
    Nvu 1.0
    Paragon Drive Backup™ 9 Professional
    Paragon Partition Manager
    PC Inspector smart recovery
    PCI Audio Driver
    Peggle Extreme
    PixiePack Codec Pack
    Portal
    Prey
    PrimoPDF -- brought to you by Nitro PDF Software
    Radeon Omega Drivers v4.8.442 Setup Files and Tools
    Realtek AC'97 Audio
    Reaxxion
    Remove on Reboot Shell Extension
    ResHacker
    Security Update for Windows Media Encoder (KB954156)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB958644)
    Segoe UI
    Skype™ 3.8
    SpeedFan
    SPORE™
    Spybot - Search & Destroy
    SpywareBlaster 4.2
    Stardock Central
    Steam
    StumbleUpon IE Toolbar
    stunnel
    SUPER
    Synergy
    Taskbar Shuffle
    TeamViewer 4 Host
    Tunebite
    TuneUp Utilities 2007
    Tweak UI
    Update for Windows XP (KB898461)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    USB Video Device
    VideoLAN VLC media player
    Virtual Desktop Manager Powertoy for Windows XP
    VisualWget 2.0b3rev1
    VMware Server
    VNC
    Wakoopa
    WampServer
    WebFldrs XP
    Winamp
    Windows Automated Installation Kit
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Encoder 9 Series
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinPcap
    WinRAR archiver
    WinSCP
    Wireshark
    X-Chat
    XML Paper Specification Shared Components Pack 1.0
    Ycopy 1.0d

    ==== Event Viewer Messages From Past Week ========

    30/08/2009 15:33:43, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    30/08/2009 13:45:30, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    30/08/2009 13:45:01, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdPPM Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip UimBus Uim_IM
    30/08/2009 13:45:01, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    30/08/2009 13:45:01, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    30/08/2009 13:45:01, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    30/08/2009 13:45:01, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    30/08/2009 13:43:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    30/08/2009 12:03:48, error: ati2mtag [45062] - CRT invalid display type

    ==== End Of File ===========================



    Thanks

  7. #7
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Step # 1: Download and Run ComboFix

    Download ComboFix from any of the links below. You must rename it before saving it. Save it to your desktop.

    Link 1
    Link 2





    --------------------------------------------------------------------

    Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please include C:\ComboFix.txt and a fresh HiJackThis Log in your next reply so we can continue cleaning the system.


    Use multiple posts if you can't fit everything into one post.

    Note:
    Do not mouseclick combofix's window while it's running. That may cause it to stall
    Malware Removal University Master
    Member of ASAP & UNITE

  8. #8
    Junior Member
    Join Date
    Aug 2009
    Posts
    9

    Default

    Combo-Fix log


    ComboFix 09-09-03.02 - Colin 03/09/2009 23:31.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1559 [GMT 1:00]
    Running from: E:\Combo-Fix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\$recycle.bin\S-1-5-21-1844777888-1334603955-2330895487-1000
    c:\$recycle.bin\S-1-5-21-3798779890-1755164031-1987388742-1001
    c:\$recycle.bin\S-1-5-21-859717620-1026242230-2079068911-1001
    c:\windows\Installer\1218b0.msp
    c:\windows\Installer\129989.msp
    c:\windows\Installer\145581.msp
    c:\windows\Installer\19fdde.msp
    c:\windows\Installer\1a2df7.msp
    c:\windows\Installer\1faa0f5.msp
    c:\windows\Installer\28a25.msp
    c:\windows\Installer\2c769c3.msp
    c:\windows\Installer\2d334.msp
    c:\windows\Installer\2d572f7.msp
    c:\windows\Installer\2ee00.msp
    c:\windows\Installer\2fa766.msp
    c:\windows\Installer\31057f.msp
    c:\windows\Installer\335f5.msp
    c:\windows\Installer\3b8c2.msp
    c:\windows\Installer\3d1d8.msp
    c:\windows\Installer\3ee3ea.msp
    c:\windows\Installer\41928f.msp
    c:\windows\Installer\47aba.msp
    c:\windows\Installer\47ac1.msp
    c:\windows\Installer\4cd03de.msp
    c:\windows\Installer\60050.msp
    c:\windows\Installer\701d3b.msp
    c:\windows\Installer\799dca.msp
    c:\windows\Installer\878f2.msp
    c:\windows\Installer\878f9.msp
    c:\windows\Installer\8d59f.msp
    c:\windows\Installer\ca0f.msi
    c:\windows\Installer\d7bba9.msp
    c:\windows\Installer\e7144.msp
    c:\windows\Installer\ed36be.msp
    c:\windows\Installer\WMEncoder.msi
    c:\windows\system32\drivers\kbiwkmomkamxxm.sys
    c:\windows\system32\kbiwkmbpyojdcj.dat
    c:\windows\system32\kbiwkmllvfyxun.dat
    c:\windows\system32\kbiwkmmaowujby.dll
    c:\windows\system32\kbiwkmuodjkcka.dll
    c:\windows\system32\nbfrpcod.ini

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_kbiwkmesqgicqa
    -------\Legacy_kbiwkmesqgicqa


    ((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
    .

    2009-09-03 14:10 . 2009-09-03 14:48 -------- d--h--w- C:\$AVG8.VAULT$
    2009-09-03 13:34 . 2009-09-03 13:34 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-09-03 13:34 . 2009-09-03 13:34 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-09-03 13:34 . 2009-09-03 13:34 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-09-03 13:34 . 2009-09-03 13:34 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-09-03 13:34 . 2009-09-03 13:34 -------- d-----w- c:\windows\system32\drivers\Avg
    2009-09-03 13:34 . 2009-09-03 13:34 -------- d-----w- c:\program files\AVG
    2009-09-03 13:34 . 2009-09-03 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-09-03 13:29 . 2009-09-03 13:29 -------- d-----w- c:\documents and settings\Colin\Application Data\AVG8
    2009-08-30 14:05 . 2009-08-30 14:10 -------- d-----w- c:\program files\SpywareBlaster
    2009-08-30 11:46 . 2009-08-30 11:46 -------- d-----w- c:\documents and settings\Colin\.thumb
    2009-08-30 11:46 . 2009-08-30 11:46 -------- d-----w- c:\program files\DVDStyler
    2009-08-20 16:25 . 2009-08-20 16:25 -------- d-----w- c:\program files\Hasbro
    2009-08-20 16:18 . 2009-08-20 16:19 -------- d-----w- c:\program files\Image Grabber II
    2009-08-20 14:20 . 2009-08-20 14:20 -------- d-----w- c:\documents and settings\Colin\Local Settings\Application Data\Russell_Joyce
    2009-08-20 12:46 . 2009-08-20 12:46 -------- d-----w- c:\documents and settings\Colin\Local Settings\Application Data\IsolatedStorage
    2009-08-20 12:46 . 2009-08-20 12:46 -------- d-----w- c:\program files\Virtual Earth 3D
    2009-08-09 08:52 . 2009-08-09 17:48 -------- d-----w- c:\documents and settings\Colin\Application Data\Free Download Manager
    2009-08-09 08:52 . 2009-08-09 08:52 -------- d-----w- c:\program files\Free Download Manager
    2009-08-09 08:50 . 2009-08-09 08:50 -------- d-----w- c:\program files\FreshDevices
    2009-08-09 08:39 . 2009-08-09 08:42 -------- d-----w- c:\program files\FlashGet
    2009-08-08 18:17 . 2009-08-08 18:17 -------- d-----w- c:\documents and settings\Colin\Application Data\VisualWget
    2009-08-08 18:15 . 2009-08-08 18:15 -------- d-----w- c:\program files\VisualWget
    2009-08-08 18:02 . 2009-08-08 18:02 -------- d-----w- c:\documents and settings\Colin\Application Data\NeoDownloader
    2009-08-05 11:49 . 2009-08-05 11:49 -------- d-----w- c:\documents and settings\Colin\Application Data\MACiOZO
    2009-08-05 11:49 . 2009-08-05 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\MACiOZO
    2009-08-05 11:49 . 2009-08-05 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
    2009-08-05 11:48 . 2009-08-05 11:49 -------- d-----w- c:\program files\LEGO Fever

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-03 18:40 . 2008-10-12 13:36 -------- d-----w- c:\program files\Crazy Browser
    2009-09-03 14:58 . 2008-10-23 19:05 -------- d-----w- c:\program files\Steam
    2009-09-03 13:22 . 2008-10-12 13:49 -------- d-----w- c:\program files\Taskbar Shuffle
    2009-08-22 14:13 . 2008-10-12 13:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-08-22 14:04 . 2008-10-24 09:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-22 14:00 . 2008-10-12 13:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-22 13:21 . 2008-10-16 18:00 -------- d-----w- c:\documents and settings\Colin\Application Data\GetBot
    2009-08-20 16:24 . 2009-08-20 16:24 20818736 ----a-w- c:\documents and settings\Colin\Application Data\Monopoly 2008.exe
    2009-08-09 14:06 . 2008-10-12 13:25 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware
    2009-08-09 12:11 . 2009-01-07 14:33 -------- d-----w- c:\documents and settings\Colin\Application Data\VMware
    2009-08-09 11:53 . 2008-10-12 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
    2009-08-06 12:03 . 2008-11-14 02:43 -------- d-----w- c:\documents and settings\Colin\Application Data\uTorrent
    2009-08-06 11:49 . 2008-10-12 13:14 -------- d-----w- c:\program files\UltraISO
    2009-08-03 12:36 . 2008-10-24 09:29 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 12:36 . 2008-10-24 09:29 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-08-03 11:29 . 2008-10-26 14:05 -------- d-----w- c:\documents and settings\Colin\Application Data\FileZilla
    2009-07-26 20:56 . 2008-10-12 13:33 -------- d-----w- c:\program files\X-Chat 2
    2009-07-25 21:47 . 2009-07-25 21:42 -------- d-----w- c:\program files\Google
    2009-07-25 10:25 . 2008-10-12 13:47 -------- d-----w- c:\program files\SpeedFan
    2009-07-24 10:59 . 2009-07-24 10:54 -------- d-----w- c:\program files\HDD Regenerator
    2009-07-24 10:56 . 2009-07-24 10:54 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-07-18 11:38 . 2008-10-12 13:27 -------- d-----w- c:\program files\ColorCop
    2009-07-16 12:25 . 2009-01-15 10:51 -------- d-----w- c:\program files\Messenger Plus! Live
    2009-07-14 21:26 . 2009-07-14 21:26 -------- d-----w- c:\documents and settings\Colin\Application Data\backupClientAdminAccess
    2009-07-14 21:24 . 2009-07-14 21:24 -------- d-----w- c:\documents and settings\Colin\Application Data\Ocster Backup
    2009-07-14 21:24 . 2009-07-14 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Ocster Backup
    2009-07-14 21:09 . 2009-07-14 21:09 -------- d-----w- c:\documents and settings\Colin\Application Data\NetView
    2009-07-14 21:09 . 2009-07-14 21:09 9216 ----a-w- c:\windows\nvapi.dll
    2009-07-14 21:08 . 2009-07-14 21:05 -------- d-----w- c:\program files\Areca
    2009-07-14 21:07 . 2009-07-14 21:07 410984 ----a-w- c:\windows\system32\deploytk.dll
    2009-07-14 21:07 . 2009-07-14 21:07 -------- d-----w- c:\program files\Java
    2009-06-09 17:15 . 2009-06-20 11:25 37664 ----a-w- c:\windows\system32\drivers\tbhsd.sys
    2006-05-03 09:06 . 2008-10-12 13:44 163328 --sha-r- c:\windows\system32\flvDX.dll
    2007-02-21 10:47 . 2008-10-12 13:44 31232 --sha-r- c:\windows\system32\msfDX.dll
    2007-12-17 12:43 . 2008-10-12 13:44 27648 --sha-w- c:\windows\system32\Smab0.dll
    .

    ------- Sigcheck -------

    [-] 2008-04-14 04:42 1032704 A787EB28EB622570B3A1CB7F471FA679 c:\windows\explorer.exe
    [-] 2002-12-15 00:00 1004032 A82B28BFC2E4455FE43022A498C0EF0A c:\windows\$NtServicePackUninstall$\explorer.exe
    [-] 2008-04-14 04:42 1032704 A787EB28EB622570B3A1CB7F471FA679 c:\windows\ServicePackFiles\i386\explorer.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wakoopa"="c:\program files\Wakoopa\Wakoopa.exe" [2008-10-08 552960]
    "Taskbar Shuffle"="c:\program files\Taskbar Shuffle\taskbarshuffle.exe" [2008-04-17 818176]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-23 3885408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-03 2007832]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "MaxRecentDocs"= 1 (0x1)
    "NoRecentDocsNetHood"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
    2008-09-22 16:59 174328 ----a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-09-03 13:34 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^Colin^Start Menu^Programs^Startup^ap]
    path=c:\documents and settings\Colin\Start Menu\Programs\Startup\ap
    backup=c:\windows\pss\apStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "WMPNetworkSvc"=3 (0x3)
    "WLSetupSvc"=3 (0x3)
    "ose"=3 (0x3)
    "idsvc"=3 (0x3)
    "ATI Smart"=2 (0x2)
    "Ati HotKey Poller"=2 (0x2)
    "Adobe LM Service"=3 (0x3)
    "TeamViewer4"=2 (0x2)
    "MDM"=2 (0x2)
    "JavaQuickStarterService"=2 (0x2)
    "gupdate1c97cc432b80608"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\WAMP\\bin\\apache\\apache2.2.6\\bin\\httpd.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [12/10/2008 13:24 40464]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03/09/2009 14:34 335240]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [03/09/2009 14:34 108552]
    R1 NetBurn;Paragon NetBurning Driver;c:\windows\system32\drivers\NetBurn.sys [07/06/2008 15:54 84752]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [03/09/2009 14:34 908056]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03/09/2009 14:34 297752]
    R2 SocketLock;Raw Socket Lock Driver;c:\windows\system32\socketlock.sys [12/10/2008 14:47 3712]
    S3 DOSMEMIO;MEMIO;\??\j:\memio.sys --> j:\MEMIO.SYS [?]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06/11/2007 21:22 34064]
    S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [23/04/2007 14:54 83208]
    S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [23/04/2007 14:54 15112]
    S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [23/04/2007 14:54 108680]
    S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [23/04/2007 14:54 100488]
    S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [23/04/2007 14:54 98568]
    S3 vmserverdWin32;VMware Registration Service;c:\program files\VMware\VMware Server\vmserverdWin32.exe [09/05/2008 21:05 1650781]
    S3 wimmount;wimmount;c:\windows\system32\drivers\wimmount.sys [12/12/2008 23:59 20232]
    S4 gupdate1c97cc432b80608;Google Update Service (gupdate1c97cc432b80608);c:\program files\Google\Update\GoogleUpdate.exe [25/07/2009 22:42 133104]
    S4 NetBurnerService;Net Burner iSCSI Service;c:\program files\Paragon Software\Drive Backup 9 Professional\Net Burner Service\NetBurnerService.exe [07/06/2008 15:54 223248]
    S4 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [18/05/2009 14:13 185640]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
    c:\program files\PixiePack Codec Pack\InstallerHelper.exe
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyServer = 127.0.0.1:8080
    IE: Download with &FD - c:\program files\FreshDevices\FreshDownload\fdiectx.htm
    IE: StumbleUpon: &Blog This - StumbleUponIEBar.dll/blogimage
    Trusted Zone: digitalriver.com
    Trusted Zone: stumbleupon.com
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Colin\Application Data\Mozilla\Firefox\Profiles\uiyu3vyl.default\
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff30\gears.dll
    FF - component: c:\program files\RapidSolution\Tunebite\plugins\GeckoBased\tunebite-firefox-surf-and-catch-extension@audials.com\components\TB_WebRipFFPlugin.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\RapidSolution\Tunebite\plugins\GeckoBased\tunebite-firefox-surf-and-catch-extension@audials.com\plugins\np_TB_OgloPlugin.dll
    FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-03 23:35
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1957994488-606747145-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1148)
    c:\windows\system32\Ati2evxx.dll
    c:\progra~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll

    - - - - - - - > 'lsass.exe'(1204)
    c:\windows\system32\relog_ap.dll
    .
    Completion time: 2009-09-03 23:37
    ComboFix-quarantined-files.txt 2009-09-03 22:37

    Pre-Run: 14,089,211,904 bytes free
    Post-Run: 14,498,328,576 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP"
    [spybotsd]
    timeout.old=20

    249 --- E O F --- 2008-11-04 18:09



    Fresh HJT Log


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:43:48, on 03/09/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\stunnel\stunnel.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\RealVNC\VNC4\WinVNC4.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Advertising Cookie Opt-out - {8E425EB4-ADBD-4816-B1E8-49BB9DECF034} - C:\Program Files\Google\Advertising Cookie Opt-out\opt_out.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
    O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
    O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [Wakoopa] C:\Program Files\Wakoopa\Wakoopa.exe
    O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O8 - Extra context menu item: Download with &FD - C:\Program Files\FreshDevices\FreshDownload\fdiectx.htm
    O8 - Extra context menu item: StumbleUpon: &Blog This - res://StumbleUponIEBar.dll/blogimage
    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.30.0\gears.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O15 - Trusted Zone: *.stumbleupon.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1223924430421
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: stunnel - Unknown owner - C:\Program Files\stunnel\stunnel.exe
    O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
    O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
    O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
    O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
    O23 - Service: wampapache - Apache Software Foundation - C:\Program Files\WAMP\bin\apache\apache2.2.6\bin\httpd.exe
    O23 - Service: wampmysqld - Unknown owner - C:\Program Files\WAMP\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

    --
    End of file - 6774 bytes


    Thanks

  9. #9
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Step # 1 Upload Files

    Go to Jotti
    Copy the following line into the white textbox:
    c:\windows\explorer.exe
    Click Submit.
    Please post the results of this scan to this thread.

    If Jotti is busy, Go to VirusTotal and scan the file(s) there.
    Malware Removal University Master
    Member of ASAP & UNITE

  10. #10
    Junior Member
    Join Date
    Aug 2009
    Posts
    9

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •