Hi,
I had encountered a problem in running kaspersky online scanner using IE. I get the following message " Launch of Java application is interrupted! Please establish an unterrupted internet connection for work with this program". My internet connection is fine and I dont get a problem when I try to run with firefox. Should I run using firefox?
Here is the combofix log.
ComboFix 09-12-25.04 - ganesh 12/26/2009 18:33:52.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.247 [GMT -5:00]
Running from: c:\documents and settings\ganesh\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\ganesh\Desktop\CFScript.txt
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Eusing Free Registry Cleaner
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090821175123.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090821175902.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090821180220.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090823204622.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090830210910.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090903184539.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090908131905.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20090920171943.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091011132219.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091018173812.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091025094806.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091101144546.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091115000834.reg
c:\program files\Eusing Free Registry Cleaner\Backup\Backup20091217091250.reg
.
((((((((((((((((((((((((( Files Created from 2009-11-26 to 2009-12-26 )))))))))))))))))))))))))))))))
.
2009-12-26 18:35 . 2009-12-26 18:35 -------- dc----w- C:\DISSERTATION FINAL
2009-12-26 14:11 . 2009-12-26 14:11 -------- d-----w- c:\windows\ERUNT
2009-12-25 02:57 . 2009-12-25 02:59 1924744 ----a-w- c:\documents and settings\ganesh\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-24 16:48 . 2009-12-24 16:48 -------- dc----w- C:\rsit
2009-12-22 19:09 . 2009-12-16 19:42 43008 ----a-w- c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-22 19:09 . 2009-12-16 19:42 340480 ----a-w- c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-22 19:09 . 2009-12-16 19:42 872960 ----a-w- c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-22 19:09 . 2009-12-16 19:41 346624 ----a-w- c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-20 01:35 . 2009-12-20 01:35 -------- d-----w- c:\program files\AC3Filter
2009-12-19 14:23 . 2009-12-19 14:23 -------- d-----w- c:\program files\ERUNT
2009-12-19 13:08 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2009-12-19 13:00 . 2009-12-19 13:00 152576 ----a-w- c:\documents and settings\ganesh\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-19 13:00 . 2009-12-19 13:00 79488 ----a-w- c:\documents and settings\ganesh\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-17 14:30 . 2009-12-03 21:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-17 14:30 . 2009-12-17 14:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-17 14:30 . 2009-12-03 21:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 21:43 . 2009-12-16 21:43 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-15 22:52 . 2009-12-15 22:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-10 03:43 . 2009-12-10 04:25 -------- dc----w- C:\nm7
2009-12-10 03:26 . 2009-12-11 03:14 -------- dc----w- C:\pdxpop4
2009-12-08 15:16 . 2009-12-08 15:18 -------- d-----w- c:\program files\gfortran
2009-12-04 15:03 . 2009-12-04 15:03 251376 ----a-w- c:\documents and settings\ganesh\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-12-01 00:36 . 2009-12-16 18:33 -------- dc----w- C:\HLM
2009-11-27 21:24 . 2009-11-27 21:24 -------- d-----w- c:\documents and settings\ganesh\Application Data\GARMIN
2009-11-27 21:23 . 2009-11-27 21:23 -------- d-----w- c:\program files\Garmin GPS Plugin
2009-11-27 21:23 . 2009-11-27 21:23 -------- d-----w- c:\program files\DIFX
2009-11-27 21:23 . 2009-11-27 21:23 -------- dc----w- c:\windows\system32\DRVSTORE
2009-11-27 21:23 . 2009-11-27 21:23 -------- d-----w- c:\program files\Garmin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-24 13:50 . 2009-08-01 01:08 -------- d-----w- c:\documents and settings\ganesh\Application Data\ZoomBrowser EX
2009-12-24 13:25 . 2008-09-21 19:09 -------- d-----w- c:\program files\Common Files\Pharsight
2009-12-24 13:22 . 2007-05-06 01:59 -------- d-----w- c:\program files\Symantec
2009-12-24 13:22 . 2007-05-06 01:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-24 13:21 . 2007-05-06 01:59 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-24 13:16 . 2009-05-06 02:13 -------- d--h--w- c:\program files\InstallJammer Registry
2009-12-24 13:16 . 2009-05-06 02:11 -------- d-----w- c:\program files\PLTTools
2009-12-24 02:29 . 2008-10-21 03:38 85464 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-20 21:17 . 2008-11-16 03:49 664 ----a-w- c:\documents and settings\ganesh\Local Settings\Application Data\d3d9caps.dat
2009-12-19 13:02 . 2006-04-18 03:39 -------- d-----w- c:\program files\Java
2009-12-13 20:31 . 2009-11-05 19:11 186 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2009-12-09 17:06 . 2009-07-04 01:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-04 19:48 . 2009-02-19 00:33 -------- d-----w- c:\program files\QuickTime
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-08 00:00 . 2009-11-05 19:11 158 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\ssprs.dll
2009-11-06 01:10 . 2009-11-05 19:11 -------- d-----w- c:\documents and settings\ganesh\Application Data\Pharsight
2009-11-05 20:11 . 2009-11-05 19:11 1024 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\grcauth2.dll
2009-11-05 20:11 . 2009-11-05 19:11 1024 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\grcauth1.dll
2009-11-05 20:11 . 2009-11-05 19:11 1024 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\clauth2.dll
2009-11-05 20:11 . 2009-11-05 19:11 1024 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\clauth1.dll
2009-11-05 19:08 . 2007-11-24 00:59 -------- d-----w- c:\program files\Pharsight
2009-11-05 03:42 . 2009-08-01 00:58 -------- d-----w- c:\documents and settings\ganesh\Application Data\CameraWindowDC
2009-11-03 01:42 . 2009-10-03 12:00 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 17:54 . 2006-12-02 15:36 103304 ----a-w- c:\documents and settings\ganesh\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-01 17:11 . 2009-07-04 16:18 -------- d-----w- c:\program files\Microsoft Works
2009-10-29 07:45 . 2005-08-16 09:18 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2005-08-16 09:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 09:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2005-08-16 09:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 09:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 09:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 09:17 . 2008-12-27 16:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-09-28 02:43 . 2008-09-21 19:49 4940 ----a-w- c:\program files\Trial Simulator.wsp
2008-09-21 19:49 . 2008-09-21 19:49 201 ----a-w- c:\program files\LicenseInstallWizard3.log
2008-09-21 19:40 . 2008-09-21 19:40 160883036 ----a-w- c:\program files\TS221.zip
2008-09-21 19:07 . 2008-09-21 19:06 57141408 ----a-w- c:\program files\WinNonlin521.zip
2007-01-26 02:27 . 2006-12-29 00:35 8154264 ----a-w- c:\program files\CleanAccessAgent.exe
2007-01-07 03:04 . 2007-01-07 03:04 165888 ----a-w- c:\program files\Pharmaceutical Industry Internships.doc
2006-12-02 16:18 . 2006-12-02 16:18 18192896 ----a-w- c:\program files\ucvse80isp13Spy5100.exe
2005-08-15 18:54 . 2005-08-15 18:54 442 ----a-w- c:\program files\WinNonlin.pdf
2005-08-15 18:54 . 2005-08-15 18:54 12695132 ----a-w- c:\program files\WinNonlin.msi
2005-08-15 18:54 . 2005-08-15 18:54 1013 ----a-w- c:\program files\Setup.ini
2005-08-15 18:53 . 2005-08-15 18:53 477696 ----a-w- c:\program files\isscript.msi
2005-08-15 18:53 . 2005-08-15 18:53 3673 ----a-w- c:\program files\0x0409.ini
2005-08-15 18:53 . 2005-08-15 18:53 1821008 ----a-w- c:\program files\instmsiw.exe
2005-08-15 18:53 . 2005-08-15 18:53 1707856 ----a-w- c:\program files\instmsia.exe
2008-06-19 09:16 . 2008-06-19 09:16 118784 ----a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2007-03-27 23:33 . 2006-12-19 02:31 56 --sh--r- c:\windows\system32\7A83BC0799.sys
2007-03-11 20:49 . 2006-12-03 18:47 88 --sh--r- c:\windows\system32\9907BC837A.sys
2007-04-22 13:40 . 2007-04-22 13:40 56 --sh--r- c:\windows\system32\B6EC45BF34.sys
2009-04-18 16:47 . 2006-12-03 18:47 7154 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"Google Update"="c:\documents and settings\ganesh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-14 133104]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"VoipRaider"="c:\program files\VoipRaider.com\VoipRaider\VoipRaider.exe" [2009-12-25 9111344]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-02 413696]
"MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [2008-03-26 69632]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 110592]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 8192]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-26 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 21:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^ganesh^Start Menu^Programs^Startup^WordWeb.lnk]
backup=c:\windows\pss\WordWeb.lnkStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"VoipRaider"="c:\program files\VoipRaider.com\VoipRaider\VoipRaider.exe" -nosplash -minimized
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Dell QuickSet"=c:\program files\Dell\QuickSet\quickset.exe
"DLA"=c:\windows\System32\DLA\DLACTRLW.EXE
"ehTray"=c:\windows\ehome\ehtray.exe
"googletalk"=c:\program files\Google\Google Talk\googletalk.exe /autostart
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VoipRaider.com\\VoipRaider\\voipraider.exe"=
"c:\\Documents and Settings\\ganesh\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\ganesh\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
R2 mpich2_smpd;MPICH2 Process Manager, Argonne National Lab;c:\program files\Pharsight\MPICH2\bin\smpd.exe [10/16/2009 1:53 PM 450560]
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
FF - ProfilePath - c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\
FF - component: c:\documents and settings\ganesh\Application Data\Mozilla\Firefox\Profiles\1ernd1cl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\ganesh\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\ganesh\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-26 18:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(696)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-12-26 18:45:39
ComboFix-quarantined-files.txt 2009-12-26 23:45
ComboFix2.txt 2009-12-26 14:45
ComboFix3.txt 2009-09-03 23:24
ComboFix4.txt 2008-12-30 13:47
Pre-Run: 17,338,179,584 bytes free
Post-Run: 17,329,119,232 bytes free
- - End Of File - - BA1E0C32ED885C7AA26C1FBBACAB3466