Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

serious prob acessing web

  • 10-12-2008 12:13am
    #1
    Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭


    :mad:

    hi guys,
    ive been infected with something and i cant access the inmternet through traditional means. Im currently posting here using a path through msn. For a few months now ive been getting constant popups about ringtones/american green cards etc. Ive tried ad bl;ockers and blocking the pop p urls but they kept on coming. Only 30ins ago i couldn't log on. I use firefox and IE but neither would work, then up pops a pop up... i use the adress bar in the pop up and get online. Imeadiately i log on here and go through the sticky on getting rid of maalware and virus's, but when i get to step 2 the Malwarebytes' Anti-Malware application pauses after about 28sec having found at least 20 infections and crashes/stalls. As a result i go back to my registery point (as advised to set) but now the Malwarebytes' Anti-Malware application isnt there anymore... and i cant get online AND the pop ups seem to have stopped !!!
    Please advise help or guide me in getting rid of whatever is causing this....
    thanks a million in advance....

    admin, im sorry about the long post


Comments

  • Registered Users, Registered Users 2 Posts: 16,288 ✭✭✭✭ntlbell


    boot into safe mode

    run spyware blaster

    spy bot search and destroy

    ad-aware and get rid of as many as you can

    use firefox in future install adblock plus and no-script

    and stay off the porn sites etc

    setup a normal user account no admin priv's and use this for day to day useage dont be browsing as administrator


  • Closed Accounts Posts: 68 ✭✭numbnuts


    Please download ATF Cleaner by Atribune from http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25 . Save it to your Desktop.

    Run ATF Cleaner
    Double-click ATF-Cleaner.exe to run the program.
    Click Select All found at the bottom of the list.
    Click the Empty Selected button.
    Click Exit on the Main menu to close the program.
    Shutdown/restart the computer.

    Now boot into safe mode and run Malwarebytes.

    When the scan is complete, click OK, then Show Results to view the results.
    Be sure that everything is checked, and click Remove Selected.
    When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Please post contents of that file in your next reply.

    numbnuts..


  • Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


    hi numbnuts,
    i carried out what you said and i have posted the reults below...it seems a lot of info but maybe im just ignorant:

    Thanks for your time so far (i'll hang around 10mins but i may have to wait till tomorrow to carry out any further instructions as im shattered and might do something wrong).... still getting the annoying popups but can access the net through firefox and IE at the moment..

    Malwarebytes' Anti-Malware 1.31
    Database version: 1479
    Windows 5.1.2600 Service Pack 3

    10/12/2008 01:18:44
    mbam-log-2008-12-10 (01-18-44).txt

    Scan type: Quick Scan
    Objects scanned: 54571
    Time elapsed: 3 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 22
    Registry Values Infected: 10
    Registry Data Items Infected: 0
    Folders Infected: 12
    Files Infected: 26

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f3487350-ee58-4eba-9eab-db13f04120a6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{f3487350-ee58-4eba-9eab-db13f04120a6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ultra soft (Rogue.Multiple) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\WakeNet (Trojan.Adware) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3wPlayer_is1 (Trojan.Adware) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jojagunije (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm239faa44 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3wplayer service (Trojan.Adware) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\netsearchsoft.com (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.netsearchsoft.com (Malware.Trace) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\skins (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\3wPlayer (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\glenn\Application Data\ultra (Rogue.Multiple) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Program Files\3wPlayer\wakeservice.exe (Trojan.Adware) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\bayunivu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\hutikovu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\kagavuva.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\~.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\settings.dat.bak (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\settings.ini (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\settings.stp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\SkinCrafterDll.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\test.gif (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\unins000.dat (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\unins000.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files\3wPlayer\skins\PlayerSkin.skf (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\3wPlayer\3wPlayer.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\3wPlayer\Uninstall 3wPlayer.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\glenn\Application Data\ultra\uninstall.bat (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\csrcs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32:kb11.exe (Rootkit.ADS) -> Quarantined and deleted successfully.
    C:\WINDOWS\INF\ultra.inf (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\INF\ultra.PNF (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Documents and Settings\glenn\Desktop\3wPlayer-1.9.0.0-setup-0593.exe (Trojan.Adware) -> Quarantined and deleted successfully.


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3


    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    RcAuto1.gif


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    whatnext.png


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


  • Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


    just finished carrying out that scan with Combofix. Heres is the log it provided at the end... it seems quite long. Imstill getting the annoying pop ups, but for the moment i dont have to access the web through msn....

    Any advice would be great as its all gibberish to me unfortunately.....
    thanks again



    ComboFix 08-12-09.03 - glenn 2008-12-10 23:09:57.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.495 [GMT 0:00]
    Running from: c:\documents and settings\glenn\Desktop\ComboFix.exe
    * Resident AV is active

    .
    ADS - system32: deleted 113 bytes in 1 streams.

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\~.exe
    c:\windows\system32\AutoRun.inf
    c:\windows\system32\bekehutu.dll
    c:\windows\system32\borababu.dll
    c:\windows\system32\dufizige.dll
    c:\windows\system32\ewekobem.ini
    c:\windows\system32\fibideja.dll
    c:\windows\system32\fosepoyo.dll
    c:\windows\system32\mebokewe.dll
    c:\windows\system32\nasiliyu.dll
    c:\windows\system32\reperizu.dll
    c:\windows\system32\vuwilamu.dll
    c:\windows\system32\wekenopo.dll

    .
    ((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
    .

    2008-12-10 01:14 . 2008-12-10 01:14 <DIR> d
    c:\documents and settings\glenn\Application Data\Malwarebytes
    2008-12-10 01:10 . 2008-12-10 01:11 <DIR> d
    c:\documents and settings\Administrator\Application Data\MSN6
    2008-12-10 00:53 . 2008-12-10 00:53 <DIR> d
    c:\documents and settings\Administrator\Application Data\Malwarebytes
    2008-12-10 00:53 . 2008-12-03 19:52 38,496 --a
    c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
    2008-12-10 00:53 . 2008-12-03 19:52 15,504 --a
    c:\windows\SYSTEM32\DRIVERS\mbam.sys
    2008-12-10 00:02 . 2008-12-10 00:04 <DIR> d
    c:\documents and settings\glenn\Application Data\MSN6
    2008-12-10 00:02 . 2008-12-10 00:02 <DIR> d
    c:\documents and settings\All Users\Application Data\MSN6
    2008-12-09 23:22 . 2008-12-10 00:53 <DIR> d
    c:\program files\Malwarebytes' Anti-Malware
    2008-12-09 23:22 . 2008-12-09 23:22 <DIR> d
    c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-09 23:15 . 2008-12-09 23:15 <DIR> d
    c:\program files\09-12-2008
    2008-12-09 23:14 . 2005-10-20 12:00 157,696 --a
    c:\program files\ERUNT.EXE
    2008-12-09 23:14 . 2005-10-20 12:03 140,288 --a
    c:\program files\NTREGOPT.EXE
    2008-12-09 23:14 . 2005-10-20 12:04 38,912 --a
    c:\program files\AUTOBACK.EXE
    2008-12-09 23:14 . 2002-09-25 03:11 5,417 --a
    c:\program files\LOC_GER.ZIP
    2008-12-02 23:53 . 2008-12-02 23:53 0 -rahs---- C:\khr
    2008-11-12 22:31 . 2008-09-04 17:15 1,106,944
    c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
    2008-11-12 22:31 . 2008-10-24 11:21 455,296
    c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-09 22:49
    d
    w c:\program files\Java
    2008-12-04 20:47
    d
    w c:\documents and settings\glenn\Application Data\uTorrent
    2008-11-18 18:50
    d
    w c:\program files\McAfee
    2008-11-01 23:47
    d
    w c:\program files\livetvbar
    2008-11-01 23:47
    d
    w c:\program files\Conduit
    2008-10-26 14:50
    d
    w c:\documents and settings\glenn\Application Data\Media Player Classic
    2008-10-26 00:29
    d
    w c:\program files\SopCast
    2008-10-25 17:32
    d
    w c:\program files\K-Lite Codec Pack
    2008-10-25 17:11
    d
    w c:\documents and settings\glenn\Application Data\vlc
    2008-10-25 17:02
    d
    w c:\program files\VideoLAN
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-17 15:39
    d
    w c:\documents and settings\All Users\Application Data\McAfee
    2008-03-10 13:34 3,199,933 ----a-w c:\program files\Setup-SopCast-3.0.0-2008-3-10.exe
    2006-12-03 02:27 2,581 ----a-w c:\program files\bjg.html
    2006-12-03 02:26 2,581 ----a-w c:\program files\bjg.txt
    2006-10-11 09:19 94,208 ----a-w c:\program files\max9keygen.exe
    2005-10-20 12:05 31,952 ----a-w c:\program files\README.TXT
    2005-10-20 12:04 38,994 ----a-w c:\program files\LIESMICH.TXT
    2005-10-20 12:02 163,328 ----a-w c:\program files\ERDNT.E_E
    2002-09-25 03:11 2,815 ----a-w c:\program files\ERDNTDOS.LOC
    2002-09-25 03:09 3,275 ----a-w c:\program files\ERDNTWIN.LOC
    2002-09-25 02:57 1,960 ----a-w c:\program files\NTREGOPT.LOC
    2001-11-24 04:01 4,090 ----a-w c:\program files\ERUNT.LOC
    2001-08-22 12:15 245,760 ----a-w c:\windows\INF\i386\viceo.dll
    2001-08-22 12:13 61,440 ----a-w c:\windows\INF\i386\gl.dll
    2001-08-22 12:13 32,768 ----a-w c:\windows\INF\i386\Pmicro.dll
    2001-08-03 17:29 13,824 ----a-w c:\windows\INF\i386\Usbscan.sys
    1999-07-18 19:05 15,716 ----a-w c:\windows\INF\i386\Pmxscan.sys
    2007-05-31 14:05 1,667,072 ----a-w c:\program files\mozilla firefox\plugins\fluxcore.dll
    2006-07-28 11:29 36,864 ----a-w c:\program files\mozilla firefox\plugins\fluxcryp.dll
    2007-05-31 14:06 307,200 ----a-w c:\program files\mozilla firefox\plugins\fluxdx8.dll
    2007-05-31 14:06 61,440 ----a-w c:\program files\mozilla firefox\plugins\HawkNL.dll
    2008-03-02 23:37 80 --sh--r c:\windows\SYSTEM32\D72A3A57A3.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-06 68856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-08-11 4112384]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
    "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
    "MPSExe"="c:\program files\McAfee.com\MPS\mscifapp.exe" [2003-07-02 225280]
    "EPSON Stylus Photo R320 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9XE.EXE" [2004-12-16 98304]
    "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-01-20 200704]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "Love default global mess"="c:\documents and settings\All Users\Application Data\great coal love default\dart burn.exe" [2008-12-10 5071360]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-16 185896]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\glenn\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-10-04 24576]
    TabUserW.exe.lnk - c:\windows\SYSTEM32\WTablet\TabUserW.exe [2008-07-09 114688]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.divxa32"= msaud32_divx.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\utorrent.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
    "c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
    "c:\\Program Files\\Autodesk\\backburner\\server.exe"=
    "c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\WINDOWS\\SYSTEM32\\wuauclt.exe"=
    "c:\\WINDOWS\\SYSTEM32\\dla\\tfswctrl.exe"=
    "c:\\Program Files\\QuickTime\\qttask.exe"=
    "c:\\Program Files\\McAfee\\VirusScan\\mcvsmap.exe"=
    "c:\\WINDOWS\\SYSTEM32\\cscript.exe"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

    S3 MA8630C;MA8630C;c:\windows\system32\DRIVERS\MA8630C.sys [2007-03-03 22992]
    S3 MA8630M;MA8630M;c:\windows\system32\DRIVERS\MA8630M.sys [2007-03-03 24148]
    S3 MA8630U;MA8630U;c:\windows\system32\DRIVERS\MA8630U.sys [2007-03-03 55634]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dff2909e-af29-11dd-a21f-0011113e5144}]
    \Shell\AutoRun\command - H:\djlvgy.exe
    \Shell\explore\Command - H:\djlvgy.exe
    \Shell\open\Command - H:\djlvgy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{27E9163A-80DB-FA8A-8D41-1998E47B9051}]
    c:\windows\system32:kb11.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-10 c:\windows\Tasks\B4924E7298E9C46E.job
    - c:\docume~1\glenn\applic~1\savedr~1\forkmealsurf.exe [2008-07-24 07:57]

    2008-09-15 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]

    2008-05-01 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{f3487350-ee58-4eba-9eab-db13f04120a6} - c:\windows\system32\dufizige.dll
    HKCU-Run-Body Camp - c:\docume~1\glenn\APPLIC~1\SAVEDR~1\city debug internet.exe
    HKLM-Run-VirusScan - c:\progra~1\mcafee.com\vso\mcvsshld.exe


    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.euro.dell.com/countries/ie/enu/gen/default.htm
    uInternet Connection Wizard,ShellNext = hxxp://uk.mcafee.com/apps/vso/en-gb/vso8/setexp.asp?regwiz=file://c:\program%20files\mcafee.com\agent\mcregwiz.exe&systempopup=true&affid=105-24&dtag=4XY791J
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    LSP: c:\windows\System32\mclsp.dll

    c:\windows\SYSTEM32\unicows.dll - c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader4.ocx
    O16 -: {05CDEE1D-D109-4992-B72B-6D4F5E2AB731}
    hxxp://static.photobox.co.uk/sg/common/ImageUploader4.cab
    c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader4.inf
    FireFox -: Profile - c:\documents and settings\glenn\Application Data\Mozilla\Firefox\Profiles\dn7i5poo.default\
    FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-10 23:14:27
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'lsass.exe'(784)
    c:\windows\System32\mclsp.dll
    c:\windows\system32\SPORDER.dll
    c:\windows\System32\mclsphlr\gdlsphlr.dll
    c:\windows\system32\McRtl32.dll
    .
    Other Running Processes
    .
    c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\Common Files\McAfee\MNA\McNASvc.exe
    c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
    c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
    c:\program files\McAfee\MPF\MpfSrv.exe
    c:\windows\SYSTEM32\nvsvc32.exe
    c:\windows\SYSTEM32\Tablet.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\progra~1\McAfee.com\Agent\mcagent.exe
    c:\program files\Internet Explorer\iexplore.exe
    c:\program files\Internet Explorer\iexplore.exe
    c:\windows\SoftwareDistribution\Download\cfbc39150cce12d1357ba324d4d0c40c\update\update.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-10 23:25:08 - machine was rebooted [glenn]
    ComboFix-quarantined-files.txt 2008-12-10 23:24:56

    Pre-Run: 111,822,462,976 bytes free
    Post-Run: 111,602,536,448 bytes free

    218 --- E O F --- 2008-12-09 23:13:57


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Do this

    Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum.


  • Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


    thanks for the advice. I carried through as you posted but on the reboot following the scan the SDFix window opened and has not progressed for over 20mins...


    Finishing Malware Check
    Please be patient...

    ^C^C^CtERMINATE BATCH JOB Y/N?

    Is all its saying in the window. I have just pressed N key and Enter but it is still the same???

    im gonna have to go to bed as im up for wrk in 5hrs. I will check back in the morning please post any further advice. Thanks again


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Plug your H: drive in for this

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text in the quotebox below into it:
    File::
    C:\khr
    c:\program files\bjg.html
    c:\program files\bjg.txt
    c:\program files\max9keygen.exe
    H:\djlvgy.exe

    Folder::

    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dff2909e-af29-11dd-a21f-0011113e5144}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{27E9163A-80DB-FA8A-8D41-1998E47B9051}]
    [-HKEY_CLASSES_ROOT\CLSID\{27E9163A-80DB-FA8A-8D41-1998E47B9051}]

    ADS::
    c:\windows\system32

    Driver::

    Save this as CFScript.txt, in the same location as ComboFix.exe


    CFScriptB-4.gif

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


  • Registered Users, Registered Users 2 Posts: 16,288 ✭✭✭✭ntlbell


    if you did a reinstall it'd of been fixed yesterday ;)


  • Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


    Hi Actor,
    just completed what you asked and here is the text from the log. Any ideas what the problem is ?

    ComboFix 08-12-09.03 - glenn 2008-12-11 17:27:41.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.616 [GMT 0:00]
    Running from: c:\documents and settings\glenn\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\glenn\Desktop\CFScript.txt
    * Created a new restore point
    * Resident AV is active


    FILE ::
    C:\khr
    c:\program files\bjg.html
    c:\program files\bjg.txt
    c:\program files\max9keygen.exe
    H:\djlvgy.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\khr
    c:\program files\bjg.html
    c:\program files\bjg.txt
    c:\program files\max9keygen.exe

    .
    ((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
    .

    2008-12-11 00:53 . 2008-12-11 00:53 578,560 --a
    c:\windows\SYSTEM32\DLLCACHE\user32.dll
    2008-12-11 00:50 . 2008-12-11 00:50 <DIR> d
    c:\windows\ERUNT
    2008-12-11 00:43 . 2008-12-11 01:06 <DIR> d
    C:\SDFix
    2008-12-11 00:29 . 2008-12-11 00:29 <DIR> d
    c:\program files\Common Files\Wise Installation Wizard
    2008-12-11 00:06 . 2008-12-11 17:24 <DIR> d
    c:\program files\Spybot - Search & Destroy
    2008-12-11 00:06 . 2008-12-11 17:24 <DIR> d
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-11 00:00 . 2008-12-11 00:02 <DIR> d
    c:\program files\SpywareBlaster
    2008-12-11 00:00 . 2008-12-11 00:30 <DIR> d-a
    c:\documents and settings\All Users\Application Data\TEMP
    2008-12-10 23:38 . 2008-12-10 23:39 <DIR> d
    c:\documents and settings\home pc
    2008-12-10 23:22 . 2008-12-10 23:24 1,393 --a
    c:\windows\imsins.BAK
    2008-12-10 01:14 . 2008-12-10 01:14 <DIR> d
    c:\documents and settings\glenn\Application Data\Malwarebytes
    2008-12-10 01:10 . 2008-12-10 01:11 <DIR> d
    c:\documents and settings\Administrator\Application Data\MSN6
    2008-12-10 00:53 . 2008-12-10 00:53 <DIR> d
    c:\documents and settings\Administrator\Application Data\Malwarebytes
    2008-12-10 00:53 . 2008-12-03 19:52 38,496 --a
    c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
    2008-12-10 00:53 . 2008-12-03 19:52 15,504 --a
    c:\windows\SYSTEM32\DRIVERS\mbam.sys
    2008-12-10 00:02 . 2008-12-10 00:04 <DIR> d
    c:\documents and settings\glenn\Application Data\MSN6
    2008-12-10 00:02 . 2008-12-10 00:02 <DIR> d
    c:\documents and settings\All Users\Application Data\MSN6
    2008-12-09 23:22 . 2008-12-10 00:53 <DIR> d
    c:\program files\Malwarebytes' Anti-Malware
    2008-12-09 23:22 . 2008-12-09 23:22 <DIR> d
    c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-09 23:15 . 2008-12-09 23:15 <DIR> d
    c:\program files\09-12-2008
    2008-12-09 23:14 . 2005-10-20 12:00 157,696 --a
    c:\program files\ERUNT.EXE
    2008-12-09 23:14 . 2005-10-20 12:03 140,288 --a
    c:\program files\NTREGOPT.EXE
    2008-12-09 23:14 . 2005-10-20 12:04 38,912 --a
    c:\program files\AUTOBACK.EXE
    2008-12-09 23:14 . 2002-09-25 03:11 5,417 --a
    c:\program files\LOC_GER.ZIP
    2008-11-12 22:31 . 2008-09-04 17:15 1,106,944
    c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
    2008-11-12 22:31 . 2008-10-24 11:21 455,296
    c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-10 23:49
    d
    w c:\program files\Common Files\Autodesk Shared
    2008-12-10 23:49
    d
    w c:\documents and settings\All Users\Application Data\Autodesk
    2008-12-09 22:49
    d
    w c:\program files\Java
    2008-12-04 20:47
    d
    w c:\documents and settings\glenn\Application Data\uTorrent
    2008-11-18 18:50
    d
    w c:\program files\McAfee
    2008-11-01 23:47
    d
    w c:\program files\livetvbar
    2008-11-01 23:47
    d
    w c:\program files\Conduit
    2008-10-26 14:50
    d
    w c:\documents and settings\glenn\Application Data\Media Player Classic
    2008-10-26 00:29
    d
    w c:\program files\SopCast
    2008-10-25 17:32
    d
    w c:\program files\K-Lite Codec Pack
    2008-10-25 17:11
    d
    w c:\documents and settings\glenn\Application Data\vlc
    2008-10-25 17:02
    d
    w c:\program files\VideoLAN
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720
    w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
    2008-10-17 15:39
    d
    w c:\documents and settings\All Users\Application Data\McAfee
    2008-10-17 02:08 3,593,216 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
    2008-10-16 14:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 14:13 202,776 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
    2008-10-16 14:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 14:13 1,809,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
    2008-10-16 14:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 14:12 561,688 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
    2008-10-16 14:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 14:12 323,608 ----a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
    2008-10-16 14:09 92,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
    2008-10-16 14:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 14:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 14:09 51,224 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
    2008-10-16 14:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 14:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 14:08 34,328 ----a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
    2008-10-16 13:11 70,656
    w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
    2008-10-16 13:11 13,824
    w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
    2008-10-15 16:34 337,408
    w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
    2008-10-15 07:06 633,632
    w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
    2008-10-15 07:04 161,792
    w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
    2008-10-03 10:02 247,326 ----a-w c:\windows\SYSTEM32\strmdll.dll
    2008-10-03 10:02 247,326
    w c:\windows\SYSTEM32\DLLCACHE\strmdll.dll
    2008-09-30 16:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
    2008-09-15 12:12 1,846,400 ----a-w c:\windows\SYSTEM32\win32k.sys
    2008-09-15 12:12 1,846,400
    w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
    2008-03-10 13:34 3,199,933 ----a-w c:\program files\Setup-SopCast-3.0.0-2008-3-10.exe
    2005-10-20 12:05 31,952 ----a-w c:\program files\README.TXT
    2005-10-20 12:04 38,994 ----a-w c:\program files\LIESMICH.TXT
    2005-10-20 12:02 163,328 ----a-w c:\program files\ERDNT.E_E
    2002-09-25 03:11 2,815 ----a-w c:\program files\ERDNTDOS.LOC
    2002-09-25 03:09 3,275 ----a-w c:\program files\ERDNTWIN.LOC
    2002-09-25 02:57 1,960 ----a-w c:\program files\NTREGOPT.LOC
    2001-11-24 04:01 4,090 ----a-w c:\program files\ERUNT.LOC
    2001-08-22 12:15 245,760 ----a-w c:\windows\INF\i386\viceo.dll
    2001-08-22 12:13 61,440 ----a-w c:\windows\INF\i386\gl.dll
    2001-08-22 12:13 32,768 ----a-w c:\windows\INF\i386\Pmicro.dll
    2001-08-03 17:29 13,824 ----a-w c:\windows\INF\i386\Usbscan.sys
    1999-07-18 19:05 15,716 ----a-w c:\windows\INF\i386\Pmxscan.sys
    2007-05-31 14:05 1,667,072 ----a-w c:\program files\mozilla firefox\plugins\fluxcore.dll
    2006-07-28 11:29 36,864 ----a-w c:\program files\mozilla firefox\plugins\fluxcryp.dll
    2007-05-31 14:06 307,200 ----a-w c:\program files\mozilla firefox\plugins\fluxdx8.dll
    2007-05-31 14:06 61,440 ----a-w c:\program files\mozilla firefox\plugins\HawkNL.dll
    2008-03-02 23:37 80 --sh--r c:\windows\SYSTEM32\D72A3A57A3.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-12-10_23.23.49.71 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
    + 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
    + 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
    + 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
    + 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
    + 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
    + 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
    + 2008-08-07 15:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
    + 2008-12-11 00:50:49 8,187,904 ----a-w c:\windows\ERUNT\SDFIX\Users\00000001\ntuser.dat
    + 2008-12-11 00:50:49 311,296 ----a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
    + 2008-08-07 15:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
    + 2008-12-11 00:50:48 8,187,904 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
    + 2008-12-11 00:50:48 311,296 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
    + 2008-08-26 07:24:28 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
    + 2008-08-26 07:24:28 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
    + 2008-08-26 07:24:28 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
    + 2008-08-26 07:24:28 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
    + 2008-08-26 07:24:28 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
    + 2008-08-25 08:37:59 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
    + 2008-08-26 07:24:28 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
    + 2008-08-26 07:24:28 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
    + 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
    + 2008-08-26 07:24:28 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
    + 2008-08-26 07:24:29 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
    + 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
    + 2008-08-26 07:24:29 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
    + 2008-08-26 07:24:29 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
    + 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
    + 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
    + 2008-08-26 07:24:30 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
    + 2008-08-26 07:24:30 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
    + 2008-08-26 07:24:30 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
    + 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
    + 2008-08-26 07:24:30 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
    + 2008-08-26 07:24:30 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
    + 2008-08-26 07:24:30 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
    + 2008-08-26 07:24:30 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
    + 2008-08-26 07:24:30 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
    + 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
    + 2008-08-26 07:24:30 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
    + 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
    + 2008-08-26 07:24:31 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
    + 2008-08-26 07:24:31 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
    - 2008-08-26 07:24:28 124,928 ----a-w c:\windows\SYSTEM32\advpack.dll
    + 2008-10-16 20:38:34 124,928 ----a-w c:\windows\SYSTEM32\advpack.dll
    - 2008-12-10 23:05:13 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
    + 2008-12-11 17:19:30 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
    - 2008-12-10 23:05:13 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
    + 2008-12-11 17:19:30 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
    - 2008-08-26 07:24:28 124,928
    w c:\windows\SYSTEM32\DLLCACHE\advpack.dll
    + 2008-10-16 20:38:34 124,928
    w c:\windows\SYSTEM32\DLLCACHE\advpack.dll
    - 2008-08-26 07:24:28 347,136 ----a-w c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
    + 2008-10-16 20:38:34 347,136 ----a-w c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
    - 2008-08-26 07:24:28 214,528 ----a-w c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
    + 2008-10-16 20:38:34 214,528 ----a-w c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
    - 2008-08-26 07:24:28 133,120 ----a-w c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
    + 2008-10-16 20:38:35 133,120 ----a-w c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
    - 2008-08-26 07:24:28 63,488
    w c:\windows\SYSTEM32\DLLCACHE\icardie.dll
    + 2008-10-16 20:38:35 63,488
    w c:\windows\SYSTEM32\DLLCACHE\icardie.dll
    - 2008-08-26 07:24:28 153,088
    w c:\windows\SYSTEM32\DLLCACHE\ieakeng.dll
    + 2008-10-16 20:38:35 153,088
    w c:\windows\SYSTEM32\DLLCACHE\ieakeng.dll
    - 2008-08-26 07:24:28 230,400
    w c:\windows\SYSTEM32\DLLCACHE\ieaksie.dll
    + 2008-10-16 20:38:35 230,400
    w c:\windows\SYSTEM32\DLLCACHE\ieaksie.dll
    - 2008-08-26 07:24:28 383,488
    w c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dll
    + 2008-10-16 20:38:35 383,488
    w c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dll
    - 2008-08-26 07:24:29 384,512
    w c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
    + 2008-10-16 20:38:35 384,512
    w c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
    - 2008-10-03 17:41:15 6,066,176
    w c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
    + 2008-10-16 20:38:37 6,066,176
    w c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
    - 2008-08-26 07:24:29 44,544
    w c:\windows\SYSTEM32\DLLCACHE\iernonce.dll
    + 2008-10-16 20:38:37 44,544
    w c:\windows\SYSTEM32\DLLCACHE\iernonce.dll
    - 2008-08-26 07:24:29 267,776
    w c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
    + 2008-10-16 20:38:37 267,776
    w c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
    - 2008-08-26 07:24:30 27,648 ----a-w c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
    + 2008-10-16 20:38:37 27,648 ----a-w c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
    + 2008-06-18 01:09:22 100,864
    w c:\windows\SYSTEM32\DLLCACHE\logagent.exe
    - 2008-08-26 07:24:30 459,264
    w c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
    + 2008-10-16 20:38:37 459,264
    w c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
    - 2008-08-26 07:24:30 52,224
    w c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
    + 2008-10-16 20:38:37 52,224
    w c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
    - 2008-08-26 07:24:30 477,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
    + 2008-10-16 20:38:38 477,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
    - 2008-08-26 07:24:30 193,024 ----a-w c:\windows\SYSTEM32\DLLCACHE\msrating.dll
    + 2008-10-16 20:38:38 193,024 ----a-w c:\windows\SYSTEM32\DLLCACHE\msrating.dll
    - 2008-08-26 07:24:30 671,232 ----a-w c:\windows\SYSTEM32\DLLCACHE\mstime.dll
    + 2008-10-16 20:38:39 671,232 ----a-w c:\windows\SYSTEM32\DLLCACHE\mstime.dll
    - 2008-08-26 07:24:30 102,912
    w c:\windows\SYSTEM32\DLLCACHE\occache.dll
    + 2008-10-16 20:38:39 102,912
    w c:\windows\SYSTEM32\DLLCACHE\occache.dll
    - 2008-08-26 07:24:30 44,544 ----a-w c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
    + 2008-10-16 20:38:39 44,544 ----a-w c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
    - 2008-08-26 07:24:30 105,984
    w c:\windows\SYSTEM32\DLLCACHE\url.dll
    + 2008-10-16 20:38:39 105,984
    w c:\windows\SYSTEM32\DLLCACHE\url.dll
    - 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
    + 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
    - 2008-08-26 07:24:31 233,472
    w c:\windows\SYSTEM32\DLLCACHE\webcheck.dll
    + 2008-10-16 20:38:39 233,472
    w c:\windows\SYSTEM32\DLLCACHE\webcheck.dll
    - 2008-08-26 07:24:31 826,368 ----a-w c:\windows\SYSTEM32\DLLCACHE\wininet.dll
    + 2008-10-16 20:38:40 826,368 ----a-w c:\windows\SYSTEM32\DLLCACHE\wininet.dll
    + 2008-06-18 05:03:08 938,496
    w c:\windows\SYSTEM32\DLLCACHE\WMNetmgr.dll
    - 2006-10-18 21:47:22 2,450,944
    w c:\windows\SYSTEM32\DLLCACHE\wmvcore.dll
    + 2008-06-18 05:03:14 2,458,112
    w c:\windows\SYSTEM32\DLLCACHE\WMVCore.dll
    - 2008-08-26 07:24:28 347,136 ----a-w c:\windows\SYSTEM32\dxtmsft.dll
    + 2008-10-16 20:38:34 347,136 ----a-w c:\windows\SYSTEM32\dxtmsft.dll
    - 2008-08-26 07:24:28 214,528 ----a-w c:\windows\SYSTEM32\dxtrans.dll
    + 2008-10-16 20:38:34 214,528 ----a-w c:\windows\SYSTEM32\dxtrans.dll
    - 2008-08-26 07:24:28 133,120 ----a-w c:\windows\SYSTEM32\extmgr.dll
    + 2008-10-16 20:38:35 133,120 ----a-w c:\windows\SYSTEM32\extmgr.dll
    - 2008-08-26 07:24:28 63,488 ----a-w c:\windows\SYSTEM32\icardie.dll
    + 2008-10-16 20:38:35 63,488 ----a-w c:\windows\SYSTEM32\icardie.dll
    - 2008-08-25 08:37:59 70,656 ----a-w c:\windows\SYSTEM32\ie4uinit.exe
    + 2008-10-16 13:11:09 70,656 ----a-w c:\windows\SYSTEM32\ie4uinit.exe
    - 2008-08-26 07:24:28 153,088 ----a-w c:\windows\SYSTEM32\ieakeng.dll
    + 2008-10-16 20:38:35 153,088 ----a-w c:\windows\SYSTEM32\ieakeng.dll
    - 2008-08-26 07:24:28 230,400 ----a-w c:\windows\SYSTEM32\ieaksie.dll
    + 2008-10-16 20:38:35 230,400 ----a-w c:\windows\SYSTEM32\ieaksie.dll
    - 2008-08-23 05:54:51 161,792 ----a-w c:\windows\SYSTEM32\ieakui.dll
    + 2008-10-15 07:04:53 161,792 ----a-w c:\windows\SYSTEM32\ieakui.dll
    - 2008-08-26 07:24:28 383,488 ----a-w c:\windows\SYSTEM32\ieapfltr.dll
    + 2008-10-16 20:38:35 383,488 ----a-w c:\windows\SYSTEM32\ieapfltr.dll
    - 2008-08-26 07:24:29 384,512 ----a-w c:\windows\SYSTEM32\iedkcs32.dll
    + 2008-10-16 20:38:35 384,512 ----a-w c:\windows\SYSTEM32\iedkcs32.dll
    - 2008-10-03 17:41:15 6,066,176 ----a-w c:\windows\SYSTEM32\ieframe.dll
    + 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\SYSTEM32\ieframe.dll
    - 2008-08-26 07:24:29 44,544 ----a-w c:\windows\SYSTEM32\iernonce.dll
    + 2008-10-16 20:38:37 44,544 ----a-w c:\windows\SYSTEM32\iernonce.dll
    - 2008-08-26 07:24:29 267,776 ----a-w c:\windows\SYSTEM32\iertutil.dll
    + 2008-10-16 20:38:37 267,776 ----a-w c:\windows\SYSTEM32\iertutil.dll
    - 2008-08-25 08:38:00 13,824 ----a-w c:\windows\SYSTEM32\ieudinit.exe
    + 2008-10-16 13:11:09 13,824 ----a-w c:\windows\SYSTEM32\ieudinit.exe
    - 2008-08-26 07:24:30 27,648 ----a-w c:\windows\SYSTEM32\jsproxy.dll
    + 2008-10-16 20:38:37 27,648 ----a-w c:\windows\SYSTEM32\jsproxy.dll
    - 2006-10-18 20:03:58 100,864 ----a-w c:\windows\SYSTEM32\logagent.exe
    + 2008-06-18 01:09:22 100,864 ----a-w c:\windows\SYSTEM32\logagent.exe
    - 2008-08-26 07:24:30 459,264 ----a-w c:\windows\SYSTEM32\msfeeds.dll
    + 2008-10-16 20:38:37 459,264 ----a-w c:\windows\SYSTEM32\msfeeds.dll
    - 2008-08-26 07:24:30 52,224 ----a-w c:\windows\SYSTEM32\msfeedsbs.dll
    + 2008-10-16 20:38:37 52,224 ----a-w c:\windows\SYSTEM32\msfeedsbs.dll
    - 2008-08-27 08:24:32 3,593,216 ----a-w c:\windows\SYSTEM32\mshtml.dll
    + 2008-10-17 02:08:40 3,593,216 ----a-w c:\windows\SYSTEM32\mshtml.dll
    - 2008-08-26 07:24:30 477,696 ----a-w c:\windows\SYSTEM32\mshtmled.dll
    + 2008-10-16 20:38:38 477,696 ----a-w c:\windows\SYSTEM32\mshtmled.dll
    - 2008-08-26 07:24:30 193,024 ----a-w c:\windows\SYSTEM32\msrating.dll
    + 2008-10-16 20:38:38 193,024 ----a-w c:\windows\SYSTEM32\msrating.dll
    - 2008-08-26 07:24:30 671,232 ----a-w c:\windows\SYSTEM32\mstime.dll
    + 2008-10-16 20:38:39 671,232 ----a-w c:\windows\SYSTEM32\mstime.dll
    - 2008-08-26 07:24:30 102,912 ----a-w c:\windows\SYSTEM32\occache.dll
    + 2008-10-16 20:38:39 102,912 ----a-w c:\windows\SYSTEM32\occache.dll
    - 2008-08-26 07:24:30 44,544 ----a-w c:\windows\SYSTEM32\pngfilt.dll
    + 2008-10-16 20:38:39 44,544 ----a-w c:\windows\SYSTEM32\pngfilt.dll
    - 2008-07-08 13:02:01 17,272
    w c:\windows\SYSTEM32\spmsg.dll
    + 2007-11-30 12:39:22 17,272
    w c:\windows\SYSTEM32\spmsg.dll
    - 2008-12-10 23:13:53 12,911 ----a-w c:\windows\SYSTEM32\tablet.dat
    + 2008-12-11 17:12:58 12,911 ----a-w c:\windows\SYSTEM32\tablet.dat
    - 2008-04-14 00:12:38 60,416
    w c:\windows\SYSTEM32\tzchange.exe
    + 2008-10-23 10:06:59 62,976
    w c:\windows\SYSTEM32\tzchange.exe
    - 2008-08-26 07:24:30 105,984 ----a-w c:\windows\SYSTEM32\url.dll
    + 2008-10-16 20:38:39 105,984 ----a-w c:\windows\SYSTEM32\url.dll
    - 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\SYSTEM32\urlmon.dll
    + 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\SYSTEM32\urlmon.dll
    - 2008-08-26 07:24:31 233,472 ----a-w c:\windows\SYSTEM32\webcheck.dll
    + 2008-10-16 20:38:39 233,472 ----a-w c:\windows\SYSTEM32\webcheck.dll
    - 2008-08-26 07:24:31 826,368 ----a-w c:\windows\SYSTEM32\wininet.dll
    + 2008-10-16 20:38:40 826,368 ----a-w c:\windows\SYSTEM32\wininet.dll
    - 2006-10-18 21:47:20 937,984 ----a-w c:\windows\SYSTEM32\WMNetMgr.dll
    + 2008-06-18 05:03:08 938,496 ----a-w c:\windows\SYSTEM32\WMNetmgr.dll
    - 2006-10-18 21:47:22 2,450,944 ----a-w c:\windows\SYSTEM32\wmvcore.dll
    + 2008-06-18 05:03:14 2,458,112 ----a-w c:\windows\SYSTEM32\WMVCore.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Hello

    Go to Kaspersky website and perform an online antivirus scan.
    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
        Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
        Mail databases
      [*]Click on My Computer under Scan.
      [*]Once the scan is complete, it will display the results. Click on View Scan Report.
      [*]You will see a list of infected items there. Click on Save Report As....
      [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.


    5. Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


      Hi Actor, well it took nearly 2 and a half hrs, but here is the report that Kaspersky provided. Hope this helps with finding out what is wrong with my machine, and more importantly how to fix it.
      Thanks a million for your help so far...
      KASPERSKY ONLINE SCANNER 7 REPORT
      Thursday, December 11, 2008
      Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
      Kaspersky Online Scanner 7 version: 7.0.25.0
      Program database last update: Thursday, December 11, 2008 16:38:22
      Records in database: 1452655

      Scan settings:
      Scan using the following database: extended
      Scan archives: yes
      Scan mail databases: yes

      Scan area - My Computer:
      C:\
      D:\
      E:\
      F:\

      Scan statistics:
      Files scanned: 134383
      Threat name: 4
      Infected objects: 151
      Suspicious objects: 0
      Duration of the scan: 02:54:55


      File name / Threat name / Threats count
      C:\Documents and Settings\All Users\Application Data\great coal love default\dart burn.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\Documents and Settings\glenn\Application Data\Save Draw Defy\forkmealsurf.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\Documents and Settings\glenn\Application Data\Save Draw Defy\jthifgmd.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\Program Files\Common Files\EON Reality\WebPublisher\Redist\eonx_loc.cab Infected: not-a-virus:AdWare.Win32.MyTool.b 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP628\A0040579.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP629\A0040583.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP630\A0040601.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP631\A0040605.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP631\A0040612.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP631\A0040649.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP632\A0040658.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP632\A0040667.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP633\A0040669.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP634\A0040726.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP634\A0040735.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP635\A0040740.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP636\A0040748.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP637\A0040749.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP637\A0040875.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP637\A0040883.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP638\A0040888.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP638\A0040895.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP638\A0040913.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP639\A0040920.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP639\A0040934.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP640\A0040962.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP640\A0040969.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP641\A0040985.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP641\A0041013.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP641\A0041020.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP642\A0041025.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP642\A0041033.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP642\A0041049.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP642\A0041068.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP643\A0041070.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP643\A0041077.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP644\A0041083.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP645\A0041101.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP645\A0041109.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP645\A0041125.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP646\A0042124.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP646\A0042145.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP647\A0042156.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP647\A0042197.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP648\A0042217.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP649\A0042226.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP649\A0042233.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP650\A0042282.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP651\A0042288.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP651\A0042424.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP651\A0042432.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP653\A0042541.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP653\A0046496.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP654\A0046514.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP655\A0046540.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP655\A0046585.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP655\A0046593.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP656\A0046616.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP656\A0046623.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP656\A0046651.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP656\A0046659.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP657\A0046698.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP658\A0046707.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP658\A0046716.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP658\A0046748.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP659\A0046769.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP659\A0046776.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP659\A0046789.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP660\A0047339.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP661\A0047548.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP661\A0047594.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP661\A0047604.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP662\A0047643.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP662\A0047650.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP663\A0047720.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP663\A0047727.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP663\A0047736.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP664\A0047764.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP666\A0047779.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP666\A0047787.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP667\A0047791.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP668\A0047809.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP668\A0047821.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP669\A0047859.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP669\A0047869.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP670\A0047881.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP671\A0047887.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP671\A0047906.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP672\A0047916.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP672\A0047926.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP673\A0047979.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP674\A0047980.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP675\A0048014.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP675\A0048028.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP676\A0048040.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP676\A0048047.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP676\A0048055.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP677\A0048064.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP678\A0048073.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP678\A0048080.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP679\A0048188.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP680\A0048193.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP680\A0048206.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP681\A0048240.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP681\A0048248.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP681\A0048257.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP682\A0048376.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP682\A0048407.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP683\A0048414.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP683\A0048453.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP684\A0048480.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP685\A0048500.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP685\A0048514.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP686\A0048529.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP687\A0048541.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP688\A0048566.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP688\A0048603.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP689\A0048619.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP689\A0048627.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP690\A0048631.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP690\A0048638.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP690\A0048646.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP690\A0048653.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP691\A0048672.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP691\A0048680.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP691\A0048689.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP692\A0048693.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP693\A0048695.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP693\A0048711.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP694\A0048724.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP695\A0048732.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP696\A0048743.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP696\A0048751.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP696\A0048767.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP697\A0048783.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP698\A0048785.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP698\A0048793.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP699\A0048820.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0048870.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0048873.exe Infected: Trojan.Win32.Obfuscated.iwf 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0049122.dll Infected: Trojan.Win32.Monder.abjq 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0049145.exe Infected: Trojan.Win32.Obfuscated.iwf 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0049158.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP703\A0049169.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP705\A0049236.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP705\A0049371.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP706\A0049637.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP706\A0049650.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP706\A0049736.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP706\A0049743.exe Infected: Trojan.Win32.Obfuscated.gen 1
      C:\WINDOWS\Downloaded Installations\{9362648F-972C-4B02-8CAC-FC83D2821F7E}\EON Raptor Web Studio.msi Infected: not-a-virus:AdWare.Win32.MyTool.b 1

      The selected area was scanned.


    6. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      Hello

      1. Close any open browsers.

      2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

      3. Open notepad and copy/paste the text in the quotebox below into it:
      File::
      C:\Program Files\Common Files\EON Reality\WebPublisher\Redist\eonx_loc.cab
      C:\WINDOWS\Downloaded Installations\{9362648F-972C-4B02-8CAC-FC83D2821F7E}\EON Raptor Web Studio.msi

      Folder::
      C:\Documents and Settings\All Users\Application Data\great coal love default
      C:\Documents and Settings\glenn\Application Data\Save Draw Defy

      Registry::

      Driver::

      Save this as CFScript.txt, in the same location as ComboFix.exe


      CFScriptB-4.gif

      Refering to the picture above, drag CFScript into ComboFix.exe

      When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


    7. Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


      hi Actor, here is the latest script.
      any ideas whats going on with it as its all gobbledygook to me im afraid...
      thanks again

      ComboFix 08-12-09.03 - glenn 2008-12-12 10:35:39.3 - NTFSx86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.393 [GMT 0:00]
      Running from: c:\documents and settings\glenn\Desktop\ComboFix.exe
      Command switches used :: c:\documents and settings\glenn\Desktop\CFScript.txt
      * Resident AV is active

      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\All Users\Application Data\great coal love default
      c:\documents and settings\All Users\Application Data\great coal love default\dart burn.exe
      c:\documents and settings\glenn\Application Data\Save Draw Defy
      c:\documents and settings\glenn\Application Data\Save Draw Defy\0
      c:\documents and settings\glenn\Application Data\Save Draw Defy\forkmealsurf.exe
      c:\documents and settings\glenn\Application Data\Save Draw Defy\jthifgmd.exe
      c:\windows\Temp\scsF.tmp
      H:\autorun.inf

      .
      ((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
      .

      2008-12-12 10:32 . 2008-12-12 10:33 <DIR> d
      C:\32788R22FWJFW
      2008-12-11 00:53 . 2008-12-11 00:53 578,560 --a
      c:\windows\SYSTEM32\DLLCACHE\user32.dll
      2008-12-11 00:50 . 2008-12-11 00:50 <DIR> d
      c:\windows\ERUNT
      2008-12-11 00:43 . 2008-12-11 21:37 <DIR> d
      C:\SDFix
      2008-12-11 00:29 . 2008-12-11 00:29 <DIR> d
      c:\program files\Common Files\Wise Installation Wizard
      2008-12-11 00:06 . 2008-12-11 17:24 <DIR> d
      c:\program files\Spybot - Search & Destroy
      2008-12-11 00:06 . 2008-12-11 17:24 <DIR> d
      c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-12-11 00:00 . 2008-12-11 00:02 <DIR> d
      c:\program files\SpywareBlaster
      2008-12-11 00:00 . 2008-12-11 00:30 <DIR> d-a
      c:\documents and settings\All Users\Application Data\TEMP
      2008-12-10 23:38 . 2008-12-10 23:39 <DIR> d
      c:\documents and settings\home pc
      2008-12-10 23:22 . 2008-12-10 23:24 1,393 --a
      c:\windows\imsins.BAK
      2008-12-10 01:14 . 2008-12-10 01:14 <DIR> d
      c:\documents and settings\glenn\Application Data\Malwarebytes
      2008-12-10 01:10 . 2008-12-10 01:11 <DIR> d
      c:\documents and settings\Administrator\Application Data\MSN6
      2008-12-10 00:53 . 2008-12-10 00:53 <DIR> d
      c:\documents and settings\Administrator\Application Data\Malwarebytes
      2008-12-10 00:53 . 2008-12-03 19:52 38,496 --a
      c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
      2008-12-10 00:53 . 2008-12-03 19:52 15,504 --a
      c:\windows\SYSTEM32\DRIVERS\mbam.sys
      2008-12-10 00:02 . 2008-12-10 00:04 <DIR> d
      c:\documents and settings\glenn\Application Data\MSN6
      2008-12-10 00:02 . 2008-12-10 00:02 <DIR> d
      c:\documents and settings\All Users\Application Data\MSN6
      2008-12-09 23:22 . 2008-12-10 00:53 <DIR> d
      c:\program files\Malwarebytes' Anti-Malware
      2008-12-09 23:22 . 2008-12-09 23:22 <DIR> d
      c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-12-09 23:15 . 2008-12-09 23:15 <DIR> d
      c:\program files\09-12-2008
      2008-12-09 23:14 . 2005-10-20 12:00 157,696 --a
      c:\program files\ERUNT.EXE
      2008-12-09 23:14 . 2005-10-20 12:03 140,288 --a
      c:\program files\NTREGOPT.EXE
      2008-12-09 23:14 . 2005-10-20 12:04 38,912 --a
      c:\program files\AUTOBACK.EXE
      2008-12-09 23:14 . 2002-09-25 03:11 5,417 --a
      c:\program files\LOC_GER.ZIP
      2008-11-12 22:31 . 2008-09-04 17:15 1,106,944
      c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
      2008-11-12 22:31 . 2008-10-24 11:21 455,296
      c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-12-10 23:49
      d
      w c:\program files\Common Files\Autodesk Shared
      2008-12-10 23:49
      d
      w c:\documents and settings\All Users\Application Data\Autodesk
      2008-12-09 22:49
      d
      w c:\program files\Java
      2008-12-04 20:47
      d
      w c:\documents and settings\glenn\Application Data\uTorrent
      2008-11-18 18:50
      d
      w c:\program files\McAfee
      2008-11-01 23:47
      d
      w c:\program files\livetvbar
      2008-11-01 23:47
      d
      w c:\program files\Conduit
      2008-10-26 14:50
      d
      w c:\documents and settings\glenn\Application Data\Media Player Classic
      2008-10-26 00:29
      d
      w c:\program files\SopCast
      2008-10-25 17:32
      d
      w c:\program files\K-Lite Codec Pack
      2008-10-25 17:11
      d
      w c:\documents and settings\glenn\Application Data\vlc
      2008-10-25 17:02
      d
      w c:\program files\VideoLAN
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
      2008-10-23 12:36 286,720
      w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
      2008-10-17 15:39
      d
      w c:\documents and settings\All Users\Application Data\McAfee
      2008-10-17 02:08 3,593,216 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
      2008-10-16 14:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
      2008-10-16 14:13 202,776 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
      2008-10-16 14:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
      2008-10-16 14:13 1,809,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
      2008-10-16 14:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
      2008-10-16 14:12 561,688 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
      2008-10-16 14:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
      2008-10-16 14:12 323,608 ----a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
      2008-10-16 14:09 92,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
      2008-10-16 14:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
      2008-10-16 14:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
      2008-10-16 14:09 51,224 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
      2008-10-16 14:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
      2008-10-16 14:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
      2008-10-16 14:08 34,328 ----a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
      2008-10-16 13:11 70,656
      w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
      2008-10-16 13:11 13,824
      w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
      2008-10-15 16:34 337,408
      w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
      2008-10-15 07:06 633,632
      w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
      2008-10-15 07:04 161,792
      w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
      2008-10-03 10:02 247,326 ----a-w c:\windows\SYSTEM32\strmdll.dll
      2008-10-03 10:02 247,326
      w c:\windows\SYSTEM32\DLLCACHE\strmdll.dll
      2008-09-30 16:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
      2008-09-15 12:12 1,846,400 ----a-w c:\windows\SYSTEM32\win32k.sys
      2008-09-15 12:12 1,846,400
      w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
      2008-03-10 13:34 3,199,933 ----a-w c:\program files\Setup-SopCast-3.0.0-2008-3-10.exe
      2005-10-20 12:05 31,952 ----a-w c:\program files\README.TXT
      2005-10-20 12:04 38,994 ----a-w c:\program files\LIESMICH.TXT
      2005-10-20 12:02 163,328 ----a-w c:\program files\ERDNT.E_E
      2002-09-25 03:11 2,815 ----a-w c:\program files\ERDNTDOS.LOC
      2002-09-25 03:09 3,275 ----a-w c:\program files\ERDNTWIN.LOC
      2002-09-25 02:57 1,960 ----a-w c:\program files\NTREGOPT.LOC
      2001-11-24 04:01 4,090 ----a-w c:\program files\ERUNT.LOC
      2001-08-22 12:15 245,760 ----a-w c:\windows\INF\i386\viceo.dll
      2001-08-22 12:13 61,440 ----a-w c:\windows\INF\i386\gl.dll
      2001-08-22 12:13 32,768 ----a-w c:\windows\INF\i386\Pmicro.dll
      2001-08-03 17:29 13,824 ----a-w c:\windows\INF\i386\Usbscan.sys
      1999-07-18 19:05 15,716 ----a-w c:\windows\INF\i386\Pmxscan.sys
      2007-05-31 14:05 1,667,072 ----a-w c:\program files\mozilla firefox\plugins\fluxcore.dll
      2006-07-28 11:29 36,864 ----a-w c:\program files\mozilla firefox\plugins\fluxcryp.dll
      2007-05-31 14:06 307,200 ----a-w c:\program files\mozilla firefox\plugins\fluxdx8.dll
      2007-05-31 14:06 61,440 ----a-w c:\program files\mozilla firefox\plugins\HawkNL.dll
      2008-03-02 23:37 80 --sh--r c:\windows\SYSTEM32\D72A3A57A3.dll
      .

      ((((((((((((((((((((((((((((( snapshot_2008-12-11_17.31.54.01 )))))))))))))))))))))))))))))))))))))))))
      .
      - 2008-12-11 17:19:30 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
      + 2008-12-12 10:32:50 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
      - 2008-12-11 17:19:30 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
      + 2008-12-12 10:32:50 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
      + 2008-12-09 15:24:38 17,593,280 ----a-w c:\windows\SYSTEM32\MRT.exe
      - 2008-12-11 17:12:58 12,911 ----a-w c:\windows\SYSTEM32\tablet.dat
      + 2008-12-12 10:25:31 12,911 ----a-w c:\windows\SYSTEM32\tablet.dat
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-06 68856]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-08-11 4112384]
      "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
      "IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
      "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
      "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
      "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
      "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
      "MPSExe"="c:\program files\McAfee.com\MPS\mscifapp.exe" [2003-07-02 225280]
      "EPSON Stylus Photo R320 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9XE.EXE" [2004-12-16 98304]
      "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-01-20 200704]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
      "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
      "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-16 185896]
      "SDFix"="c:\sdfix\RunThis.bat" [2008-11-06 964661]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

      c:\documents and settings\glenn\Start Menu\Programs\Startup\
      Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-10-04 24576]
      TabUserW.exe.lnk - c:\windows\SYSTEM32\WTablet\TabUserW.exe [2008-07-09 114688]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "msacm.divxa32"= msaud32_divx.acm

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\uTorrent\\utorrent.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=
      "c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
      "c:\\WINDOWS\\SYSTEM32\\wuauclt.exe"=
      "c:\\WINDOWS\\SYSTEM32\\dla\\tfswctrl.exe"=
      "c:\\Program Files\\QuickTime\\qttask.exe"=
      "c:\\Program Files\\McAfee\\VirusScan\\mcvsmap.exe"=
      "c:\\WINDOWS\\SYSTEM32\\cscript.exe"=
      "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

      S3 MA8630C;MA8630C;c:\windows\system32\DRIVERS\MA8630C.sys [2007-03-03 22992]
      S3 MA8630M;MA8630M;c:\windows\system32\DRIVERS\MA8630M.sys [2007-03-03 24148]
      S3 MA8630U;MA8630U;c:\windows\system32\DRIVERS\MA8630U.sys [2007-03-03 55634]
      .
      Contents of the 'Scheduled Tasks' folder

      2008-12-12 c:\windows\Tasks\B4924E7298E9C46E.job
      - c:\docume~1\glenn\applic~1\savedr~1\forkmealsurf.exe []

      2008-09-15 c:\windows\Tasks\McDefragTask.job
      - c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]

      2008-05-01 c:\windows\Tasks\McQcTask.job
      - c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]
      .
      - - - - ORPHANS REMOVED - - - -

      HKLM-Run-Love default global mess - c:\documents and settings\All Users\Application Data\great coal love default\dart burn.exe


      .
      Supplementary Scan
      .
      uStart Page = hxxp://www.euro.dell.com/countries/ie/enu/gen/default.htm
      uInternet Connection Wizard,ShellNext = hxxp://uk.mcafee.com/apps/vso/en-gb/vso8/setexp.asp?regwiz=file://c:\program%20files\mcafee.com\agent\mcregwiz.exe&systempopup=true&affid=105-24&dtag=4XY791J
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      LSP: c:\windows\System32\mclsp.dll

      c:\windows\SYSTEM32\unicows.dll - c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader4.ocx
      O16 -: {05CDEE1D-D109-4992-B72B-6D4F5E2AB731}
      hxxp://static.photobox.co.uk/sg/common/ImageUploader4.cab
      c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader4.inf
      FireFox -: Profile - c:\documents and settings\glenn\Application Data\Mozilla\Firefox\Profiles\dn7i5poo.default\
      FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-12 10:42:30
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...


      c:\docume~1\glenn\LOCALS~1\Temp\Perflib_Perfdata_f6c.dat 16384 bytes

      scan completed successfully
      hidden files: 1

      **************************************************************************
      .
      DLLs Loaded Under Running Processes

      - - - - - - - > 'lsass.exe'(780)
      c:\windows\System32\mclsp.dll
      c:\windows\system32\SPORDER.dll
      c:\windows\System32\mclsphlr\gdlsphlr.dll
      c:\windows\system32\McRtl32.dll
      .
      Completion time: 2008-12-12 10:47:56
      ComboFix-quarantined-files.txt 2008-12-12 10:47:12
      ComboFix2.txt 2008-12-11 17:32:55
      ComboFix3.txt 2008-12-10 23:25:14

      Pre-Run: 111,118,204,928 bytes free
      Post-Run: 111,195,271,168 bytes free

      228 --- E O F --- 2008-12-11 20:04:58


    8. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      Just had a rootkit

      Please download the OTMoveIt3 by OldTimer or from here.
      • Save it to your desktop.
      • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
      • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
        :Processes
        explorer.exe
        
        :Services
        
        :Reg
        
        :Files
        c:\windows\Tasks\B4924E7298E9C46E.job
        c:\docume~1\glenn\applic~1\savedr~1
        
        :Commands
        [purity]
        [emptytemp]
        [start explorer]
        [Reboot]
        
      • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
      • Click the red Moveit! button.
      • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
      • Close OTMoveIt3
      Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




      CLICK HERE to download the HijackThis Installer:
      1. Save HJTInstall.exe to your desktop.
      2. Double-click on HJTInstall.exe to run the program.
      3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
      4. Accept the license agreement by clicking the "I Accept" button.
      5. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
      6. Click "Save log" to save the log file and then the log will open in Notepad.
      7. Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
      8. Come back here to this thread and paste the log in your next reply.
      9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


    9. Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


      my machine aint letting me download the O2moveit3 application, its claimimg that my desktop is write protected?


    10. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      Strange

      Try save it to your C:\ drive and run it from there

      If that fails, boot into safe mode and delete those two things


    11. Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


      alright mate,
      its giving the folowing error when i try and save it to my c/ or desktop...

      Cannot copy OTMovieIt3[1]: Access is denied
      Make sure that disk is not full or write protected and the file is not currently in use

      :confused:


    12. Registered Users, Registered Users 2 Posts: 16,288 ✭✭✭✭ntlbell


      reinstall the OS christ.


    13. Registered Users, Registered Users 2 Posts: 2,337 ✭✭✭positivenote


      could be the best bet alright at this stage ntlbell. how do i go about doing this? i'll have to copoy aload of stuff to my external hard drive and lose a rake load of music.
      oh yeah, i aint got a notion where the os disk is either?


    14. Advertisement
    15. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      Your machine is clean now, if you want to format go ahead but there is no need


    16. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      ntlbell not everybody wants to format, so stop saying it and being an idiot

      If you don't have any good advice, then don't post

      positivenote do this then we are all done here

      Follow these steps to uninstall Combofix and tools used in the removal of malware
      • Click START then RUN
      • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
        CF_Cleanup.png


      • Make sure you have an Internet Connection.
      • Download OTCleanIt to your desktop and run it
      • A list of tool components used in the Cleanup of malware will be downloaded.
      • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
      • Click Yes to beging the Cleanup process and remove these components, including this application.
      • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



      Please download JavaRa to your desktop and unzip it to its own folder
      • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
      • Accept any prompts.
      • Open JavaRa.exe again and select Search For Updates.
      • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



      Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
      http://www.adobe.com/products/acrobat/readstep2.html




      Below I have included a number of recommendations for how to protect your computer against malware infections.

      * Keep Windows updated by regularly checking their website at :
      http://windowsupdate.microsoft.com/
      This will ensure your computer has always the latest security updates available installed on your computer.

      * To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

      SpywareBlaster protects against bad ActiveX

      * SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

      Make Internet Explorer more secure
      • Click Start > Run
      • Type Inetcpl.cpl & click OK
      • Click on the Security tab
      • Click Reset all zones to default level
      • Make sure the Internet Zone is selected & Click Custom level
      • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
      • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


      *ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

      *NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

      *Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

      * MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

      * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
      secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
      blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
      Here

      * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
      Here

      *ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

      * Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

      Thank you for your patience, and performing all of the procedures requested.


    17. Registered Users, Registered Users 2 Posts: 16,288 ✭✭✭✭ntlbell


      ntlbell not everybody wants to format, so stop saying it and being an idiot
      .

      don't call me an idiot.

      It's not a case of wanting to or not, he's been trying now for nearly three days to fix this issue. a reinstall takes an hour.

      If he's had a rootkit or any serious virus then he's better off for peace of mind as well as everything else to reinstall take proper measures in future to prevent it happening and put it down to lesson learned...

      instead of taken a week to try and fix something.

      mind your tone.


    18. Closed Accounts Posts: 17,208 ✭✭✭✭aidan_walsh


      Handbags away please...


    19. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      So it it a week or three days....

      The OP has PMed me saying he doesn't want to reformat, not everybody does. So what should he do then genius since that was your big idea


    20. Closed Accounts Posts: 40 dublinpd


      http://support.microsoft.com/kb/307654 - This could help in having problems with recovery console.


    21. Registered Users, Registered Users 2 Posts: 16,288 ✭✭✭✭ntlbell


      So it it a week or three days....

      The OP has PMed me saying he doesn't want to reformat, not everybody does. So what should he do then genius since that was your big idea

      he should spend a few more days pissing around with various tools to get his machine to a state where he won't know if it's actually secure or not and carry on regardless

      what do you want to hear?


    22. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      I don't want to hear anything from you as your posts are not helpful or needed.


    Advertisement