[Resolved] Virus or Spyware via USB Flash drive (HijackThis log included)

  1. #11
    ThuG_PoeT is offline Elite Member

    re: [Resolved] Virus or Spyware via USB Flash drive (HijackThis log included)

    Yeah Oman Telecommunications Company is my ISP.

    Still unable to go to Safe Mode.
    Task Manager and Registry Editor are working fine now.

    What about the "Media Player Classic" problem?


  2. #12
    broni is offline Senior Member
    Let's go for final cleaning steps, first....

    1. Download, and install CCleaner: CCleaner - Builds. Get "Slim" version.
    Read CCleaner instruction here: CCleaner Manual.
    Run CCleaner.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. Make sure, Windows Updates are current.

    6. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    7. Download, and install WOT (Web OF Trust): Internet Security | WOT Web of Trust. It'll warn you (in most cases) about dangerous web sites.

    8. Read How did I get infected?, With steps so it does not happen again!: How did I get infected?


    Let me know, when You're done, so we can try to solve those two other problems.

  3. #13
    ThuG_PoeT is offline Elite Member
    Ok done... it took me sometime to get the .NET Framework latest update... so what can we do about the other two problems?

  4. #14
    broni is offline Senior Member
    There is only limited access to HJT forum, so since your computer is malware free, I propose, you create new topic under Windows section about your two other problems.

  5. #15
    broni is offline Senior Member
    Reopened, because of this: http://www.d-a-l.com/help/windows-xp...safe-mode.html

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

  6. #16
    ThuG_PoeT is offline Elite Member
    here are the logs:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:59:50 AM, on 10/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
    C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\LClock\LClock.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Razer\Lachesis\razerhid.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\oodag.exe
    C:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
    C:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\UPHClean\uphclean.exe
    C:\oracle\product\10.2.0\db_1\jdk\bin\java.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Razer\Lachesis\OSD.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Razer\Lachesis\razertra.exe
    C:\Program Files\Razer\Lachesis\razerofa.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
    O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
    O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
    O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RegGenie v2.0] "C:\Program Files\RegGenie\RegGenieOnReboot.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [IE7-10] rundll32 advpack.dll,LaunchINFSectionEx NR_IE7en.inf,AfterUserStart,,4,N (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
    O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
    O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
    O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://asia.msi.com.tw
    O15 - Trusted Zone: http://global.msi.com.tw
    O15 - Trusted Zone: http://www.msi.com.tw
    O15 - Trusted Zone: http://download.windowsupdate.com
    O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/micr...?1203861047687
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupda...01/CTSUEng.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1203861024281
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/Driver...aSmartScan.cab
    O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobio...ne/install.cab
    O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) - http://officeint.microsoft.com/offic...tent/opuc4.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupda...5106/CTPID.cab
    O17 - HKLM\System\CS1\Services\Tcpip\..\{93C9F370-603E-4462-8DCD-066A10DAC118}: NameServer = 202.188.0.133,202.188.1.5
    O17 - HKLM\System\CS5\Services\Tcpip\..\{93C9F370-603E-4462-8DCD-066A10DAC118}: NameServer = 202.188.0.133,202.188.1.5
    O17 - HKLM\System\CS7\Services\Tcpip\..\{93C9F370-603E-4462-8DCD-066A10DAC118}: NameServer = 202.188.0.133,202.188.1.5
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
    O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
    O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
    O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    O23 - Service: OracleDBConsoleorcl - Unknown owner - E:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe (file missing)
    O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
    O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
    O23 - Service: OracleServiceORCL - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 11548 bytes
    Attached Files

  7. #17
    broni is offline Senior Member
    ComboFix 09-06-09.06 - MaK 10/06/2009 2:36.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2421 [GMT 4:00]
    Running from: c:\documents and settings\MaK\Desktop\ComboFix.exe
    AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\msvrc20.dll
    c:\windows\system32\_000006_.tmp.dll
    c:\windows\system32\_000009_.tmp.dll
    c:\windows\system32\dumphive.exe
    c:\windows\system32\IEDFix.exe
    c:\windows\system32\Process.exe
    c:\windows\system32\SrchSTS.exe
    c:\windows\system32\tmp.reg
    c:\windows\system32\VCCLSID.exe
    c:\windows\system32\WS2Fix.exe

    .
    ((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
    .

    2009-06-08 00:49 . 2009-06-08 00:49 -------- d-----w- C:\Hotspot Shield
    2009-06-07 23:11 . 2009-06-07 23:11 -------- d-----w- c:\documents and settings\MaK\Local Settings\Application Data\RadarSync
    2009-06-07 23:11 . 2009-06-07 23:11 -------- d-----w- c:\program files\RadarSync
    2009-06-07 23:01 . 2009-06-08 00:11 -------- d-----w- c:\documents and settings\MaK\Local Settings\Application Data\eSupport.com
    2009-06-07 22:25 . 2009-05-04 11:07 2298680 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\npTVUAx.dl l
    2009-06-07 22:25 . 2008-03-04 14:52 286720 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\libcurl.dl l
    2009-06-07 22:25 . 2007-10-31 05:39 59904 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\zlib1.dll
    2009-06-07 22:25 . 2007-05-17 09:58 143360 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\libexpatw. dll
    2009-06-07 22:25 . 2006-10-18 13:32 499712 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\msvcp71.dl l
    2009-06-07 22:25 . 2006-10-18 13:32 348160 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\msvcr71.dl l
    2009-06-07 22:25 . 2006-10-16 14:44 196608 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\ssleay32.d ll
    2009-06-07 22:25 . 2006-10-16 14:44 1028096 ----a-w- c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\libeay32.d ll
    2009-06-07 22:17 . 2005-05-13 06:52 176128 ----a-w- c:\windows\system32\nvusmb.exe
    2009-06-07 12:48 . 2009-06-07 22:33 -------- d-----w- C:\NVIDIA
    2009-05-21 10:09 . 2009-05-21 10:09 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    2009-05-12 19:19 . 2009-05-12 19:19 -------- d-----w- c:\documents and settings\MaK\Application Data\MXit
    2009-05-12 19:19 . 2009-05-12 19:19 -------- d-----w- c:\program files\MXit
    2009-05-12 14:31 . 2009-05-12 17:08 -------- d-----w- c:\documents and settings\MaK\Application Data\%#@_&^
    2009-05-11 00:20 . 2008-01-23 21:25 27136 ----a-w- c:\windows\system32\drivers\tapvpn.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2009-06-09 22:32 . 2007-08-15 14:33 -------- d-----w- c:\documents and settings\MaK\Application Data\uTorrent
    2009-06-09 22:29 . 2007-09-15 07:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
    2009-06-09 22:26 . 2007-09-15 07:39 99310880 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2009-06-09 22:26 . 2007-09-15 07:39 5357344 --sha-w- c:\windows\system32\drivers\fidbox2.dat
    2009-06-09 22:26 . 2007-09-15 07:39 497912 --sha-w- c:\windows\system32\drivers\fidbox2.idx
    2009-06-09 22:26 . 2007-09-15 07:39 1332968 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2009-06-09 22:25 . 2006-02-25 03:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-08 00:49 . 2009-01-23 21:09 -------- d-----w- c:\program files\Hotspot Shield
    2009-06-08 00:07 . 2007-08-15 14:32 -------- d-----w- c:\program files\Orbitdownloader
    2009-06-07 23:40 . 2007-08-15 14:32 -------- d-----w- c:\documents and settings\MaK\Application Data\Orbit
    2009-06-07 22:22 . 2008-11-14 14:53 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
    2009-06-07 11:36 . 2009-04-17 05:15 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
    2009-06-07 11:36 . 2009-04-15 22:02 -------- d-----w- c:\program files\RegGenie
    2009-06-01 18:13 . 2009-04-03 18:18 33840 ----a-w- c:\windows\system32\drivers\HssDrv.sys
    2009-05-20 21:17 . 2007-09-15 07:40 94643 ----a-w- c:\windows\system32\drivers\klick.dat
    2009-05-20 21:17 . 2007-09-15 07:40 105395 ----a-w- c:\windows\system32\drivers\klin.dat
    2009-05-20 18:58 . 2007-04-21 16:36 -------- d-----w- c:\program files\TVUPlayer
    2009-05-19 23:39 . 2009-04-21 18:02 -------- d-----w- c:\program files\VS Revo Group
    2009-05-17 20:41 . 2006-07-27 10:19 -------- d-----w- c:\program files\QuickSFV
    2009-05-07 22:15 . 2009-02-14 04:05 -------- d-----w- c:\program files\Java
    2009-05-07 22:14 . 2009-05-07 22:14 152576 ----a-w- c:\documents and settings\MaK\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-04-26 09:35 . 2009-04-26 09:35 -------- d-----w- c:\program files\Microsoft Visual Studio .NET
    2009-04-26 09:35 . 2009-04-23 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-04-26 09:33 . 2009-04-26 09:20 -------- d-----w- c:\program files\Oracle
    2009-04-23 16:22 . 2009-04-23 16:22 126 ----a-w- c:\documents and settings\MaK\Local Settings\Application Data\fusioncache.dat
    2009-04-21 21:31 . 2009-04-21 21:30 -------- d-----w- c:\program files\K-Lite Codec Pack
    2009-04-21 18:20 . 2009-04-08 13:48 -------- d-----w- c:\documents and settings\MaK\Application Data\SUPERAntiSpyware.com
    2009-04-21 18:09 . 2009-04-21 18:09 -------- d-----w- c:\documents and settings\MaK\Application Data\VSRevoGroup
    2009-04-21 17:52 . 2007-07-15 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-04-21 17:05 . 2009-04-21 17:05 -------- d-----w- c:\program files\Mythicsoft
    2009-04-17 16:21 . 2006-02-25 20:31 82040 -c--a-w- c:\documents and settings\MaK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-04-16 19:30 . 2007-09-16 16:39 -------- d-----w- c:\documents and settings\MaK\Application Data\Nokia Multimedia Player
    2009-04-15 23:27 . 2009-04-15 23:27 -------- d-----w- c:\program files\Reference Assemblies
    2009-04-15 22:36 . 2008-05-30 19:46 -------- d-----w- c:\program files\MSECACHE
    2009-04-15 10:43 . 2007-09-15 07:39 -------- d-----w- c:\program files\Kaspersky Lab
    2009-04-11 13:39 . 2009-04-11 13:39 -------- d-----w- c:\program files\Microsoft
    2009-04-06 17:46 . 2009-04-15 22:02 161816 ----a-w- c:\windows\RegGenieOnUninstall.exe
    2009-04-02 11:21 . 2009-04-21 21:30 84480 ----a-w- c:\windows\system32\ff_vfw.dll
    2007-07-25 01:41 . 2007-08-10 01:11 12592 ----a-w- c:\program files\mozilla firefox\plugins\libcomm.dll
    2007-07-25 01:41 . 2007-08-10 01:11 37256 ----a-w- c:\program files\mozilla firefox\plugins\NanoInst.dll
    2007-07-25 01:41 . 2007-08-10 01:11 43824 ----a-w- c:\program files\mozilla firefox\plugins\PSComm.dll
    2007-07-25 01:41 . 2007-08-10 01:11 113456 ----a-w- c:\program files\mozilla firefox\plugins\PSNAdBrk.dll
    .

    ------- Sigcheck -------

    [7] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
    [-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    [-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    [7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    [7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    [-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\SDTemp\Download\146ae5e7b51a37f45e0e5cf 03d0d5e3c\SP2GDR\tcpip.sys
    [-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\SDTemp\Download\146ae5e7b51a37f45e0e5cf 03d0d5e3c\SP2QFE\tcpip.sys
    [7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\TCPIP.SYS
    [7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\SoftwareDistribution\Download\dd9ab5193 501484cf5e6884fa1d22f9e\tcpip.sys
    [-] 2008-12-18 10:42 361600 A18B54F12E86B5F21266937E485E3DF5 c:\windows\system32\drivers\TCPIP.SYS
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
    2009-05-11 00:20 218160 ----a-w- c:\program files\Hotspot Shield\HssIE\HssIE.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-02-09 270128]
    "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2009-04-06 81920]
    "msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "RegGenie v2.0"="c:\program files\RegGenie\RegGenieOnReboot.exe" [2009-04-06 374808]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-04-06 204288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2009-04-06 479232]
    "PRONoMgrWired"="c:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2009-04-06 86016]
    "NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2007-11-06 81920]
    "LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
    "Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2008-10-14 172032]
    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 437008]
    "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-05 185872]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]
    "P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
    "ShowDeskFix"="shell32" [X]
    "tscuninstall"="c:\windows\system32\tscupgrd.e xe" [2004-08-03 44544]
    "SetDefaultMIDI"="MIDIDEF.EXE" - c:\windows\system32\MIDIDEF.EXE [2008-06-27 28672]
    "IE7-10"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
    "NoSecurityTab"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
    "NoSecurityTab"= 1 (0x1)
    "NoRecentDocsNetHood"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Creative Service for CDROM Access"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000001
    "UacDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride"=dword:00000001
    "AntiVirusDisableNotify"=dword:00000001
    "FirewallDisableNotify"=dword:00000001
    "FirewallOverride"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001
    "UacDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\MSI\\i-Speeder\\i-Speeder.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
    "c:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
    "c:\\Program Files\\Ares\\Ares.exe"=
    "c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
    "c:\\Program Files\\TVAnts\\Tvants.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\SopCast\\SopCast.exe"=
    "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
    "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
    "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
    "c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
    "54545:TCP"= 54545:TCP:Ar
    "54545:UDP"= 54545:UDP:Ar2
    "38010:TCP"= 38010:TCP:uT

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [07/04/2009 09:30 PM 64160]
    R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [07/10/2008 08:31 PM 61424]
    R2 HssSrv;Hotspot Shield Routing Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [01/06/2009 10:13 PM 331312]
    R2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_hom e1TNSListener;c:\oracle\product\10.2.0\db_1\BIN\TN SLSNR --> c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR [?]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [04/04/2007 10:58 AM 24344]
    R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [28/12/2007 09:33 PM 12032]
    S2 OracleServiceORCL;OracleServiceORCL;c:\oracle\prod uct\10.2.0\db_1\bin\ORACLE.EXE ORCL --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE ORCL [?]
    S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUS HWIO.SYS [25/02/2006 09:37 PM 5824]
    S3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\drivers\athrusb.sys [22/12/2008 03:20 PM 446976]
    S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [28/01/2008 04:16 PM 20608]
    S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\driv ers\COMMONFX.sys [27/06/2008 07:21 PM 99352]
    S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMM ONFX.sys [27/06/2008 07:21 PM 99352]
    S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\driver s\CTAUDFX.sys [27/06/2008 07:21 PM 555032]
    S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDF X.sys [27/06/2008 07:21 PM 555032]
    S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\driv ers\CTERFXFX.sys [27/06/2008 07:21 PM 100888]
    S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTER FXFX.sys [27/06/2008 07:21 PM 100888]
    S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\driver s\CTSBLFX.sys [27/06/2008 07:21 PM 566296]
    S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLF X.sys [27/06/2008 07:21 PM 566296]
    S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [21/03/2002 05:14 AM 21376]
    S3 DVT_CSDriver;DVT_CSDriver;\??\c:\docume~1\MaK\LOCA LS~1\Temp\Dep1.tmp\DVT_CSDriver.sys --> c:\docume~1\MaK\LOCALS~1\Temp\Dep1.tmp\DVT_CSDrive r.sys [?]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\pro gram files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
    S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [01/06/2009 10:58 PM 34352]
    S3 p17filt;p17filt;c:\windows\system32\drivers\p17fil t.sys [20/03/2006 06:34 PM 1452032]
    S3 TUSB1150;WL635USB WLAN USB Adapter;c:\windows\system32\drivers\TUSB1150.sys [25/03/2006 12:45 PM 494848]
    S3 ZD1211BU(SMC);802.11g Wireless USB2.0 Adapter Driver(SMC);c:\windows\system32\drivers\ZD1211BU.s ys [24/08/2006 01:44 AM 477696]
    S3 ZD1211BU(WIFI LINK);WIFI LINK IEEE 802.11 b+g Wireless LAN Driver (USB)(WIFI LINK);c:\windows\system32\drivers\ZD1211BU.sys [24/08/2006 01:44 AM 477696]
    S4 OracleJobSchedulerORCL;OracleJobSchedulerORCL;c:\o racle\product\10.2.0\db_1\Bin\extjob.exe ORCL --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe ORCL [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - project
    *Deregistered* - uphcleanhlp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 08:34]

    2009-06-09 c:\windows\Tasks\User_Feed_Synchronization-{FA8EE9B5-41C6-4D52-85BF-93EE9EF64EFB}.job
    - c:\windows\system32\msfeedssync.exe [2006-10-17 00:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = local
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: com.tw\asia.msi
    Trusted Zone: com.tw\global.msi
    Trusted Zone: com.tw\www.msi
    Trusted Zone: microsoft.com\download.windowsupdate
    Trusted Zone: microsoft.com\update
    Trusted Zone: microsoft.com\windowsupdate
    Trusted Zone: windowsupdate.com\download
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
    FF - ProfilePath - c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
    FF - prefs.js: keyword.enabled - false
    FF - component: c:\program files\Real\RealPlayer\browserrecord\components\npr pbrowserrecordplugin.dll
    FF - plugin: c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\firefox@tvunetworks.com\plugins\npTVUAx.dl l
    FF - plugin: c:\documents and settings\MaK\Application Data\Mozilla\Firefox\Profiles\hd5sp8kz.default\ext ensions\moveplayer@movenetworks.com\platform\WINNT _x86-msvc\plugins\npmnqmp07076007.dll
    FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npbabelgum.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npJoostPlugin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
    .

    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2009-06-10 02:40
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************

    [HKEY_LOCAL_MACHINE\System\ControlSet016\Services\O racleOraDb10g_home1TNSListener]
    "ImagePath"="c:\oracle\product\10.2.0\db_1\BIN\TNS LSNR "

    [HKEY_LOCAL_MACHINE\System\ControlSet016\Services\{ FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
    "ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\System\ControlSet016\Enum\HID\V id_1532&Pid_000c&MI_00\7&346f3358&0&0000\LogConf]
    @DACL=(02 0000)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1540)
    c:\windows\system32\klogon.dll
    .
    Completion time: 2009-06-09 2:50
    ComboFix-quarantined-files.txt 2009-06-09 22:50

    Pre-Run: 1,336,561,664 bytes free
    Post-Run: 841,428,992 bytes free

    Current=16 Default=16 Failed=15 LastKnownGood=17 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17
    293 --- E O F --- 2009-05-13 09:42

  8. #18
    ThuG_PoeT is offline Elite Member
    btw safe mode is working now

  9. #19
    broni is offline Senior Member
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.


    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    File::

    Folder::

    Driver::

    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
    "NoSecurityTab"=-
    [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
    "NoSecurityTab"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.




    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.

  10. #20
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    btw safe mode is working now
    Cool

+ Reply to Thread
Page 2 of 4 FirstFirst 1 2 3 4 LastLast