Dev Shed Forums
> System Administration
> Antivirus Protection
Help needed: cannot access drives, task manager and run command disabled !!
Discuss Help needed: cannot access drives, task manager and run command disabled !! in the Antivirus Protection forum on Dev Shed. Help needed: cannot access drives, task manager and run command disabled !! Antivirus Protection forum discussing issues relating to antivirus programs, spyware, hijack protection, and personal firewalls for all operating systems. Keep your systems protected from hackers and other hazards.
Receive the tools necessary to be the rock star of your field. Our 12-month program teaches you the evolving world of multi-channel marketing as well as the complex issues and opportunities found in the industry.
ASP Free and Iron Speed Designer are giving away $5,500+ in FREE licenses . Iron Speed's RAD CASE toolset can save up to 80% of your coding time. One free license per week, one perpetual license per month!
Download and Activate to enter!
Web development can be a daunting task, even for specialists. There is a lot of information to absorb and a lot of technologies to learn in order to manage a superior website. When trying to learn the ropes, developers need a reliable source to introduce new ideas that can be easily implemented. When working on large projects, even web veterans may run into a technology or an aspect of a technology that they are unfamiliar with.
Learn More!
Download to Enter | Contest Rules
Tutorials | Forums
Dev Shed Forums Sponsor:
April 12th, 2008, 12:47 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
Help needed: cannot access drives, task manager and run command disabled !!
Dear Friends,
recently i was hit by trojan/viruses/malware and I tried to clean my system with AVG anti-spyware. After cleaning my system, I still have problems accessing my hard-drive ( msg: cannot find copy.exe etc), my task manager option is disabled, Run command is inaccesible from start menu etc etc. Though I am able to access drives by explore option but same fails when i try to access it through My computer. Also after cleaning, Twice I have got windows message that my system is low on virtual memory and its size is being adjusted.
I read your rules for posting queries but i could not complete step 1 and step 4 i.e cleanup software is getting downloaded in faulty state and online cleaning status is not visible when i hit 'clean now' button....
I will appreciate if you can help me come out of this situation. Thanx
April 12th, 2008, 12:50 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 3:28:27 AM 4/12/2008
+ Scan result:
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018550.exe -> Backdoor.Small.lo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018567.exe -> Backdoor.Small.lo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\temp2.exe -> Backdoor.Small.lo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP135\A0014086.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP135\A0014216.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018648.exe -> Dropper.Small.apl : Cleaned with backup (quarantined).
C:\host.exe -> Dropper.Small.apl : Cleaned with backup (quarantined).
D:\host.exe -> Dropper.Small.apl : Cleaned with backup (quarantined).
E:\host.exe -> Dropper.Small.apl : Cleaned with backup (quarantined).
F:\host.exe -> Dropper.Small.apl : Cleaned with backup (quarantined).
:mozilla.477:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.478:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.479:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.480:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.481:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.482:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.483:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.484:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.485:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.486:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.487:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.488:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.489:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.490:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.491:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.492:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.493:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.494:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.495:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.496:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.497:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.498:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.595:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.125:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.126:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.127:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.128:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.156:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.274:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.275:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.276:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.277:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.741:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.354:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.355:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.356:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.357:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.358:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.392:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.871:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.298:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.301:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.302:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.303:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.304:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.305:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.306:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.307:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.308:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.309:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.310:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.311:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.157:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.757:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.758:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@whitepapers.techrepublic.com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.960:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.170:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.317:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.318:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.319:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.320:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.321:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.322:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.684:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.685:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.234:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.235:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.687:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.688:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.811:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.812:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.920:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.965:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.966:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@ehg-ittoolbox.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.459:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.460:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.828:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@search.live[1].txt -> TrackingCookie.Live : Cleaned.
:mozilla.892:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.893:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.543:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@auto.search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
:mozilla.400:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.404:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.405:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.406:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.186:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.596:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.597:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.598:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.599:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.600:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.601:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.602:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.603:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.461:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.462:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@real[1].txt -> TrackingCookie.Real : Cleaned.
:mozilla.869:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.555:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.556:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.557:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.558:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.559:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.560:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.561:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.419:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.420:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.421:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.422:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.423:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.428:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.466:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
April 12th, 2008, 12:51 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
continued--log report AVG anti spyware
:mozilla.467:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.468:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.469:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.471:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.472:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.473:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.696:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.697:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.101:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.102:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.103:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.104:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.105:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.106:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.107:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.108:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.109:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.110:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.111:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.112:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.113:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.116:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.117:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.118:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.119:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.120:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.121:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.75:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.76:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.77:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.78:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.80:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.81:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.85:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.86:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.87:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.88:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.89:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.90:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.91:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.92:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.93:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.94:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.95:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.96:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.97:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.98:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.99:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.313:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.314:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.315:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.316:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.415:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.27:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.323:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.328:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.329:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.330:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.435:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.42:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.43:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.44:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.45:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.46:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.134:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.135:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.136:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.137:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.138:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.139:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.140:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.141:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.142:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3y7trjx1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018566.exe -> Trojan.Copier : Cleaned with backup (quarantined).
C:\WINDOWS\xcopy.exe -> Trojan.Copyself : Cleaned with backup (quarantined).
C:\copy.exe -> Trojan.Copyself : Cleaned with backup (quarantined).
D:\copy.exe -> Trojan.Copyself : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018647.exe -> Trojan.Copyself : Cleaned with backup (quarantined).
F:\copy.exe -> Trojan.Copyself : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E3536418-8A9A-4438-BDED-9B242547A6ED}\RP157\A0018646.exe -> Worm.VB.ck : Cleaned with backup (quarantined).
C:\WINDOWS\system\lsass.exe -> Worm.VB.ck : Cleaned with backup (quarantined).
::Report end
April 12th, 2008, 12:52 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
step-2 - MALWARE BYTES log report ( note- all problems were fixed)
Malwarebytes' Anti-Malware 1.11
Database version: 616
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 170119
Time elapsed: 48 minute(s), 5 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
C:\WINDOWS\system32\svehost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\svehost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.01 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.03 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.05 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.07 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.09 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.11 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.13 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.15 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.17 (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\WINDOWS\system32\drivers\etc\services.19 (Heuristics.Reserved.Word.Exploit) -> No action taken.
April 12th, 2008, 12:53 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
log report- super antispyware
SUPERAntiSpyware Scan Log
Generated 04/12/2008 at 08:50 PM
Application Version : 4.0.1154
Core Rules Database Version : 3437
Trace Rules Database Version: 1429
Scan type : Complete Scan
Total Scan Time : 00:26:17
Memory items scanned : 413
Memory threats detected : 0
Registry items scanned : 5272
Registry threats detected : 6
File items scanned : 18475
File threats detected : 32
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}
HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}
HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}
HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32
HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32#ThreadingModel
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\~DP1F4.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{598F4775-6FB6-477B-9842-E0426824E077}
Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1064535546[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1070698946[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@emp3finder[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@statse.webtrendslive[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ehg-ittoolbox.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fcstats.bcentral[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@richmedia.yahoo[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@kontera[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.ozonemedia.co[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@media.adrevolver[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adinterax[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.emp3finder[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@accounts[2].txt
Trojan.Downloader
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\MSCONFIG.EXE
April 12th, 2008, 12:55 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
step 4- online scanning was not responsive so here is HIJACK THIS log report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:09:33 PM, on 4/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 128.1.2.1:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [Microsoft Updates] svehost.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [Microsoft Updates] svehost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8BB99EF-1AA7-41CF-B8B7-C5E748E10766}: NameServer = 59.144.127.16,59.144.127.17
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7078 bytes
April 12th, 2008, 12:56 PM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
uninstall list- Hijack this
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Reader 6.0.1
Applian FLV Player
AVG 7.5
AVG Anti-Spyware 7.5
BCM V.92 56K Modem
BootSkin
Broadcom 440x 10/100 Integrated Controller
DB2 Enterprise Server Edition
Dell Resource CD
Glarysoft Registry Repair 2.7
Google Earth
Google Talk (remove only)
HijackThis 2.0.2
HP Customer Participation Program 7.0
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart Premier Software 6.5
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
IsoBuster 1.2
J2SE Runtime Environment 5.0 Update 11
Jetfighter V Homeland Protector
K-Lite Mega Codec Pack 2.01
Kundli for Windows (Lite Edition)
Malwarebytes' Anti-Malware
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft Office Professional Edition 2003
Mojo Master Winamp Visualizer for Winamp (remove only)
Mozilla Firefox (1.5.0.12)
MSVC80_x86
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
NVIDIA Drivers
OCR Software by I.R.I.S 7.0
PC Connectivity Solution
Picasa 2
PowerDVD 5.1
PowerQuest PartitionMagic 7.0
QuickSet
SigmaTel AC97 Audio Drivers
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
VideoLAN VLC media player 0.8.2
Winamp (remove only)
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)
Windows Driver Package - Nokia Modem (10/12/2007 3.6)
Windows Media Format Runtime
Windows Media Player 10
WinRAR archiver
WinZip
Wondershare Photo Collage Studio (4.2.0) Trial Version
Yahoo! Messenger
ZoneAlarm Pro
April 12th, 2008, 02:43 PM
Malware Warrior /AV forum Mod
Join Date: Nov 2006
Location: San Antonio Tx
Welcome, Thanks for working the steps in the Sticky.
Lets move on to the more advanced tools.
Download Combofix from the link below. You must rename it before saving it. Save it to your desktop. I suggest that you rename it to Combo-Fix.exe. The tool will suggest that name as default any way.
>> Download
ComboFix <<
--------------------------------------------------------------------
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
* Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
* Remember to re enable the protection again afterwards.
2. Double click on Combo-Fix.exe & follow the prompts.
* When finished, it will produce a report for you. Please post the C:\ComboFix.txt so we can continue cleaning the system.
Notes:
* Do not mouseclick combofix's window while it's running. That may cause it to stall
* CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Please stay by the machine as it runs, and if any errors occur please try and see what they are so we can pinpoint the problem.
__________________
Neera: The wraith will not allow us to escape.
Sheppard: Yeah, well I try not to let them tell me what I can and can't do.
Neera: You do not fear them?
Sheppard: The wraith, nah.
Now clowns that's another story . They scare the crap out of me.
April 13th, 2008, 01:40 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
hi porthos..thanx for your speedy response
.....I disabled running anti-virus and anti-spywares softwares before running it but could not kill the process using task manager as this feature is blocked by malware...here is the test log..
ComboFix 08-04-12.5 - Administrator 2008-04-13 11:54:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.277 [GMT 5.5:30]
Running from: C:\Documents and Settings\Administrator\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\Administrator\ravmonlog
C:\WINDOWS\autorun.inf
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\NPF
((((((((((((((((((((((((( Files Created from 2008-03-13 to 2008-04-13 )))))))))))))))))))))))))))))))
.
2008-04-12 22:09 . 2008-04-12 22:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-12 21:09 . 2008-04-12 21:09 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-12 20:18 . 2008-04-12 21:02 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-12 20:18 . 2008-04-12 20:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-12 20:18 . 2008-04-12 20:18 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-12 20:17 . 2008-04-12 20:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-12 19:17 . 2008-04-12 19:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 19:17 . 2008-04-12 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-12 19:17 . 2008-04-12 19:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-04-12 04:10 . 2008-04-12 04:10 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AVG7
2008-04-12 03:52 . 2008-04-12 03:52 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-12 03:52 . 2008-04-13 11:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-12 03:51 . 2008-04-12 04:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-12 03:33 . 2008-04-12 03:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-12 02:33 . 2008-04-12 02:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-04-12 02:33 . 2007-05-30 17:40 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-08 20:51 . 2008-04-08 20:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Image Zone Express
2008-03-31 18:08 . 2008-03-31 18:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-03-31 17:42 . 2008-03-31 17:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-03-31 17:41 . 2008-03-31 17:41 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-03-31 17:41 . 2008-03-31 17:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-29 11:59 . 2008-03-29 15:19 <DIR> d-------- C:\Documents and Settings\Administrator\dwhelper
2008-03-19 18:10 . 2008-03-19 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GlarySoft
2008-03-19 18:09 . 2008-03-19 18:09 <DIR> d-------- C:\Program Files\Registry Repair
2008-03-17 17:41 . 2008-03-17 17:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2008-03-17 17:41 . 2008-03-17 17:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\iolo
2008-03-17 17:41 . 2008-03-17 17:41 74,703 --a------ C:\WINDOWS\system32\mfc45.dll
2008-03-17 17:12 . 2008-03-17 17:12 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-03-17 17:12 . 2008-03-17 17:12 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-17 17:12 . 2008-03-17 17:13 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-17 17:11 . 2008-04-13 11:58 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-17 17:11 . 2008-04-12 23:09 526 --ah----- C:\WINDOWS\system32\vsconfig.xml
2008-03-17 17:02 . 2008-03-17 17:02 <DIR> d--hs---- C:\INCINERATE
2008-03-17 16:59 . 2008-04-06 17:44 512 --a------ C:\WINDOWS\randseed.rnd
2008-03-17 16:58 . 2008-03-17 16:58 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-03-17 15:16 . 2008-03-17 15:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-17 15:13 . 2008-03-17 15:13 <DIR> d-------- C:\Program Files\DIFX
2008-03-17 15:12 . 2008-03-17 15:12 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-03-17 15:12 . 2008-03-17 15:12 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-03-17 15:11 . 2008-03-17 15:13 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-17 15:11 . 2008-03-17 15:11 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-03-17 15:11 . 2008-03-17 15:12 <DIR> d-------- C:\Program Files\Nokia
2008-03-17 15:11 . 2007-02-22 10:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-03-17 15:10 . 2008-03-17 15:10 19 --a------ C:\WINDOWS\SoundConverter.INI
2008-03-17 15:05 . 2008-03-17 15:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2008-03-13 14:58 . 2008-03-13 15:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\HP
2008-03-13 14:57 . 2008-03-13 14:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-03-13 14:53 . 2008-03-13 14:53 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-13 14:53 . 2008-03-13 14:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-03-13 14:51 . 2008-03-13 14:53 <DIR> d-------- C:\Program Files\Common Files\HP
2008-03-13 14:49 . 2008-03-13 14:49 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-03-13 14:48 . 2008-03-13 14:48 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-13 14:48 . 2006-04-13 05:34 49,664 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-03-13 14:48 . 2006-04-13 05:34 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-03-13 14:47 . 2006-01-04 14:42 77,824 -ra------ C:\WINDOWS\system32\HPZIDS01.dll
2008-03-13 14:47 . 2006-04-10 14:03 48,128 --a------ C:\WINDOWS\system32\hpzll054.dll
2008-03-13 14:47 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-13 14:47 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-13 14:46 . 2006-03-03 21:03 282,680 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-03-13 14:46 . 2006-03-03 21:02 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-03-13 14:46 . 2006-03-03 21:02 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-03-13 14:46 . 2006-03-03 21:03 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-03-13 14:46 . 2006-03-03 21:03 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-03-13 14:46 . 2006-03-03 21:02 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-03-13 14:45 . 2008-03-13 14:56 <DIR> d-------- C:\Program Files\HP
2008-03-13 14:43 . 2008-03-13 15:05 117,421 --a------ C:\WINDOWS\hpoins11.dat
2008-03-13 14:43 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-03-13 14:43 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
April 13th, 2008, 01:41 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
continued...
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 14:54 1,107,968 ----a-w C:\WINDOWS\Internet Logs\xDB56.tmp
2008-04-12 04:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-12 04:01 984,576 ----a-w C:\WINDOWS\Internet Logs\xDB55.tmp
2008-04-11 22:38 73,728 ----a-w C:\WINDOWS\Internet Logs\xDB54.tmp
2008-04-11 22:38 1,017,856 ----a-w C:\WINDOWS\Internet Logs\xDB53.tmp
2008-04-11 22:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-11 22:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-04-11 20:09 107,132 ----a-w C:\WINDOWS\UninstallFirefox.exe
2008-04-11 19:08 48,640 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2008-04-11 18:35 981,504 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2008-04-10 21:35 39,424 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2008-04-10 21:35 1,030,656 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2008-04-10 04:39 23,552 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2008-04-10 04:38 1,013,248 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2008-04-09 20:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IBM
2008-04-09 16:26 17,408 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2008-04-09 15:56 918,016 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2008-04-09 15:29 918,016 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2008-04-09 15:29 16,896 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2008-04-09 15:10 918,016 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2008-04-09 15:10 17,920 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2008-04-09 14:33 23,040 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2008-04-09 14:31 942,592 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2008-04-09 13:00 18,432 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2008-04-09 12:59 919,040 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2008-04-09 10:34 920,064 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2008-04-09 10:34 16,896 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2008-04-09 10:31 931,328 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2008-04-09 10:31 19,968 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2008-04-09 10:17 17,408 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2008-04-09 10:08 920,064 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2008-04-09 09:17 25,600 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2008-04-09 09:12 928,256 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2008-04-08 17:45 923,648 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2008-04-08 17:26 17,920 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2008-04-08 17:08 920,064 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2008-04-08 17:08 16,896 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2008-04-08 16:54 939,520 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2008-04-08 16:08 19,456 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2008-04-08 14:49 29,184 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2008-04-08 14:29 931,328 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2008-04-08 08:11 24,064 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2008-04-08 07:31 920,576 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2008-04-07 12:10 28,672 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2008-04-07 11:49 908,288 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2008-04-07 11:19 976,896 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2008-04-07 11:19 25,088 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2008-04-07 00:04 20,480 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2008-04-07 00:02 906,240 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2008-04-06 23:59 22,016 ----a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2008-04-06 23:57 894,976 ----a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2008-04-06 08:46 892,928 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2008-04-06 08:46 17,920 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2008-04-06 08:43 2,893,824 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2008-04-06 08:43 1,020,928 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2008-04-05 05:19 891,392 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2008-04-05 05:19 17,408 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2008-04-04 17:43 902,144 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2008-04-04 17:43 2,841,088 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2008-04-04 05:08 896,000 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-04-04 05:07 16,896 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-04-04 05:05 2,849,280 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-04-04 05:04 908,288 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-04-03 10:25 893,952 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-04-03 10:25 2,344,448 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-04-02 05:28 2,879,488 ----a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2008-04-02 05:27 916,480 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-03-31 20:10 817,152 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-03-31 20:10 2,785,280 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-03-31 17:26 781,312 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-03-31 17:26 2,807,808 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-03-31 12:10 --------- d-----w C:\Program Files\Common Files\Real
2008-03-30 06:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-03-29 20:49 666,624 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-03-29 20:49 13,824 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-03-29 20:48 744,448 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-03-29 20:47 18,944 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2008-03-29 20:46 869,376 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-03-29 20:45 38,400 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-03-29 06:26 33,280 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-03-29 05:57 778,240 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-03-29 04:41 40,448 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-03-29 04:40 880,640 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-03-28 04:52 40,448 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-03-28 04:51 910,336 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-03-27 09:06 27,136 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-03-27 09:05 771,072 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-03-27 08:45 47,616 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-03-27 08:36 1,086,464 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-03-23 13:43 2,941,952 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-03-23 13:43 1,222,144 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-03-17 11:55 --------- d-----w C:\Program Files\iolo
2008-03-17 11:51 685,568 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-17 11:50 22,528 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-03-17 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-03-17 10:34 --------- d-----w C:\Program Files\Webshots
2008-03-17 09:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-03-17 09:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-03-17 09:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-03 08:09 --------- d-----w C:\Program Files\Wondershare
April 13th, 2008, 01:42 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
continued..
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22 4670968]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 14:15 90169]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-02-05 16:07 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-02-05 16:07 495616]
"BootSkin Startup Jobs"="C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 16:21 270336]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-06-18 13:31 3698688]
"nwiz"="nwiz.exe" [2004-06-18 13:31 790528 C:\WINDOWS\system32\nwiz.exe]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2004-03-04 20:59 487424]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"Zone Labs Client"="C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe" [2003-11-15 17:20 689248]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-04-12 03:33 6731312]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-12 03:51 406016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft Updates"="svehost.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-12 03:51 146432]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Webshots.lnk]
backup=C:\WINDOWS\pss\Webshots.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RealDownload.lnk]
backup=C:\WINDOWS\pss\RealDownload.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CleanUp]
C:\PROGRA~1\McAfee.com\Shared\mcappins.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\db2systray.exe]
--a------ 2004-08-15 20:34 61521 C:\Program Files\IBM\SQLLIB\BIN\db2systray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-08-13 01:05 122939 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-04-11 11:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 02:41 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Updates]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2007-12-10 10:12 695808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2007-11-07 17:35 1294336 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-10-24 02:48 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2004-01-07 01:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Venturi Configurator]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-27 15:22 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"Diskeeper"=2 (0x2)
"xsSmartAgent"=3 (0x3)
"ose"=3 (0x3)
"ServiceLayer"=3 (0x3)
"OracleOraHome90SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome90SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome90PagingServer"=3 (0x3)
"OracleOraHome90HTTPServer"=2 (0x2)
"OracleOraHome90ClientCache"=3 (0x3)
"OracleOraHome90Agent"=2 (0x2)
"Oracle OLAP Agent"=3 (0x3)
"OLAPServer"=3 (0x3)
"MDM"=2 (0x2)
"McTskshd.exe"=2 (0x2)
"McDetect.exe"=2 (0x2)
"DB2REMOTECMD"=2 (0x2)
"DB2NTSECSERVER"=2 (0x2)
"DB2LICD"=2 (0x2)
"DB2JDS"=2 (0x2)
"DB2GOVERNOR"=3 (0x3)
"DB2DWServer"=3 (0x3)
"DB2DWLogger"=3 (0x3)
"DB2DAS00"=2 (0x2)
"DB2CTLSV-0"=2 (0x2)
"DB2-0"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12745:TCP"= 12745:TCP:NortonAV
"16349:TCP"= 16349:TCP:NortonAV
"17996:TCP"= 17996:TCP:NortonAV
"13650:TCP"= 13650:TCP:NortonAV
S3 SGUARD;SGUARD;C:\WINDOWS\system32\drivers\SGuard.sys []
S3 zteusbser;ZTE USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\zteusbser.sys [2007-08-08 14:50]
S4 DB2-0;DB2 - DB2-0;C:\PROGRA~1\IBM\SQLLIB\bin\db2syscs.exe [2004-08-15 20:33]
S4 DB2CTLSV-0;DB2 - DB2CTLSV-0;C:\PROGRA~1\IBM\SQLLIB\bin\db2syscs.exe [2004-08-15 20:33]
S4 DB2DWLogger;DB2 Warehouse Logger;"C:\Program Files\IBM\SQLLIB\BIN\iwh2log.exe" [2004-08-15 20:33]
S4 DB2DWServer;DB2 Warehouse Server;"C:\Program Files\IBM\SQLLIB\BIN\iwh2serv.exe" [2004-08-15 20:33]
S4 OracleOraHome90ClientCache;OracleOraHome90ClientCache;C:\oracle\ora90\BIN\ONRSD.EXE [2001-08-14 18:25]
S4 OracleOraHome90HTTPServer;OracleOraHome90HTTPServer;C:\oracle\ora90\Apache\Apache\Apache.exe [2001-08-17 14:49]
S4 OracleOraHome90PagingServer;OracleOraHome90PagingServer;C:\oracle\ora90/bin/pagntsrv.exe [2001-08-28 17:07]
S4 OracleOraHome90SNMPPeerEncapsulator;OracleOraHome90SNMPPeerEncapsulator;C:\oracle\ora90\BIN\ENCSVC.E XE [2001-08-16 20:18]
S4 OracleOraHome90SNMPPeerMasterAgent;OracleOraHome90SNMPPeerMasterAgent;C:\oracle\ora90\BIN\AGNTSVC.EX E [2001-08-16 20:18]
S4 xsSmartAgent;Visibroker Smart Agent;C:\oracle\ora90\bin\osagent.exe [2001-03-30 16:42]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed515e7c-ecd1-11dc-b616-000f1f219ffc}]
\Shell\AutoRun\command - H:\startup.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 11:58:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome90PagingServer]
"ImagePath"="C:\oracle\ora90/bin/pagntsrv.exe"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-13 12:01:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-13 06:31:08
Pre-Run: 6,432,493,568 bytes free
Post-Run: 6,538,858,496 bytes free
April 13th, 2008, 01:56 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
well my system is behaving fine now...i can access my drives, task manager option is enabled and run command is showing up in start menu...do u think we need to continue hunting for viruses etc [
]
April 13th, 2008, 02:07 AM
Malware Warrior /AV forum Mod
Join Date: Nov 2006
Location: San Antonio Tx
There is more
Download SDfix from
HERE and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
· Restart your computer
· After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
· Instead of Windows loading as normal, the Advanced Options Menu should appear;
· Select the first option, to run Windows in Safe Mode, then press Enter.
· Choose your usual account.
· Open the extracted SDFix folder and double click RunThis.bat to start the script.
· Type Y to begin the cleanup process.
· It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
· Press any Key and it will restart the PC.
· When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
· Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
April 13th, 2008, 06:08 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
Quote:
Originally Posted by Porthos
There is more
Wel..here is the report of SDfix..
SDFix: Version 1.170
Run by Administrator on Sun 04/13/2008 at 02:41 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 14:49:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\0011b107a365]
"001b33c96a76"=hex:33,8b,eb,c1,66,56,e1,a9,07,0b,d6,1f,7d,bb,74,12
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011b107a365]
"001b33c96a76"=hex:33,8b,eb,c1,66,56,e1,a9,07,0b,d6,1f,7d,bb,74,12
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0011b107a365]
"001b33c96a76"=hex:33,8b,eb,c1,66,56,e1,a9,07,0b,d6,1f,7d,bb,74,12
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000000
"TracesSuccessful"=dword:00000000
"LastTraceFailure"=dword:00000000
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:ęTorrent"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 20 Feb 2008 6,219,320 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sun 3 Feb 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 3 Feb 2008 4,348 ...H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1key.bak"
Sun 3 Feb 2008 20 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1lic.bak"
Sun 3 Feb 2008 400 A.SH. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Finished!
April 13th, 2008, 06:11 AM
Contributing User
Join Date: Apr 2008
Posts: 49
Time spent in forums: 2 h 45 m 6 sec
Reputation Power: 5
after running SDfix...my i ran my AVG anti-virus test on my system...this is the report...seems like infection keeps on coming up
..though iem not facing the problems i was facing before..but still these malicious programs gives me goose bumps
report:
Scan "Scan whole computer" was finished.
Infections found:;"2"
Infected objects removed or healed;"2"
Not removed or healed.;"0"
Spyware found:;"2"
Spyware removed:;"2"
Not removed:;"0"
Warnings count:;"2"
Information count:;"0"
Scan started:;"Sunday, April 13, 2008, 3:06:15 PM"
Total object scanned:;"714594"
Time needed:;"1 hour(s) 26 minute(s) 28 second(s) "
Errors encountered:;"0"
Infections
File;"Infection";"Result"
E:\RECYCLER\S-1-5-21-1229272821-1979792683-1417001333-1003\Dg1\ruby184-19.exe:\$JN\lib\ruby\1.8\i386-mswin32\digest.so;"Trojan horse Generic10.JXS";"Deleted"
E:\RECYCLER\S-1-5-21-1229272821-1979792683-1417001333-1003\Dg1\ruby184-19.exe;"Trojan horse Generic10.JXS";"Deleted"
Spyware
File;"Infection";"Result"
E:\RECYCLER\S-1-5-21-1708537768-1123561945-842925246-500\De2.rar:\keygen.exe;"Potentially harmful program Crack.D";"Deleted"
E:\RECYCLER\S-1-5-21-1708537768-1123561945-842925246-500\De2.rar;"Potentially harmful program Crack.D";"Deleted"
Warnings
File;"Infection";"Result"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EDC6C20-A31C-11DB-8AB9-0800200C9A66};"Found Adware.RogueSuspect";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3AAC4C68-AFC8-11DB-80EF-8AF955D89593};"Found Adware.RogueSuspect";"Potentially dangerous object"
Thread Tools
Search this Thread
Display Modes
Rate This Thread
Linear Mode
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off