Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
 
Old 05-23-2008, 12:54 AM   #1 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Virtumondo help! HJT log please!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:05:47 PM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BMd34e7fa3] Rundll32.exe "C:\WINDOWS\system32\xnwwxxlp.dll",s
O4 - HKLM\..\Run: [d07d4c3f] rundll32.exe "C:\WINDOWS\system32\kpnqlkpq.dll",b
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

--
End of file - 6043 bytes
NurthinAziz is offline  
Old 05-23-2008, 11:41 AM   #2 (permalink)
 
Super Techie

Join Date: Aug 2007

Posts: 451

techpro5238 is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Things don't look to bad on the top but let's work into the system a bit deeper and run a few tools before we say anything

Step1

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

Step2

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

Logs Required In Next Post:
-------------------------------

Deckards Log (Extra.txt Attached)
VundoFix Log

Kind Regards,
Techpro5238
techpro5238 is offline  
Old 05-23-2008, 06:51 PM   #3 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Go so I'ma just do it this way, since I made changed not too long ago and deleted some stuff I made a new HJT log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:31, on 2008-05-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [d07d4c3f] rundll32.exe "C:\WINDOWS\system32\nwhrsdri.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BMd34e7fa3] Rundll32.exe "C:\WINDOWS\system32\xbiojjmc.dll",s
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

--
End of file - 5759 bytes





And here is my VundoFix.exe log







VundoFix V7.0.5

Scan started at 15:20:52 2008-05-23

Listing files found while scanning....

No infected files were found.


VundoFix V7.0.5

Scan started at 15:31:59 2008-05-23

Listing files found while scanning....

No infected files were found.
NurthinAziz is offline  
Old 05-23-2008, 06:56 PM   #4 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Deckard's System Scanner v20071014.68
Run by Aziz Home on 2008-05-23 15:28:18
Computer is in Safe Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------



-- Last 2 Restore Point(s) --
2: 2008-05-23 22:26:11 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-05-23 22:15:35 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Aziz Home.exe) -------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:30, on 2008-05-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Aziz Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Aziz Home.exe
C:\WINDOWS\system32\rundll32.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [d07d4c3f] rundll32.exe "C:\WINDOWS\system32\nwhrsdri.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BMd34e7fa3] Rundll32.exe "C:\WINDOWS\system32\xbiojjmc.dll",s
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

--
End of file - 5835 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080522-221743-164 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080522-221743-232 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
backup-20080522-221743-350 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
backup-20080522-221743-418 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
backup-20080522-221743-439 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
backup-20080522-221743-478 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
backup-20080522-221743-485 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080522-221743-493 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20080522-221743-527 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
backup-20080522-221743-617 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
backup-20080522-221743-713 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
backup-20080522-221743-787 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
backup-20080522-221743-816 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080522-221743-923 O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
backup-20080522-221743-969 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 Afc (PPdus ASPI Shell) - c:\windows\system32\drivers\afc.sys <Not Verified; Arcsoft, Inc.; Arcsoft(R) ASPI Shell>

S0 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys (file missing)
S0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys (file missing)
S1 ISODrive (ISO DVD/CD-ROM Device Driver) - c:\program files\ultraiso\drivers\isodrive.sys <Not Verified; EZB Systems, Inc.; ISODrive>
S1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
S2 Haspnt - c:\windows\system32\drivers\haspnt.sys <Not Verified; Aladdin Knowledge Systems; Windows NT HASP Kernel Device Driver>
S2 npkcrypt - c:\nexon\maplestory\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
S3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys (file missing)
S3 BlueletSCOAudio (Bluetooth SCO Audio Service) - c:\windows\system32\drivers\blueletscoaudio.sys (file missing)
S3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys (file missing)
S3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys (file missing)
S3 catchme - c:\combofix\catchme.sys (file missing)
S3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys (file missing)
S3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys (file missing)
S3 XDva032 - c:\windows\system32\xdva032.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not Verified; Prolific Technology Inc.; IoctlSvc Application>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S3 WLSetupSvc (Windows Live Setup Service) - "c:\program files\windows live\installer\wlsetupsvc.exe" <Not Verified; Microsoft Corporation; Windows Live installer>
S4 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
S4 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S4 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: System Interrupt Controller
Device ID: PCI\VEN_1106&DEV_5336&SUBSYS_00000000&REV_00\3&241 1E6FE&0&05
Manufacturer:
Name: System Interrupt Controller
PNP Device ID: PCI\VEN_1106&DEV_5336&SUBSYS_00000000&REV_00\3&241 1E6FE&0&05
Service:

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Zune Bus Root Bus Enumerator
Device ID: ROOT\SYSTEM\0003
Manufacturer: Microsoft
Name: Zune Bus Root Bus Enumerator
PNP Device ID: ROOT\SYSTEM\0003
Service: zumbus


-- Scheduled Tasks -------------------------------------------------------------

2008-05-22 07:00:03 406 --a------ C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job
2008-05-21 22:02:51 418 --a------ C:\WINDOWS\Tasks\AwcProUpdate.job
NurthinAziz is offline  
Old 05-23-2008, 06:56 PM   #5 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

-- Files created between 2008-04-23 and 2008-05-23 -----------------------------

2008-05-23 12:57:04 0 d-------- C:\WINDOWS\Prefetch
2008-05-23 00:36:17 0 d-------- C:\WINDOWS\system32\en
2008-05-22 22:20:23 0 d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-22 22:05:29 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-05-22 22:02:10 68096 --a------ C:\WINDOWS\zip.exe
2008-05-22 22:02:10 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-22 22:02:10 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-22 22:02:10 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-22 22:02:10 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-22 22:02:10 98816 --a------ C:\WINDOWS\sed.exe
2008-05-22 22:02:10 80412 --a------ C:\WINDOWS\grep.exe
2008-05-22 22:02:10 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-22 21:47:28 134144 --a------ C:\WINDOWS\system32\kndovpeg.dll
2008-05-22 21:42:04 115200 --a------ C:\WINDOWS\system32\nwhrsdri.dll
2008-05-22 21:36:35 0 d-------- C:\VundoFix Backups
2008-05-22 21:34:52 126464 --a------ C:\WINDOWS\system32\xbiojjmc.dll
2008-05-22 21:07:25 0 dr-h----- C:\Documents and Settings\Aziz Home\Recent
2008-05-22 21:01:13 0 d-------- C:\Program Files\Trend Micro
2008-05-22 20:58:16 0 d--hs---- C:\WINDOWS\CSC
2008-05-22 20:54:19 126464 --a------ C:\WINDOWS\system32\xnwwxxlp.dll
2008-05-21 21:47:19 0 d-------- C:\Program Files\IObit
2008-05-21 21:36:52 0 d-------- C:\Documents and Settings\Aziz Home\Dr Delete
2008-05-21 20:50:09 6291456 --a------ C:\Documents and Settings\Aziz Home\ntuser.dat
2008-05-21 20:44:30 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\DNA
2008-05-21 20:43:59 95232 --a------ C:\WINDOWS\system32Windows-Update.exe
2008-05-21 17:54:21 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\teamspeak2
2008-05-20 20:04:10 0 d-------- C:\Fraps
2008-05-17 17:23:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-05-17 17:15:37 6656 --a------ C:\WINDOWS\system32\haspvdd.dll <Not Verified; Aladdin Knowledge Systems.; Windows NT HASP Virtual Device Driver>
2008-05-17 17:15:37 383 --a------ C:\WINDOWS\system32\haspdos.sys
2008-05-17 17:15:37 47616 --a------ C:\WINDOWS\system32\drivers\Haspnt.sys <Not Verified; Aladdin Knowledge Systems; Windows NT HASP Kernel Device Driver>
2008-05-09 22:01:41 0 d-------- C:\Program Files\Curse
2008-05-08 21:00:38 0 d-------- C:\Nexon
2008-05-06 21:45:13 0 d-------- C:\Program Files\Yahoo!
2008-05-06 19:59:29 0 d-------- C:\Program Files\Ventrilo
2008-05-06 19:59:20 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-05 22:53:52 0 d-------- C:\Logs
2008-05-05 07:13:40 0 d-------- C:\Program Files\World of Warcraft
2008-05-02 15:53:28 0 d-------- C:\Program Files\Haali
2008-05-02 15:46:51 0 d-------- C:\Program Files\GPL MPEG Decoder
2008-04-23 17:25:14 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\InternetCalls
2008-04-23 17:13:07 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\VoipBuster
2008-04-23 16:56:46 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Media Player Classic
2008-04-23 16:55:37 0 d-------- C:\Program Files\Real Alternative
2008-04-23 16:55:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Real
2008-04-23 16:17:15 0 d-------- C:\Program Files\Apex


-- Find3M Report ---------------------------------------------------------------

2008-05-23 12:48:20 22720 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 12:47:56 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-23 12:34:56 0 d-------- C:\Program Files\Windows NT
2008-05-22 21:39:59 0 d-------- C:\Program Files\PowerISO
2008-05-22 20:51:42 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Azureus
2008-05-21 20:52:54 0 d-------- C:\Program Files\SpywareGuard
2008-05-21 19:11:35 0 d-------- C:\Program Files\Starcraft
2008-05-11 18:41:18 0 d-------- C:\Program Files\Free Music Zilla
2008-05-06 21:59:07 0 d-------- C:\Program Files\SpywareBlaster
2008-05-06 19:59:20 0 d-------- C:\Program Files\Common Files
2008-05-05 07:27:47 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-04-23 17:56:09 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Real
2008-04-22 20:14:40 0 d-------- C:\Program Files\HiFisoftware
2008-04-22 07:10:31 0 d-------- C:\Program Files\Xilisoft
2008-04-20 21:07:45 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Jubler
2008-04-20 20:54:12 0 d-------- C:\Program Files\Gaupol
2008-04-19 17:09:14 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\LimeWire
2008-04-18 20:02:46 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\gtk-2.0
2008-04-18 16:13:24 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\GRETECH
2008-04-18 16:13:13 0 d-------- C:\Program Files\GRETECH
2008-04-16 19:41:00 0 d-------- C:\Program Files\Azureus
2008-04-16 08:39:11 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Macromedia
2008-04-16 08:38:00 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-04-16 08:37:22 0 d-------- C:\Program Files\Common Files\Macromedia
2008-04-16 08:36:41 0 d-------- C:\Program Files\Macromedia
2008-04-16 08:36:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-15 21:57:33 0 d-------- C:\Program Files\DynoPlex
2008-04-15 21:29:42 256 --a------ C:\WINDOWS\system32\pool.bin
2008-04-15 20:31:36 0 d-------- C:\Program Files\DIFX
2008-04-15 03:00:49 0 d-------- C:\Program Files\MSXML 6.0
2008-04-14 15:29:21 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Roxio
2008-04-14 15:24:39 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Research In Motion
2008-04-14 15:23:44 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-04-14 15:23:10 0 d-------- C:\Program Files\Roxio
2008-04-14 15:22:26 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-04-14 15:21:39 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-14 15:20:03 0 d-------- C:\Program Files\Common Files\Research In Motion
2008-04-14 15:19:44 0 d-------- C:\Program Files\Research In Motion
2008-04-12 22:23:57 0 d-------- C:\Program Files\NeroInstall.bak
2008-04-12 22:22:23 0 d-------- C:\Program Files\Common Files\Nero
2008-04-03 21:00:19 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Snapfish
2008-04-03 21:00:18 2819 --a------ C:\WINDOWS\mozver.dat
2008-03-31 19:48:44 0 d-------- C:\Documents and Settings\Aziz Home\Application Data\Adobe
2008-03-25 20:20:56 0 d-------- C:\Program Files\Windows Live
2008-03-25 20:20:41 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-10-25 10:26]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.e xe" [2004-08-04 05:00]
"d07d4c3f"="C:\WINDOWS\system32\nwhrsdri.dll" [2008-05-22 21:42]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 16:28 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2007-12-05 02:41 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2007-12-05 02:41]
"BMd34e7fa3"="C:\WINDOWS\system32\xbiojjmc.dll " [2008-05-22 21:34]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CurseClient"="C:\Program Files\Curse\CurseClient.exe" [2008-05-19 07:57]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" []

[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"tscuninstall"=%systemroot%\system32\tscupgrd. exe

C:\Documents and Settings\Aziz Home\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\PSEXESVC]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX5000 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIB VA.EXE /FU "C:\WINDOWS\TEMP\E_S21F.tmp" /EF "HKLM"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InternetCalls]
"C:\Program Files\InternetCalls.com\InternetCalls\InternetCall s.exe" -nosplash -minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2kAutostart]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]
"c:\program files\voipbuster.com\voipbuster\voipbuster.exe" -nosplash -minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
"c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
"c:\Program Files\Zune\ZuneLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=3 (0x3)
"ZuneBusEnum"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)


[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\E]
AutoRun\command- E:\SETUP.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{a3a54843-cb07-11dc-a007-00301b80a18c}]
AutoRun\command- F:\SETUP.EXE




-- End of Deckard's System Scanner: finished at 2008-05-23 15:30:38 ------------
NurthinAziz is offline  
Old 05-23-2008, 06:58 PM   #6 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
CPU 1: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Percentage of Memory in Use: 23%
Physical Memory (total/avail): 1022.48 MiB / 786.53 MiB
Pagefile Memory (total/avail): 2459.74 MiB / 2374.17 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1929.75 MiB

C: is Fixed (NTFS) - 232.88 GiB total, 156.5 GiB free.
D: is CDROM (No Media)
F: is Removable (No Media)

\\.\PHYSICALDRIVE0 - WDC WD2500KS-00MJB0 - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - C:

\\.\PHYSICALDRIVE1 - EPSON Stylus Storage USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)

[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\DomainProfile\Authoriz edApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"="C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRende rer9"

[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List]
"C:\\Program Files\\Free Music Zilla\\FMZilla.exe"="C:\\Program Files\\Free Music Zilla\\FMZilla.exe:*:Enabled:FMZilla Module"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Documents and Settings\\Aziz Home\\My Documents\\filelib\\aziznurthin\\MySpaceGopher\\My SpaceMp3Gopher.exe"="C:\\Documents and Settings\\Aziz Home\\My Documents\\filelib\\aziznurthin\\MySpaceGopher\\My SpaceMp3Gopher.exe:*:Enabled:MySpace Mp3 Gopher Application"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Nexon\\MapleStory\\MapleStory.exe"="C:\\Nexon \\MapleStory\\MapleStory.exe:*:Enabled:MapleStory"
"C:\\ijji\\ENGLISH\\u_skid.exe"="C:\\ijji\\ENGLISH \\u_skid.exe:*:Enabled:<ijji Downloader>"
"C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe"="C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe:*:Enabled:Gun zLauncher"
"C:\\Program Files\\MAIET\\Gunz\\Gunz.exe"="C:\\Program Files\\MAIET\\Gunz\\Gunz.exe:*:Enabled:Gunz"
"C:\\Documents and Settings\\Aziz Home\\Desktop\\TBCenGB.exe"="C:\\Documents and Settings\\Aziz Home\\Desktop\\TBCenGB.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Aziz Home\\Desktop\\Server.exe"="C:\\Documents and Settings\\Aziz Home\\Desktop\\Server.exe:*:Enabled:Server"
"C:\\Documents and Settings\\Aziz Home\\Desktop\\dshobro03\\Server.exe"="C:\\Documen ts and Settings\\Aziz Home\\Desktop\\dshobro03\\Server.exe:*:Enabled:Ser ver"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Documents and Settings\\Aziz Home\\Desktop\\LocalMS 0.50\\LocalMS.exe"="C:\\Documents and Settings\\Aziz Home\\Desktop\\LocalMS 0.50\\LocalMS.exe:*:Enabled:MapleStory"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"="C:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe:*:Enabled:MediaManager9 Module"
"C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"="C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRende rer9"
"C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe" ="C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe: *:Enabled:VoipBuster"
"C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetC alls.exe"="C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetC alls.exe:*:Enabled:InternetCalls"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Prog ram Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled: BlueSoleil"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:EnabledNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTor rent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Aziz Home\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AZIZ
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Aziz Home
LOGONSERVER=\\AZIZ
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\sys tem32\WBEM;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WS F;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4b02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SAFEBOOT_OPTION=MINIMAL
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\AZIZHO~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\AZIZHO~1\LOCALS~1\Temp
USERDOMAIN=AZIZ
USERNAME=Aziz Home
USERPROFILE=C:\Documents and Settings\Aziz Home
windir=C:\WINDOWS
NurthinAziz is offline  
Old 05-23-2008, 06:58 PM   #7 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

-- User Profiles ---------------------------------------------------------------

Aziz Home (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {926CC8AE-8414-43DF-8EB4-CF26D9C3C663}
--> MsiExec.exe /I{0ADEA8E1-B211-41B8-8DD4-D9A5FB04A5FA}
--> MsiExec.exe /I{267D350E-51AB-40B8-AF9F-DA7ED5687044}
--> MsiExec.exe /I{7A9DC8F6-2466-4E04-BF51-BE499C5D02BD}
--> MsiExec.exe /I{85BD5F12-49EF-4B40-B1E0-77D85F6E99BF}
--> MsiExec.exe /I{EA9741F6-A7F2-497B-BBE4-2ED0136649BE}
--> MsiExec.exe /X{C628EC93-8E17-4114-BCE7-2D181B93FA0F}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware SE Professional --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6 ab2e\Setup.exe
Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2 --> C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e 58ff\Setup.exe
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{77D2A9D3-5800-43E3-B274-87841BC87DB2}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activ eX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugi n.exe
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb91 9b58\Setup.exe
Adobe Photoshop CS3 --> MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup --> MsiExec.exe /I{8AE03988-8C8C-40EE-BDC7-76781BEF1B1D}
Adobe Setup --> MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ArcSoft PhotoImpression 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}\Setup.exe" -l0x9
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Azureus Vuze --> C:\Program Files\Azureus\uninstall.exe
BlackBerry Desktop Software 4.3 --> MsiExec.exe /i{3AE87269-BD57-4A58-B13D-FC67664BCFB8}
BlackBerry Desktop Software 4.3 --> MsiExec.exe /I{3AE87269-BD57-4A58-B13D-FC67664BCFB8}
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
Curse Client --> C:\Program Files\Curse\uninstall.exe
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
DynoPlex eOffice --> C:\PROGRA~1\DynoPlex\UNWISE.EXE C:\PROGRA~1\DynoPlex\INSTALL.LOG
EPSON CX5000 Series User's Guide --> C:\Program Files\epson\guide\cx5000_e\uninstall.exe
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDAT E.EXE /R
EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Stylus CX5000 Scanner Driver Update --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{24ADC0E4-8D3E-40C4-9106-F2DE5E9112F1}\Setup.exe" -l0x9
ESET NOD32 Antivirus --> MsiExec.exe /I{944BFDEB-868F-4943-A37C-2852C7D9824A}
FLV to AVI MPEG WMV 3GP MP4 iPod Converter 3.2.0623 --> "C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter\unins000.exe"
Fraps (remove only) --> "C:\Fraps\uninstall.exe"
Free Music Zilla --> "C:\Program Files\Free Music Zilla\unins000.exe"
Free Video to Mp3 Converter version 2.5 --> "C:\Program Files\DVDVIDEOSOFT\Free Video to Mp3 Converter\unins000.exe"
GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
GPL MPEG-1/2 DirectShow Decoder Filter --> MsiExec.exe /I{870815CA-6B60-47B6-88DD-A67F42D2F03E}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
K-Lite Codec Pack 3.7.5 Basic --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Macromedia Flash MX 2004 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F353D44-73BB-4971-B31D-F7642E9E9531}\Setup.exe" -l0x9 UNINSTALL
MAGIX Ringtone Maker 2 silver (US) --> C:\MAGIX\Ringtone_Maker_2_silver\instslct.exe
MapleStory --> MsiExec.exe /I{92F1DEA6-C1D0-44DC-9A94-FC2DD0BD7BD1}
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 --> MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Xbox 360 Accessories 1.1 --> MsiExec.exe /X{66F0AC35-4805-44BC-A3D4-347D4196F9B3}
Mozilla Firefox (2.0.0.14) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Nero 8 --> MsiExec.exe /X{D6D5CB84-0E6E-4E69-B300-C690B6911033}
neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Real Alternative 1.7.5 --> "C:\Program Files\Real Alternative\unins000.exe"
Realtek AC'97 Audio --> Alcrmv.exe -r -m
Roxio Media Manager --> MsiExec.exe /X{5EED93A8-33AD-46A7-A6AC-4DEAFBEFEEE1}
Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Visio 2007 (KB947590) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spybot - Search & Destroy 1.5.2.20 --> "C:\WINDOWS\unins000.exe"
SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
Starcraft --> C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
UltraISO Premium V9.0 --> "C:\Program Files\UltraISO\unins000.exe"
Unlocker 1.8.5 --> C:\Program Files\Unlocker\uninst.exe
Update for Office 2007 (KB946691) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}
VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Ventrilo Client --> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VeohTV BETA --> C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
VIA Platform Device Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\ID river.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VideoLAN VLC media player 0.8.6d --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Driver Package - (mr7910) Image (08/08/2006 1.4.0.0) --> C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC45 7D98997\DPInstXP.exe /u C:\WINDOWS\system32\DRVSTORE\mr7910_1FFEF370F39864 F3AAA62219D434AE06B02B70AB\mr7910.inf
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spunin st.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
Xilisoft Video Converter --> C:\Program Files\Xilisoft\Video Converter 3\Uninstall.exe
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
Zune --> MsiExec.exe /X{FE0256DB-509C-40AC-B888-2543AD4298E6}
Zune Language Pack (ES) --> MsiExec.exe /I{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
Zune Language Pack (FR) --> MsiExec.exe /I{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}


-- Application Event Log -------------------------------------------------------

Event Record #/Type1775 / Error
Event Submitted/Written: 05/23/2008 03:30:27 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type1774 / Error
Event Submitted/Written: 05/23/2008 03:30:19 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type1773 / Error
Event Submitted/Written: 05/23/2008 03:30:19 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type1772 / Error
Event Submitted/Written: 05/23/2008 03:30:19 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type1771 / Error
Event Submitted/Written: 05/23/2008 03:30:19 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type6708 / Error
Event Submitted/Written: 05/23/2008 03:28:34 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
AFD
easdrv
epfwtdir
Fips
IPSec
MRxSmb
NetBIOS
NetBT
Processor
RasAcd
Rdbss
SCDEmu
sptd
Tcpip

Event Record #/Type6707 / Error
Event Submitted/Written: 05/23/2008 03:28:34 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Event Record #/Type6706 / Error
Event Submitted/Written: 05/23/2008 03:28:34 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Event Record #/Type6705 / Error
Event Submitted/Written: 05/23/2008 03:28:34 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31

Event Record #/Type6704 / Error
Event Submitted/Written: 05/23/2008 03:28:34 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
%%31



-- End of Deckard's System Scanner: finished at 2008-05-23 15:30:38 ------------
NurthinAziz is offline  
Old 05-23-2008, 08:21 PM   #8 (permalink)
 
Super Techie

Join Date: Aug 2007

Posts: 451

techpro5238 is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Step1

Download ComboFix from Here or Here to your Desktop.

1. Please open Notepad
  • Click Start, then Run
  • Type "notepad.exe" in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
Code:
KillAll::

DirLook::
C:\Fraps

File::
C:\WINDOWS\system32\kndovpeg.dll
C:\WINDOWS\system32\nwhrsdri.dll
C:\WINDOWS\system32\xbiojjmc.dll
C:\WINDOWS\system32\xnwwxxlp.dll
C:\WINDOWS\system32Windows-Update.exe
C:\WINDOWS\system32\emptyregdb.dat
C:\WINDOWS\system32\pool.bin
E:\SETUP.EXE
F:\SETUP.EXE

Folder::
C:\Documents and Settings\Aziz Home\Dr Delete
C:\ijji

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a54843-cb07-11dc-a007-00301b80a18c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"d07d4c3f"=-
"BMd34e7fa3"=-
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\ijji\\ENGLISH\\u_skid.exe"=-
3. Then in the text file go to FILE => SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply
techpro5238 is offline  
Old 05-24-2008, 12:51 AM   #9 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

Reboot after I did what you told me to and combofix gave me another log!

P.S. THANKYOU!!11





ComboFix 08-05-21.3 - Aziz Home 2008-05-23 21:36:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.660 [GMT -7:00]
Running from: C:\Documents and Settings\Aziz Home\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Aziz Home\Desktop\CFScript.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\emptyregdb.dat
C:\WINDOWS\system32\kndovpeg.dll
C:\WINDOWS\system32\nwhrsdri.dll
C:\WINDOWS\system32\pool.bin
C:\WINDOWS\system32\xbiojjmc.dll
C:\WINDOWS\system32\xnwwxxlp.dll
C:\WINDOWS\system32Windows-Update.exe
E:\SETUP.EXE
F:\SETUP.EXE
NurthinAziz is offline  
Old 05-24-2008, 12:51 AM   #10 (permalink)
 
True Techie

Join Date: Jun 2006

Location: Sacramento, CA

Posts: 148

NurthinAziz is on a distinguished road

Default Re: Virtumondo help! HJT log please!

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Aziz Home\Dr Delete
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete.sln
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete.suo
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr Delete.aps
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr Delete.cpp
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr Delete.h
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr Delete.rc
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr Delete.vcproj
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr DeleteDlg.cpp
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\Dr DeleteDlg.h
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\ReadMe.txt
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\resource.h
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\stdafx.cpp
C:\Documents and Settings\Aziz Home\Dr Delete\Dr Delete\stdafx.h
C:\WINDOWS\BMd34e7fa3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\emptyregdb.dat
C:\WINDOWS\system32\kndovpeg.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nwhrsdri.dll
C:\WINDOWS\system32\pool.bin
C:\WINDOWS\system32\xbiojjmc.dll
C:\WINDOWS\system32\xnwwxxlp.dll
C:\WINDOWS\system32Windows-Update.exe
.
---- Previous Run -------
.
C:\install.exe
C:\WINDOWS\BMd34e7fa3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\BJjSvGgh.ini
C:\WINDOWS\system32\BJjSvGgh.ini2
C:\WINDOWS\system32\hgGvSjJB.dll
C:\WINDOWS\system32\irdsrhwn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nnlebfks.ini2
C:\WINDOWS\system32\nnlebfks.tmp
C:\WINDOWS\system32\oWEeOXyb.ini
C:\WINDOWS\system32\oWEeOXyb.ini2
C:\WINDOWS\system32\qpklqnpk.ini
C:\WINDOWS\system32\rqRLcCuR.dll

.
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.

2008-05-23 15:25 . 2008-05-23 15:25 <DIR> d-------- C:\Deckard
2008-05-23 12:52 . 2004-08-03 14:31 482,304 --a--c--- C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-05-23 12:51 . 2001-08-23 05:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-05-23 12:49 . 2008-05-23 12:49 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-05-23 12:49 . 2008-05-23 12:49 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-05-23 12:49 . 2008-05-23 12:49 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-05-23 12:49 . 2008-05-23 12:49 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-05-23 12:49 . 2008-05-23 12:49 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-05-23 12:49 . 2008-05-23 12:49 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-05-23 07:52 . 2007-12-17 14:53 159,458 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-05-23 07:50 . 2001-08-17 12:13 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys
2008-05-23 07:14 . 2008-05-23 07:15 782 --a------ C:\WINDOWS\setupapi.old
2008-05-23 07:04 . 2008-05-23 17:15 534 ---hs---- C:\WINDOWS\system32\irdsrhwn.ini
2008-05-23 00:36 . 2008-05-23 00:41 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-22 22:20 . 2008-05-22 22:20 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-22 21:36 . 2008-05-22 21:58 <DIR> d-------- C:\VundoFix Backups
2008-05-22 21:01 . 2008-05-22 21:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-21 21:47 . 2008-05-22 20:51 <DIR> d-------- C:\Program Files\IObit
2008-05-21 20:44 . 2008-05-23 07:17 <DIR> d-------- C:\Documents and Settings\Aziz Home\Application Data\DNA
2008-05-21 17:54 . 2008-05-21 17:54 <DIR> d-------- C:\Documents and Settings\Aziz Home\Application Data\teamspeak2
2008-05-21 17:54 . 2008-05-21 17:54 34,064 --a------ C:\WINDOWS\system32\lhacm.acm
2008-05-20 20:04 . 2008-05-21 15:42 <DIR> d-------- C:\Fraps
2008-05-17 17:23 . 2008-05-17 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-05-17 17:15 . 2006-11-22 10:01 693,760 --a------ C:\WINDOWS\system32\drivers\hardlock.sys
2008-05-17 17:15 . 2008-05-17 17:15 47,616 --a------ C:\WINDOWS\system32\drivers\Haspnt.sys
2008-05-17 17:15 . 2008-05-17 17:15 6,656 --a------ C:\WINDOWS\system32\haspvdd.dll
2008-05-17 17:15 . 2008-01-19 13:58 2,577 --a------ C:\WINDOWS\system32\config.hsp
2008-05-17 17:15 . 2008-05-17 17:15 383 --a------ C:\WINDOWS\system32\haspdos.sys
2008-05-15 23:20 . 2004-08-04 05:00 811,064 --a------ C:\WINDOWS\system32\imjp81k.dll
2008-05-13 17:32 . 2008-05-22 21:23 692 --a------ C:\WINDOWS\wininit.ini
2008-05-09 22:01 . 2008-05-09 22:01 <DIR> d-------- C:\Program Files\Curse
2008-05-08 21:00 . 2008-05-08 21:00 <DIR> d-------- C:\Nexon
2008-05-06 21:45 . 2008-05-06 21:45 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-06 19:59 . 2008-05-06 19:59 <DIR> d-------- C:\Program Files\Ventrilo
2008-05-06 19:59 . 2008-05-06 19:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-05 22:53 . 2008-05-05 22:53 <DIR> d-------- C:\Logs
2008-05-05 07:13 . 2008-05-15 09:38 <DIR> d-------- C:\Program Files\World of Warcraft
2008-05-02 15:53 . 2008-05-02 15:53 <DIR> d-------- C:\Program Files\Haali
2008-04-25 21:12 . 2008-05-18 13:47 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-25 21:12 . 2008-04-25 21:12 1,409 --a------ C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-05-23 19:47 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-23 04:39 --------- d-----w C:\Program Files\PowerISO
2008-05-23 03:51 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Azureus
2008-05-22 04:08 --------- d-----w C:\Program Files\CleanUp!
2008-05-22 03:52 --------- d-----w C:\Program Files\SpywareGuard
2008-05-22 02:11 --------- d-----w C:\Program Files\Starcraft
2008-05-14 04:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 01:41 --------- d-----w C:\Program Files\Free Music Zilla
2008-05-07 04:59 --------- d-----w C:\Program Files\SpywareBlaster
2008-05-05 14:27 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-04-24 00:25 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\InternetCalls
2008-04-24 00:14 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\VoipBuster
2008-04-23 23:56 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Media Player Classic
2008-04-23 23:55 --------- d-----w C:\Program Files\Real Alternative
2008-04-23 23:17 --------- d-----w C:\Program Files\Apex
2008-04-23 03:14 --------- d-----w C:\Program Files\HiFisoftware
2008-04-22 14:10 --------- d-----w C:\Program Files\Xilisoft
2008-04-21 04:07 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Jubler
2008-04-20 00:09 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\LimeWire
2008-04-19 03:02 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\gtk-2.0
2008-04-18 23:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-18 23:13 --------- d-----w C:\Program Files\GRETECH
2008-04-18 23:13 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\GRETECH
2008-04-17 02:41 --------- d-----w C:\Program Files\Azureus
2008-04-16 15:38 --------- d-----w C:\Program Files\Common Files\Macromedia Shared
2008-04-16 15:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
2008-04-16 15:37 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-04-16 15:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-16 15:36 --------- d-----w C:\Program Files\Macromedia
2008-04-16 04:57 --------- d-----w C:\Program Files\DynoPlex
2008-04-15 10:00 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-14 22:29 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Roxio
2008-04-14 22:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Roxio
2008-04-14 22:28 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-04-14 22:24 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Research In Motion
2008-04-14 22:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2008-04-14 22:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-14 22:23 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-04-14 22:22 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-04-14 22:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-14 22:20 --------- d-----w C:\Program Files\Common Files\Research In Motion
2008-04-13 05:23 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-13 05:22 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-13 05:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-11 02:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-04 04:00 --------- d-----w C:\Documents and Settings\Aziz Home\Application Data\Snapfish
2008-03-30 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-26 03:20 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-26 03:20 --------- d-----w C:\Program Files\Windows Live
2008-03-26 03:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-29 00:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 23:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))) )))))))
.

---- Directory of C:\Fraps ----

2008-05-20 20:04 38713 --a------ C:\Fraps\uninstall.exe
2005-12-03 03:06 2826240 --a------ C:\Fraps\fraps.exe
2005-12-03 03:05 507904 --a------ C:\Fraps\frapslcd.dll
2005-12-03 03:05 106496 --a------ C:\Fraps\fraps.dll
2005-12-03 02:37 9499 --a------ C:\Fraps\changes.txt
2005-12-03 02:33 1860 --a------ C:\Fraps\README.HTM
2005-11-07 13:57 51200 --a------ C:\Fraps\fraps64.dll
2005-11-07 13:51 286208 --a------ C:\Fraps\fraps64.dat
2005-11-06 22:44 21404 --a------ C:\Fraps\HELP\fps.gif
2005-11-06 22:44 16461 --a------ C:\Fraps\HELP\general.gif
2005-11-06 22:20 2656 --a------ C:\Fraps\HELP\help_general.htm
2005-11-06 22:17 5568 --a------ C:\Fraps\HELP\help_fps.htm
2005-06-15 09:46 20950 --a------ C:\Fraps\HELP\movies.gif
2005-06-15 08:14 19413 --a------ C:\Fraps\HELP\screenshots.gif
2005-06-15 07:52 8714 --a------ C:\Fraps\HELP\help_movies.htm
2005-02-23 11:38 2439 --a------ C:\Fraps\HELP\help_screenshots.htm


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CurseClient"="C:\Program Files\Curse\CurseClient.exe" [2008-05-19 07:57 1400832]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [ ]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 16:35 67112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-10-25 10:26 1410304]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.e xe" [2004-08-04 05:00 208952]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2007-12-05 02:41 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.e xe" [2004-08-03 14:59 44544]

C:\Documents and Settings\Aziz Home\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2006-08-01 16:35 67112 C:\Program Files\AIM\aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
--a------ 2006-11-02 17:57 528384 C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-02-28 17:07 132392 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-03 16:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX5000 Series]
--a------ 2006-02-14 05:00 131072 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIB VA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InternetCalls]
C:\Program Files\InternetCalls.com\InternetCalls\InternetCall s.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-02-18 16:29 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-02-28 09:59 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 02:41 8523776 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 02:41 81920 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2kAutostart]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-06 17:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2007-08-16 08:56 236016 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-04-01 18:35 3587120 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]
c:\program files\voipbuster.com\voipbuster\voipbuster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
--a------ 2007-09-26 19:05 734264 c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2007-11-15 22:51 166304 c:\Program Files\Zune\ZuneLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=3 (0x3)
"ZuneBusEnum"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Documents and Settings\\Aziz Home\\My Documents\\filelib\\aziznurthin\\MySpaceGopher\\My SpaceMp3Gopher.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Nexon\\MapleStory\\MapleStory.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\World of Warcraft\\Repair.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfw tdir.sys [2007-10-25 10:27]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys []
S4 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 22:51]
S4 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 22:51]

.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 14:00:03 C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job"
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoCare.exe
"2008-05-24 03:00:00 C:\WINDOWS\Tasks\AwcProUpdate.job"
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoUpdate.ex
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro
.
************************************************** ************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 21:41:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\SpywareGuard\sgbhp.exe
.
************************************************** ************************
.
Completion time: 2008-05-23 21:47:01 - machine was rebooted [Aziz Home]
ComboFix-quarantined-files.txt 2008-05-24 04:46:39

Pre-Run: 167,929,171,968 bytes free
Post-Run: 167,923,949,568 bytes free

315 --- E O F --- 2008-05-16 10:01:17
NurthinAziz is offline  
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hi Guys, Can someone help me with smitfraud. here is mu HJT log Rosco_beats HijackThis Logs (finished) 13 05-15-2008 08:05 AM
HJT Log. Internet Issues Lukey114 HijackThis Logs (finished) 4 04-16-2008 09:02 AM
HJT log from a business computer cwr89 HijackThis Logs (finished) 7 02-15-2008 08:22 PM
HJT log mds303 HijackThis Logs (finished) 3 01-12-2008 01:36 PM
HJT Log. Lukey114 HijackThis Logs (finished) 20 12-20-2007 06:49 AM