 
                 
                InterviewSolution
| 1. | Solve : W32.SillyFDC? | 
| Answer» Hi, 
 A copy of the report can be found at this location: %systemdrive%\lopR.txt, in most cases C:\lopR.txt Many thanks indeed for your help evilfantasy, here is the log: --------------------\\ Lop S&D 4.2.5-0 XP/Vista Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3 X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz ) BIOS : Phoenix ROM BIOS PLUS Version 1.10 A07 USER : Peter ( Administrator ) BOOT : Normal boot Antivirus : Norton Internet Security 2006 2006 (Not Activated) Firewall : Norton Internet Security 2006 2006 (Activated) A:\ (USB) C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go) D:\ (USB) - FAT - Total:1967 Mo (Free:1 Go) E:\ (CD or DVD) F:\ (Local Disk) - FAT32 - Total:232 Go (Free:9 Go) "C:\Lop SD" ( MAJ : 19-12-2008|23:40 ) Option : [1] ( 27/03/2009| 9:20 ) --------------------\\ Listing folders in APPLIC~1 [04/01/2009|10:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft [25/01/2009|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} [27/03/2009|07:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\~0 [14/03/2009|08:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [25/01/2009|11:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple [25/01/2009|11:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer [04/01/2009|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google [01/02/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies [25/03/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft [27/03/2009|06:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes [15/02/2009|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [08/02/2009|10:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help [04/01/2009|16:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS [28/02/2009|09:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype [26/03/2009|19:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com [16/03/2009|06:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [23/03/2009|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP [04/01/2009|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [14/02/2009|08:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [04/01/2009|10:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [11/01/2009|08:32] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [04/01/2009|11:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [05/01/2009|15:38] C:\DOCUME~1\PETERE~1\APPLIC~1\Adobe [25/01/2009|13:06] C:\DOCUME~1\PETERE~1\APPLIC~1\Apple Computer [04/01/2009|14:23] C:\DOCUME~1\PETERE~1\APPLIC~1\Google [04/01/2009|11:08] C:\DOCUME~1\PETERE~1\APPLIC~1\Identities [04/01/2009|14:58] C:\DOCUME~1\PETERE~1\APPLIC~1\Macromedia [27/03/2009|06:14] C:\DOCUME~1\PETERE~1\APPLIC~1\Malwarebytes [05/03/2009|19:52] C:\DOCUME~1\PETERE~1\APPLIC~1\Microsoft [24/03/2009|18:27] C:\DOCUME~1\PETERE~1\APPLIC~1\Skype [24/03/2009|17:13] C:\DOCUME~1\PETERE~1\APPLIC~1\skypePM [25/01/2009|08:00] C:\DOCUME~1\PETERE~1\APPLIC~1\Steinberg [21/03/2009|17:18] C:\DOCUME~1\PETERE~1\APPLIC~1\Sun [26/03/2009|19:26] C:\DOCUME~1\PETERE~1\APPLIC~1\SUPERAntiSpyware.com [10/01/2009|12:53] C:\DOCUME~1\PETERE~1\APPLIC~1\Symantec [14/02/2009|08:14] C:\DOCUME~1\PETERE~1\APPLIC~1\uniblue [05/02/2009|12:35] C:\DOCUME~1\PETERE~1\APPLIC~1\vlc --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [25/03/2009 19:23][--a------] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [16/03/2009 10:51][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [14/02/2009 08:14][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job [24/03/2009 16:37][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job [21/03/2009 00:22][--a------] C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Peter.job [27/03/2009 06:34][--ah-----] C:\WINDOWS\tasks\SA.DAT [16/07/2003 20:36][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [25/01/2009|07:19] C:\Program Files\7-Zip [14/03/2009|08:05] C:\Program Files\Adobe [04/01/2009|11:34] C:\Program Files\Analog Devices [25/01/2009|11:18] C:\Program Files\Apple Software Update [27/03/2009|09:16] C:\Program Files\BitComet [25/01/2009|11:22] C:\Program Files\Bonjour [26/03/2009|19:06] C:\Program Files\CCleaner [26/03/2009|19:25] C:\Program Files\Common Files [04/01/2009|10:46] C:\Program Files\ComPlus Applications [04/01/2009|12:58] C:\Program Files\CONEXANT [18/03/2009|20:12] C:\Program Files\Creative Element Power Tools [01/02/2009|08:47] C:\Program Files\DU Meter [27/03/2009|07:07] C:\Program Files\Enigma Software Group [04/01/2009|19:06] C:\Program Files\GenoPro [04/01/2009|13:09] C:\Program Files\Google [04/01/2009|18:23] C:\Program Files\HighCriteria [18/01/2009|16:41] C:\Program Files\InstallShield Installation Information [04/01/2009|11:36] C:\Program Files\Intel [14/02/2009|08:35] C:\Program Files\Internet Explorer [25/01/2009|11:25] C:\Program Files\iPod [25/01/2009|11:26] C:\Program Files\iTunes [21/03/2009|17:20] C:\Program Files\Java [25/03/2009|19:12] C:\Program Files\Lavasoft [04/01/2009|12:54] C:\Program Files\Lexmark 5200 Series [27/03/2009|06:14] C:\Program Files\Malwarebytes' Anti-Malware [24/01/2009|09:28] C:\Program Files\M-Audio Fast Track [06/01/2009|20:24] C:\Program Files\Messenger [04/01/2009|11:01] C:\Program Files\microsoft frontpage [04/01/2009|13:18] C:\Program Files\Microsoft Office [04/01/2009|13:32] C:\Program Files\Microsoft Visual Studio [04/01/2009|13:34] C:\Program Files\Microsoft Works [06/01/2009|20:18] C:\Program Files\Movie Maker [13/02/2009|19:56] C:\Program Files\MSBuild [04/01/2009|10:45] C:\Program Files\MSN [04/01/2009|10:45] C:\Program Files\MSN Gaming Zone [06/01/2009|20:14] C:\Program Files\NetMeeting [04/01/2009|17:27] C:\Program Files\Nike+ Utility [21/03/2009|07:08] C:\Program Files\Norton Ghost [16/03/2009|10:19] C:\Program Files\Norton Internet Security [04/01/2009|16:27] C:\Program Files\NOS [04/01/2009|10:47] C:\Program Files\Online Services [06/01/2009|20:14] C:\Program Files\Outlook Express [04/01/2009|12:59] C:\Program Files\PowerISO [25/01/2009|11:21] C:\Program Files\QuickTime [13/02/2009|19:56] C:\Program Files\Reference Assemblies [28/02/2009|09:34] C:\Program Files\Skype [14/02/2009|08:14] C:\Program Files\SpeedupmyPC [15/02/2009|10:29] C:\Program Files\Steinberg [26/03/2009|19:26] C:\Program Files\SUPERAntiSpyware [06/01/2009|06:28] C:\Program Files\Symantec [25/01/2009|07:44] C:\Program Files\Syncrosoft [04/01/2009|17:26] C:\Program Files\TClockEx [14/02/2009|08:14] C:\Program Files\Uniblue [04/01/2009|11:08] C:\Program Files\Uninstall Information [05/02/2009|12:28] C:\Program Files\VideoLAN [07/01/2009|10:27] C:\Program Files\Windows Desktop Search [06/01/2009|21:25] C:\Program Files\Windows Media Connect 2 [06/01/2009|21:25] C:\Program Files\Windows Media Player [06/01/2009|20:14] C:\Program Files\Windows NT [04/01/2009|11:41] C:\Program Files\WindowsUpdate [14/02/2009|08:10] C:\Program Files\WinZip [04/01/2009|11:01] C:\Program Files\xerox [04/01/2009|15:27] C:\Program Files\Yahoo! --------------------\\ Listing Folders in C:\Program Files\Common Files [14/03/2009|08:05] C:\Program Files\Common Files\Adobe [04/01/2009|15:04] C:\Program Files\Common Files\Adobe AIR [25/01/2009|11:25] C:\Program Files\Common Files\Apple [04/01/2009|13:32] C:\Program Files\Common Files\DESIGNER [24/01/2009|09:27] C:\Program Files\Common Files\InstallShield [04/01/2009|12:59] C:\Program Files\Common Files\logishrd [04/01/2009|13:33] C:\Program Files\Common Files\Microsoft Shared [04/01/2009|10:46] C:\Program Files\Common Files\MSSoap [04/01/2009|10:37] C:\Program Files\Common Files\ODBC [04/01/2009|10:47] C:\Program Files\Common Files\Services [28/02/2009|09:34] C:\Program Files\Common Files\Skype [04/01/2009|10:37] C:\Program Files\Common Files\SpeechEngines [27/03/2009|06:16] C:\Program Files\Common Files\Symantec Shared [06/01/2009|20:14] C:\Program Files\Common Files\System [26/03/2009|19:25] C:\Program Files\Common Files\Wise Installation Wizard --------------------\\ Process ( 48 Processes ) iexplore.exe ~ [PID:1044] --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders C:\DOCUME~1\PETERE~1\Cookies\[emailprotected][1].txt C:\DOCUME~1\PETERE~1\Cookies\[emailprotected][1].txt C:\DOCUME~1\PETERE~1\Cookies\[emailprotected][1].txt C:\DOCUME~1\PETERE~1\Cookies\[emailprotected][1].txt --------------------\\ Searching within the Registry ..... OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-27 09:19:58 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-27 09:22:43 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Searching for other infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\PETERE~1\Favorites\SpyHunter Security Suite v3.4.9+Crack-HeartBug (download torrent) - TPB.url C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.2 Pro. with crack.Sfx.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.3 + Keygen.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Total_Recorder_v4.x_Generic_Crack.zip C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\keygen.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\setup.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\ssg.nfo C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\Torrent downloaded from Demonoid.com.txt [F:104][D:9]-> C:\DOCUME~1\PETERE~1\LOCALS~1\Temp [F:409][D:0]-> C:\DOCUME~1\PETERE~1\Cookies [F:1336][D:5]-> C:\DOCUME~1\PETERE~1\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - 27/03/2009| 9:24 - Option : [1] --------------------\\ Scan completed at 9:24:32 You are going to have to remove the cracks before I can continue helping. Download the OTMoveIt3 by OldTimer Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTMoveIt3.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :services :reg :files C:\DOCUME~1\PETERE~1\Favorites\SpyHunter Security Suite v3.4.9+Crack-HeartBug (download torrent) - TPB.url C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.2 Pro. with crack.Sfx.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.3 + Keygen.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Total_Recorder_v4.x_Generic_Crack.zip C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\keygen.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\setup.exe C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\ssg.nfo C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\Torrent downloaded from Demonoid.com.txt :Commands [purity] [emptytemp] [start explorer] [REBOOT] * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. Close OTMoveIt3 Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes.Here it is evilfantasy (after reboot)... ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\DOCUME~1\PETERE~1\Favorites\SpyHunter Security Suite v3.4.9+Crack-HeartBug (download torrent) - TPB.url not found. C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG moved successfully. C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.2 Pro. with crack.Sfx.exe moved successfully. C:\DOCUME~1\PETERE~1\My Documents\Software\Total Recorder 4.3 + Keygen.exe moved successfully. C:\DOCUME~1\PETERE~1\My Documents\Software\Total_Recorder_v4.x_Generic_Crack.zip moved successfully. File/Folder C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\keygen.exe not found. File/Folder C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\setup.exe not found. File/Folder C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\ssg.nfo not found. File/Folder C:\DOCUME~1\PETERE~1\My Documents\Software\Corel.Paint.Shop.Pro.Photo.XI.v11.0.Incl.Keygen-SSG\Torrent downloaded from Demonoid.com.txt not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\Perflib_Perfdata_844.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\~DFA191.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\~DFA1A4.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6b0.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03272009_170508 Files moved on Reboot... File C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\Perflib_Perfdata_844.dat not found! File C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\~DFA191.tmp not found! File C:\DOCUME~1\PETERE~1\LOCALS~1\Temp\~DFA1A4.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\WINDOWS\temp\Perflib_Perfdata_6b0.dat moved successfully. Thank you. Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. Double click LopSD.exe - If you are using Windows Vista, right-click on the LopSD icon and select Run as administrator to perform this scan. 
 Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixHi evilfantasy (and many thanks again for all this!), here are the logs: --------------------\\ Lop S&D 4.2.5-0 XP/Vista Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3 X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz ) BIOS : Phoenix ROM BIOS PLUS Version 1.10 A07 USER : Peter ( Administrator ) BOOT : Normal boot Antivirus : Norton Internet Security 2006 2006 (Not Activated) Firewall : Norton Internet Security 2006 2006 (Not Activated) A:\ (USB) C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go) E:\ (CD or DVD) "C:\Lop SD" ( MAJ : 19-12-2008|23:40 ) Option : [2] ( 27/03/2009|17:55 ) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Listing folders in APPLIC~1 [04/01/2009|10:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft [25/01/2009|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} [14/03/2009|08:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [25/01/2009|11:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple [25/01/2009|11:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer [04/01/2009|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google [01/02/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies [27/03/2009|07:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft [27/03/2009|06:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes [15/02/2009|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [08/02/2009|10:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help [04/01/2009|16:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS [28/02/2009|09:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype [26/03/2009|19:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com [16/03/2009|06:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [23/03/2009|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP [04/01/2009|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [14/02/2009|08:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [04/01/2009|10:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [11/01/2009|08:32] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [04/01/2009|11:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [05/01/2009|15:38] C:\DOCUME~1\PETERE~1\APPLIC~1\Adobe [25/01/2009|13:06] C:\DOCUME~1\PETERE~1\APPLIC~1\Apple Computer [04/01/2009|14:23] C:\DOCUME~1\PETERE~1\APPLIC~1\Google [04/01/2009|11:08] C:\DOCUME~1\PETERE~1\APPLIC~1\Identities [04/01/2009|14:58] C:\DOCUME~1\PETERE~1\APPLIC~1\Macromedia [27/03/2009|06:14] C:\DOCUME~1\PETERE~1\APPLIC~1\Malwarebytes [05/03/2009|19:52] C:\DOCUME~1\PETERE~1\APPLIC~1\Microsoft [24/03/2009|18:27] C:\DOCUME~1\PETERE~1\APPLIC~1\Skype [24/03/2009|17:13] C:\DOCUME~1\PETERE~1\APPLIC~1\skypePM [25/01/2009|08:00] C:\DOCUME~1\PETERE~1\APPLIC~1\Steinberg [21/03/2009|17:18] C:\DOCUME~1\PETERE~1\APPLIC~1\Sun [26/03/2009|19:26] C:\DOCUME~1\PETERE~1\APPLIC~1\SUPERAntiSpyware.com [10/01/2009|12:53] C:\DOCUME~1\PETERE~1\APPLIC~1\Symantec [14/02/2009|08:14] C:\DOCUME~1\PETERE~1\APPLIC~1\uniblue [05/02/2009|12:35] C:\DOCUME~1\PETERE~1\APPLIC~1\vlc --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [25/03/2009 19:23][--a------] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [16/03/2009 10:51][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job [14/02/2009 08:14][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job [24/03/2009 16:37][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job [21/03/2009 00:22][--a------] C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Peter.job [27/03/2009 17:43][--ah-----] C:\WINDOWS\tasks\SA.DAT [16/07/2003 20:36][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [25/01/2009|07:19] C:\Program Files\7-Zip [14/03/2009|08:05] C:\Program Files\Adobe [04/01/2009|11:34] C:\Program Files\Analog Devices [25/01/2009|11:18] C:\Program Files\Apple Software Update [27/03/2009|16:59] C:\Program Files\BitComet [25/01/2009|11:22] C:\Program Files\Bonjour [26/03/2009|19:06] C:\Program Files\CCleaner [26/03/2009|19:25] C:\Program Files\Common Files [04/01/2009|10:46] C:\Program Files\ComPlus Applications [04/01/2009|12:58] C:\Program Files\CONEXANT [18/03/2009|20:12] C:\Program Files\Creative Element Power Tools [01/02/2009|08:47] C:\Program Files\DU Meter [27/03/2009|07:07] C:\Program Files\Enigma Software Group [04/01/2009|19:06] C:\Program Files\GenoPro [04/01/2009|13:09] C:\Program Files\Google [04/01/2009|18:23] C:\Program Files\HighCriteria [18/01/2009|16:41] C:\Program Files\InstallShield Installation Information [04/01/2009|11:36] C:\Program Files\Intel [14/02/2009|08:35] C:\Program Files\Internet Explorer [25/01/2009|11:25] C:\Program Files\iPod [25/01/2009|11:26] C:\Program Files\iTunes [21/03/2009|17:20] C:\Program Files\Java [27/03/2009|07:06] C:\Program Files\Lavasoft [04/01/2009|12:54] C:\Program Files\Lexmark 5200 Series [27/03/2009|06:14] C:\Program Files\Malwarebytes' Anti-Malware [24/01/2009|09:28] C:\Program Files\M-Audio Fast Track [06/01/2009|20:24] C:\Program Files\Messenger [04/01/2009|11:01] C:\Program Files\microsoft frontpage [04/01/2009|13:18] C:\Program Files\Microsoft Office [04/01/2009|13:32] C:\Program Files\Microsoft Visual Studio [04/01/2009|13:34] C:\Program Files\Microsoft Works [06/01/2009|20:18] C:\Program Files\Movie Maker [13/02/2009|19:56] C:\Program Files\MSBuild [04/01/2009|10:45] C:\Program Files\MSN [04/01/2009|10:45] C:\Program Files\MSN Gaming Zone [06/01/2009|20:14] C:\Program Files\NetMeeting [04/01/2009|17:27] C:\Program Files\Nike+ Utility [21/03/2009|07:08] C:\Program Files\Norton Ghost [16/03/2009|10:19] C:\Program Files\Norton Internet Security [04/01/2009|16:27] C:\Program Files\NOS [04/01/2009|10:47] C:\Program Files\Online Services [06/01/2009|20:14] C:\Program Files\Outlook Express [04/01/2009|12:59] C:\Program Files\PowerISO [25/01/2009|11:21] C:\Program Files\QuickTime [13/02/2009|19:56] C:\Program Files\Reference Assemblies [28/02/2009|09:34] C:\Program Files\Skype [14/02/2009|08:14] C:\Program Files\SpeedupmyPC [15/02/2009|10:29] C:\Program Files\Steinberg [26/03/2009|19:26] C:\Program Files\SUPERAntiSpyware [06/01/2009|06:28] C:\Program Files\Symantec [25/01/2009|07:44] C:\Program Files\Syncrosoft [04/01/2009|17:26] C:\Program Files\TClockEx [14/02/2009|08:14] C:\Program Files\Uniblue [04/01/2009|11:08] C:\Program Files\Uninstall Information [05/02/2009|12:28] C:\Program Files\VideoLAN [07/01/2009|10:27] C:\Program Files\Windows Desktop Search [06/01/2009|21:25] C:\Program Files\Windows Media Connect 2 [06/01/2009|21:25] C:\Program Files\Windows Media Player [06/01/2009|20:14] C:\Program Files\Windows NT [04/01/2009|11:41] C:\Program Files\WindowsUpdate [14/02/2009|08:10] C:\Program Files\WinZip [04/01/2009|11:01] C:\Program Files\xerox [04/01/2009|15:27] C:\Program Files\Yahoo! --------------------\\ Listing Folders in C:\Program Files\Common Files [14/03/2009|08:05] C:\Program Files\Common Files\Adobe [04/01/2009|15:04] C:\Program Files\Common Files\Adobe AIR [25/01/2009|11:25] C:\Program Files\Common Files\Apple [04/01/2009|13:32] C:\Program Files\Common Files\DESIGNER [24/01/2009|09:27] C:\Program Files\Common Files\InstallShield [04/01/2009|12:59] C:\Program Files\Common Files\logishrd [04/01/2009|13:33] C:\Program Files\Common Files\Microsoft Shared [04/01/2009|10:46] C:\Program Files\Common Files\MSSoap [04/01/2009|10:37] C:\Program Files\Common Files\ODBC [04/01/2009|10:47] C:\Program Files\Common Files\Services [28/02/2009|09:34] C:\Program Files\Common Files\Skype [04/01/2009|10:37] C:\Program Files\Common Files\SpeechEngines [27/03/2009|06:16] C:\Program Files\Common Files\Symantec Shared [06/01/2009|20:14] C:\Program Files\Common Files\System [26/03/2009|19:25] C:\Program Files\Common Files\Wise Installation Wizard --------------------\\ Process ( 54 Processes ) ... OK ! --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders No Lop folder found ! --------------------\\ Searching within the Registry ..... OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-27 17:58:50 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Searching for other infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\PETERE~1\Recent\Total_Recorder_v4.x_Generic_Crack.zip.lnk [F:99][D:6]-> C:\DOCUME~1\PETERE~1\LOCALS~1\Temp [F:21][D:0]-> C:\DOCUME~1\PETERE~1\Cookies [F:825][D:9]-> C:\DOCUME~1\PETERE~1\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - 27/03/2009| 9:24 - Option : [1] 2 - "C:\Lop SD\LopR_2.txt" - 27/03/2009|17:52 - Option : [2] 3 - "C:\Lop SD\LopR_3.txt" - 27/03/2009|18:06 - Option : [2] --------------------\\ Scan completed at 18:06:09 ComboFix 09-03-26.03 - Peter 2009-03-27 18:19:39.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.122 [GMT 0:00] Running from: c:\documents and settings\Peter \Desktop\ComboFix.exe AV: Norton Internet Security 2006 *On-access scanning disabled* (Updated) FW: Norton Internet Security 2006 *disabled* FW: Norton Internet Worm Protection *disabled* * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\patchw32.dll c:\windows\pw32a.dll c:\windows\system32\_000096_.tmp.dll c:\windows\system32\_000099_.tmp.dll c:\windows\system32\_000109_.tmp.dll c:\windows\system32\_000120_.tmp.dll c:\windows\system32\_000122_.tmp.dll c:\windows\system32\_005487_.tmp.dll c:\windows\system32\_005488_.tmp.dll c:\windows\system32\_005489_.tmp.dll c:\windows\system32\_005490_.tmp.dll c:\windows\system32\_005497_.tmp.dll c:\windows\system32\_005498_.tmp.dll c:\windows\system32\_005499_.tmp.dll c:\windows\system32\_005500_.tmp.dll c:\windows\system32\_005502_.tmp.dll c:\windows\system32\_005503_.tmp.dll c:\windows\system32\_005506_.tmp.dll c:\windows\system32\_005507_.tmp.dll c:\windows\system32\_005510_.tmp.dll c:\windows\system32\_005511_.tmp.dll c:\windows\system32\_005513_.tmp.dll c:\windows\system32\_005516_.tmp.dll c:\windows\system32\_005517_.tmp.dll c:\windows\system32\_005522_.tmp.dll c:\windows\system32\_005524_.tmp.dll c:\windows\system32\_005527_.tmp.dll c:\windows\system32\_005529_.tmp.dll c:\windows\system32\_005530_.tmp.dll c:\windows\system32\_005531_.tmp.dll c:\windows\system32\_005532_.tmp.dll c:\windows\system32\_005533_.tmp.dll c:\windows\system32\_005536_.tmp.dll c:\windows\system32\_005537_.tmp.dll c:\windows\system32\_005538_.tmp.dll c:\windows\system32\_005539_.tmp.dll c:\windows\system32\_005540_.tmp.dll c:\windows\system32\_005545_.tmp.dll c:\windows\system32\_005547_.tmp.dll c:\windows\system32\_005548_.tmp.dll . ((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 ))))))))))))))))))))))))))))))) . 2009-03-27 17:05 . 2009-03-27 17:05d--------C:\_OTMoveIt 2009-03-27 09:14 . 2009-03-27 18:06d--------C:\Lop SD 2009-03-27 06:14 . 2009-03-27 06:14d--------c:\program files\Malwarebytes' Anti-Malware 2009-03-27 06:14 . 2009-03-27 06:14d--------c:\documents and settings\Peter \Application Data\Malwarebytes 2009-03-27 06:14 . 2009-03-27 06:14d--------c:\documents and settings\All Users\Application Data\Malwarebytes 2009-03-27 06:14 . 2009-03-26 16:4938,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-27 06:14 . 2009-03-26 16:4915,504--a------c:\windows\system32\drivers\mbam.sys 2009-03-26 19:26 . 2009-03-26 19:26d--------c:\program files\SUPERAntiSpyware 2009-03-26 19:26 . 2009-03-26 19:26d--------c:\documents and settings\Peter \Application Data\SUPERAntiSpyware.com 2009-03-26 19:26 . 2009-03-26 19:26d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-03-26 19:25 . 2009-03-26 19:25d--------c:\program files\Common Files\Wise Installation Wizard 2009-03-26 19:06 . 2009-03-26 19:06d--------c:\program files\CCleaner 2009-03-25 19:12 . 2009-03-27 07:06d--------c:\program files\Lavasoft 2009-03-23 20:44 . 2009-03-23 21:32d-a------c:\documents and settings\All Users\Application Data\TEMP 2009-03-23 20:07 . 2009-03-23 20:0914,417,922--a------C:\SYM_REGISTRY_BACKUP.reg 2009-03-21 20:49 . 2009-03-27 07:07d--------c:\program files\Enigma Software Group 2009-03-21 18:00 . 2009-03-21 18:22d--------c:\documents and settings\Peter\.housecall6.6 2009-03-21 17:22 . 2009-03-21 17:22d--------c:\windows\Sun 2009-03-21 17:21 . 2009-03-21 17:20410,984--a------c:\windows\system32\deploytk.dll 2009-03-21 17:21 . 2009-03-21 17:2073,728--a------c:\windows\system32\javacpl.cpl 2009-03-21 17:20 . 2009-03-21 17:20d--------c:\program files\Java 2009-03-18 20:12 . 2001-01-20 11:43712,704--a------c:\windows\system32\_ISource21.dll 2009-03-18 20:12 . 2004-10-08 12:15278,016--a------c:\windows\system32\aisExif.dll 2009-03-18 20:12 . 2004-12-06 09:27231,139--a------c:\windows\system32\BtnPlus1.ocx 2009-03-18 20:12 . 1999-10-30 02:00167,936--a------c:\windows\system32\ccrpftv6.ocx 2009-03-18 20:12 . 1996-02-11 01:42113,664--a------c:\windows\system32\APIGID32.DLL 2009-03-18 20:12 . 2001-07-28 11:4757,344--a------c:\windows\system32\mp3SpecX4.dll 2009-03-18 20:12 . 2001-12-07 11:4144,752--a------c:\windows\system32\FMDROP32.OCX 2009-03-18 20:12 . 2000-02-03 08:3039,424--a------c:\windows\system32\rpiAccessProcess.dll 2009-03-18 20:11 . 2004-03-09 00:00224,016--a------c:\windows\system32\TABCTL32.OCX 2009-03-18 20:11 . 2004-03-09 00:00212,240--a------c:\windows\system32\RICHTX32.OCX 2009-03-18 20:11 . 2004-12-06 11:22178,889--a------c:\windows\system32\FraPlus1.ocx 2009-03-18 20:11 . 1999-08-11 13:21129,024--a------c:\windows\system32\vdgt.ocx 2009-03-18 20:11 . 2001-12-07 11:4176,496--a------c:\windows\system32\mftp32.ocx 2009-03-18 20:11 . 1998-01-25 12:5465,536--a------c:\windows\system32\sblist.ocx 2009-03-18 20:07 . 2009-03-18 20:12d--------c:\program files\Creative Element Power Tools 2009-03-18 18:43 . 2009-03-18 18:43d--------c:\documents and settings\Administrator 2009-03-18 17:34 . 2009-03-27 07:06d--------c:\documents and settings\All Users\Application Data\Lavasoft 2009-03-16 11:16 . 2009-03-21 11:1979,515,096--a------C:\SYM_REGISTRY_BACKUP.old 2009-02-28 09:34 . 2009-02-28 09:34d--------c:\program files\Common Files\Skype . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-27 18:240----a-wc:\windows\system32\drivers\lvuvc.hs 2009-03-27 18:09---------d-----wc:\program files\BitComet 2009-03-27 06:16---------d-----wc:\program files\Common Files\Symantec Shared 2009-03-24 18:27---------d-----wc:\documents and settings\Peter\Application Data\Skype 2009-03-24 17:13---------d-----wc:\documents and settings\Peter\Application Data\skypePM 2009-03-21 07:08---------d-----wc:\program files\Norton Ghost 2009-03-16 10:19---------d-----wc:\program files\Norton Internet Security 2009-03-16 06:30---------d-----wc:\documents and settings\All Users\Application Data\Symantec 2009-03-14 08:05---------d-----wc:\program files\Common Files\Adobe 2009-02-28 09:34---------d-----wc:\documents and settings\All Users\Application Data\Skype 2009-02-28 09:34---------d-----rc:\program files\Skype 2009-02-15 10:29---------d-----wc:\program files\Steinberg 2009-02-14 08:14---------d-----wc:\program files\Uniblue 2009-02-14 08:14---------d-----wc:\program files\SpeedupmyPC 2009-02-14 08:14---------d-----wc:\documents and settings\Peter\Application Data\uniblue 2009-02-14 08:11---------d-----wc:\documents and settings\All Users\Application Data\WinZip 2009-02-13 19:56---------d-----wc:\program files\Reference Assemblies 2009-02-13 19:56---------d-----wc:\program files\MSBuild 2009-02-08 10:37---------d-----wc:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-05 12:35---------d-----wc:\documents and settings\Peter\Application Data\vlc 2009-02-05 12:28---------d-----wc:\program files\VideoLAN 2009-02-01 08:47---------d-----wc:\program files\DU Meter 2009-02-01 08:35---------d-----wc:\documents and settings\All Users\Application Data\Hagel Technologies . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "TClockEx"="c:\program files\TClockEx\TCLOCKEX.EXE" [2000-03-09 89088] "DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2009-02-01 2645528] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-04 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-03 4800512] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-02-11 53096] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "Norton Ghost 10.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2007-04-10 1537640] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-21 148888] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-05-11 441120] c:\documents and settings\Peter\Start Menu\Programs\Startup\ Creative Element Power Tools Startup.lnk - c:\program files\Creative Element Power Tools\Startup.exe [2009-03-18 257192] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Nike+ Utility.lnk - c:\program files\Nike+ Utility\Nike+ Utility.exe [2008-04-30 1228800] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"= DrvTrNTm.dll "wave"= DrvTrNTm.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk backup=c:\windows\pss\Windows Search.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2009-02-27 17:10 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O] --a------ 2005-05-11 02:46 200069 c:\program files\Syncrosoft\POS\H2O\cledx.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2009-01-06 13:06 290088 c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5200 series] --a------ 2004-06-04 09:58 57344 c:\program files\Lexmark 5200 Series\lxbtbmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 10.0] --a------ 2007-04-10 12:01 1537640 c:\program files\Norton Ghost\Agent\GhostTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE] --a------ 2007-08-07 00:05 200704 c:\program files\PowerISO\PWRISOVM.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2009-01-05 16:18 413696 c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] --a------ 2009-01-04 13:09 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TotalRecorderScheduler] --a------ 2003-05-08 23:27 81920 c:\program files\HighCriteria\TotalRecorder\TotRecSched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC] --a------ 2007-10-22 10:13 9438488 c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "14709:TCP"= 14709:TCP:BitComet 14709 TCP "14709:UDP"= 14709:UDP:BitComet 14709 UDP R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-03-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-03-23 72944] R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2009-02-01 1386008] R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2009-01-25 33792] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936] S3 MA763010;M-Audio Fast Track;c:\windows\system32\drivers\MA763010.sys [2009-01-24 30848] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408] --- Other Services/Drivers In Memory --- *NewlyCreated* - COMHOST . Contents of the 'Scheduled Tasks' folder 2009-03-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [] 2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] 2009-03-21 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Peter.job - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2007-05-23 12:13] 2009-03-16 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-10-22 10:13] 2009-02-14 c:\windows\Tasks\Uniblue SpeedUpMyPC.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-10-22 10:13] . - - - - ORPHANS REMOVED - - - - MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.hotmail.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-27 18:26:12 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DUMeterSvc] "ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C8618CE4-B0B4-4D1D-8336-866A8B88B639}] @Denied: (A 2 3) (Everyone) [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C8618CE4-B0B4-4D1D-8336-866A8B88B639}\InProcServer32] @="%SystemRoot%\\Explorer.exe" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C8618CE4-B0B4-4D1D-8336-866A8B88B639}\ProgID] @="DAO.Client" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C8618CE4-B0B4-4D1D-8336-866A8B88B639}\TypeLib] @="{C8618CE4-0468-2079-8336-66696B6B6E75}" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(752) c:\program files\SUPERAntiSpyware\SASWINLO.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE c:\program files\Common Files\Symantec Shared\CCPROXY.EXE c:\program files\Common Files\Symantec Shared\SNDSrvc.exe c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\M-Audio Fast Track\GBInst.exe c:\windows\system32\gearsec.exe c:\program files\Norton Ghost\Agent\VProSvc.exe c:\windows\system32\nvsvc32.exe c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE . ************************************************************************** . Completion time: 2009-03-27 18:29:57 - machine was rebooted ComboFix-quarantined-files.txt 2009-03-27 18:29:54 Pre-Run: 41,062,494,208 bytes free Post-Run: 41,076,527,104 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 292--- E O F ---2009-03-11 07:42:39 -------------------\\ Cracks & Keygens .. I'm not going to insist you remove this but do be aware that probable over 75% of cracks contain some form of malware and is likely the source of your problems. The people who host these are CROOKS. How can you trust them? Unistall LOP S&D Click START then RUN Now type C:\Lop SD\Uninstal.exe in the runbox. Then click OK. ---------- 
 
 ---------- Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator. 
 There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As 
 Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. Hi evilfantasy, yes I'll happily remove that crack file! And here is the Kaspersky log: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Saturday, March 28, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, March 28, 2009 08:21:47 Records in database: 1980471 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ E:\ Scan statistics: Files scanned: 54191 Threat name: 1 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:24:33 File name / Threat name / Threats count C:\Documents and Settings\Peter\Local Settings\Application Data\Identities\{2294E92E-64C5-4AF2-BF01-297EE7005EFE}\Microsoft\Outlook Express\Deleted Items.bakInfected: Trojan-Spy.HTML.Paylap.fa1 C:\Documents and Settings\Peter\Local Settings\Application Data\Identities\{2294E92E-64C5-4AF2-BF01-297EE7005EFE}\Microsoft\Outlook Express\Deleted Items.dbxInfected: Trojan-Spy.HTML.Paylap.fa1 The selected area was scanned. Empty the Outlook Express deleted items folder. How is the computer running now? You can find free alternatives to almost any software made. This list has some very good picks for all types of software and everything listed in it is 100% free for home use.Done - and in answer to your question, it runs like a brand new car, but without that new car smell. You sir are a prince among men! (Or if female, the princess thing). Many many thanks!Quote from: Arbeloa on March 28, 2009, 10:06:10 AM it runs like a brand new car, but without that new car smell. Click here OK time to finish up. Use the Secunia Software Inspector to check for out of date software. 
 ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.All this and a fine smelling computer too - thanks again! | |