|
|
|
Red X on C Drive - Adware/Trojan
|
Original Message
|
Name: canon5d
Date: January 28, 2008 at 11:13:21 Pacific
Subject: Red X on C Drive - Adware/TrojanOS: WIN XP 2002 SP 2CPU/Ram: 2.2 GHz/ 1 GBModel/Manufacturer: Sony Vaio |
Comment: I have been infected by a virus / trojan, and have gotten a number of unwanted popup ad when i launch ie. i also have the red 'x' next to my c drive. i ran the vundofix, it appeared to have removed some files. i ran windows defender it still finds the win32/fotomot virus/trojan. i ran trendmicro's house call and it found the troj_vundo.aah and pe_trats_a trojan/virus. this all started when i downloaded software from limewire that i thought was going to help me crack a password on a word doc that i had forgotten the password to. please advise.
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: Beginner1
Date: January 28, 2008 at 12:31:33 Pacific
|
Reply: (edit)You might want to dowload and install AVG if you dont have a virus program installed. Afterward's start windows in safe mode, by constantly pressing F8 when you restart your computer. Once in safe mode, do a full system scan with avg and see if it can quaranteen those viruses. Jim R
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: jabuck
Date: January 28, 2008 at 14:25:31 Pacific
|
Reply: (edit)Run Vundofix twice. Go to the this link: Disable Realtime Protection Follow their directions to disable any realtime protection that you have as it will interfere with the fix by reinstalling the corrupt files. Please download and install the latest version of HijackThis v2.0.2: Download the "HijackThis" Installer from this link: Hijack This 1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Please download ComboFix to the desktop from one of the following links: Link1 Link 2 Link 3 Double-click combofix.exe Follow the prompts. (Don't click on the window while the program is running, it may cause your system to hang.) Please post the log it produces.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: canon5d
Date: January 28, 2008 at 16:04:58 Pacific
|
Reply: (edit)Hello, Here are the logs. Thanks for all your help. I really appreciate it. -Paul Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:03:56 PM, on 1/29/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINXP\System32\smss.exe C:\WINXP\system32\winlogon.exe C:\WINXP\system32\services.exe C:\WINXP\system32\lsass.exe C:\WINXP\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINXP\System32\svchost.exe C:\WINXP\system32\svchost.exe C:\WINXP\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe C:\Documents and Settings\All Users.WINXP\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINXP\System32\nvsvc32.exe C:\WINXP\System32\svchost.exe C:\Program Files\Linksys\WUSB300N\WLService.exe C:\Program Files\Linksys\WUSB300N\WUSB300N.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINXP\system32\WDBtnMgr.exe C:\WINXP\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe C:\Program Files\Sony\Giga Pocket\usbsircs.exe C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Sony\Giga Pocket\ReserveModule.exe C:\Program Files\Sony\Giga Pocket\gps.exe C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe C:\WINXP\system32\hpoipm07.exe C:\WINXP\explorer.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe C:\WINXP\System32\svchost.exe C:\WINXP\system32\notepad.exe E:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Gneco\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin... R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin... O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINXP\system32\BhoCitUS.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: {9f96e779-3c0d-7afb-6e34-f6dc42c7c0d7} - {7d0c7c24-cd6f-43e6-bfa7-d0c3977e69f9} - C:\WINXP\system32\drodfrrf.dll (file missing) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINXP\System32\hphmon04.exe O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [f043a0bf] rundll32.exe "C:\WINXP\system32\ewmkdxis.dll",b O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler O4 - HKCU\..\Run: [EPSON Stylus Photo R260 Series] C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBNA.EXE /FU "C:\WINXP\TEMP\E_S1BD.tmp" /EF "HKCU" O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Giga Pocket Initialize.lnk = C:\Program Files\Sony\Giga Pocket\initovl.exe O4 - Global Startup: Giga Pocket Remocon Driver.lnk = C:\Program Files\Sony\Giga Pocket\usbsircs.exe O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\Giga Pocket\ReserveModule.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\winxp\system32\nwprovau.dll O16 - DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} (Cacher Class) - http://www.priv.njmls.xmlsweb.com/X... O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/Walgreen... O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://org.mlxchange.com/Control/Mu... O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.nationalgeomatica.com/mg... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso... O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://org.mlxchange.com/Control/ML... O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/inst... O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/I... O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://org.mlxchange.com/Control/IR... O16 - DPF: {9E214F45-89C2-4DE3-94A9-530EB1D05F7E} - http://www.quest3d.com/Quest3D_WebI... O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AutoUpdate: Cisco Apps (AutoUpdate__Cisco) - Cisco Systems, Inc. - C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users.WINXP\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXP\System32\nvsvc32.exe O23 - Service: Pml Driver HPH11 - HP - C:\WINXP\System32\HPHipm11.exe O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe O24 - Desktop Component 0: (no name) - http://www.buildabear.com/graphics/... -- End of file - 10305 bytes ComboFix 08-01-29.2 - Gneco 2008-01-28 18:36:17.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.475 [GMT -5:00] Running from: C:\Documents and Settings\Gneco\Desktop\ComboFix.exe * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINXP\system32\ssqro.dll C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\NetMon C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\NetMon\domains.txt C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\NetMon\log.txt C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\QuickTime\qttask .exe C:\Program Files\QuickTime\qttask .exe C:\Program Files\QuickTime\qttask .exe C:\Program Files\Windows Defender\MSASCui.exe C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\temp\tn3 C:\WINXP\cookies.ini C:\WINXP\system32\ctfmon.exe.tmp C:\WINXP\system32\e9 C:\WINXP\system32\e9\farstadcom2.exe C:\WINXP\system32\hptqkxxc.dllbox C:\WINXP\system32\inolvwhy.exe C:\WINXP\system32\jkkjhif.dll C:\WINXP\system32\mcrh.tmp C:\WINXP\system32\oevqitjt.ini C:\WINXP\system32\orqss.ini C:\WINXP\system32\orqss.ini2 C:\WINXP\system32\p2 C:\WINXP\system32\pac.txt C:\WINXP\system32\qilucocl.ini C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBNA.EXE C:\WINXP\system32\ssqro.dll C:\WINXP\system32\ssqro.exe C:\WINXP\system32\t8 C:\WINXP\system32\tjtiqveo.dll C:\WINXP\Fonts\' . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_DOMAINSERVICE -------\LEGACY_NETWORK_MONITOR -------\DomainService ((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 ))))))))))))))))))))))))))))))) .
2008-01-28 02:26 . 2008-01-28 12:29 <DIR> d-------- C:\Documents and Settings\Gneco\.housecall6.6 2008-01-28 02:10 . 2008-01-28 02:10 <DIR> d-------- C:\WINXP\LastGood.Tmp 2008-01-28 00:00 . 2008-01-28 11:10 <DIR> d-------- C:\VundoFix Backups 2008-01-25 22:57 . 2008-01-27 11:28 <DIR> d-------- C:\WINXP\system32\SysDriversBak 2008-01-17 16:28 . 2008-01-29 18:39 <DIR> d-------- C:\Program Files\Windows Defender 2008-01-17 16:24 . 2008-01-28 12:35 15,360 --a------ C:\WINXP\system32\ctfmon .exe 2008-01-17 15:43 . 2008-01-26 00:02 <DIR> d-a------ C:\Documents and Settings\All Users.WINXP\Application Data\TEMP 2008-01-17 13:05 . 2008-01-27 22:43 348,160 --a------ C:\WINXP\system32\hphmon04 .exe 2008-01-17 13:05 . 2008-01-17 16:24 153,088 --a------ C:\WINXP\system32\VOBREGCheck .exe 2008-01-17 00:41 . 2008-01-17 00:41 147,456 --a------ C:\WINXP\system32\vbzip10.dll 2008-01-17 00:34 . 2008-01-24 07:11 <DIR> d--hs---- C:\WINXP\VmlkZW8 2008-01-17 00:34 . 2008-01-17 00:34 <DIR> d-------- C:\WINXP\system32\edcA18 2008-01-17 00:34 . 2008-01-17 00:34 <DIR> d-------- C:\temp\Ryuan1 2008-01-11 23:44 . 2008-01-12 12:59 54,156 --ah----- C:\WINXP\QTFont.qfn 2008-01-11 23:44 . 2008-01-11 23:44 1,409 --a------ C:\WINXP\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-29 23:39 --------- d-----w C:\Program Files\QuickTime 2008-01-29 23:39 --------- d-----w C:\Program Files\MSN Messenger 2008-01-29 23:39 --------- d-----w C:\Program Files\Citi Virtual Account Numbers 2008-01-28 18:47 --------- d-----w C:\Program Files\Quicken 2008-01-28 05:42 --------- d-----w C:\Program Files\Java 2008-01-26 05:01 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-01-26 04:58 --------- d-----w C:\Program Files\ItsDeductibleEX 2008-01-17 17:02 --------- d-----w C:\Program Files\Real 2008-01-17 17:02 --------- d-----w C:\Program Files\QUICKENW 2008-01-12 17:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-01-11 23:14 --------- d-----w C:\Program Files\Symantec 2008-01-11 23:06 --------- d-----w C:\Documents and Settings\All Users.WINXP\Application Data\Symantec 2007-12-19 22:52 --------- d-----w C:\Documents and Settings\Gneco\Application Data\Snapfish 2007-12-05 00:02 --------- d-----w C:\Program Files\InterActual . [code] ----a-w 192,512 2008-01-28 17:35:21 C:\Program Files\Citi Virtual Account Numbers\CitiVAN .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:30 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 39,264 2008-01-28 17:35:33 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe ----a-w 69,632 2008-01-28 17:35:18 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe ----a-w 132,496 2008-01-28 17:35:24 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 1,289,000 2008-01-17 21:24:23 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 1,289,000 2008-01-28 16:10:36 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 5,674,352 2008-01-28 17:35:37 C:\Program Files\MSN Messenger\msnmsgr .exe ----a-w 155,648 2008-01-28 16:10:37 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:38 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 866,584 2008-01-28 17:35:28 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 15,360 2008-01-28 17:35:29 C:\WINXP\system32\ctfmon .exe ----a-w 348,160 2008-01-28 03:43:42 C:\WINXP\system32\hphmon04 .exe ----a-w 153,088 2008-01-17 21:24:02 C:\WINXP\system32\VOBREGCheck .exe ----a-w 139,264 2008-01-28 17:35:27 C:\WINXP\system32\spool\drivers\w32x86\3\E_FATIBNA .EXE ----a-w 188,416 2008-01-28 03:43:41 C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb07 .exe
[/code] -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0c7c24-cd6f-43e6-bfa7-d0c3977e69f9}] C:\WINXP\system32\drodfrrf.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ] "ctfmon.exe"="C:\WINXP\system32\ctfmon.exe" [2004-08-04 02:56 15360] "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ] "EPSON Stylus Photo R260 Series"="C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBNA.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPDJ Taskbar Utility"="C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb07.exe" [ ] "Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [ ] "HPHmon04"="C:\WINXP\System32\hphmon04.exe" [ ] "PtiuPbmd"="ptipbm.dll" [2003-05-20 16:56 24576 C:\WINXP\system32\ptipbm.dll] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "CitiVAN"="C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe" [ ] "WD Button Manager"="WDBtnMgr.exe" [2007-06-03 13:01 364544 C:\WINXP\system32\WDBtnMgr.exe] "UserFaultCheck"="C:\WINXP\system32\dumprep 0 -u" [ ] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ] "f043a0bf"="C:\WINXP\system32\ewmkdxis.dll" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [ ] C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2005-12-30 00:01:21 43520] Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-08-08 00:28:49 113664] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Giga Pocket Initialize.lnk - C:\Program Files\Sony\Giga Pocket\initovl.exe [2004-08-07 03:42:45 20480] Giga Pocket Remocon Driver.lnk - C:\Program Files\Sony\Giga Pocket\usbsircs.exe [2004-08-07 03:03:06 94208] HPAiODevice(hp officejet 7100 series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 19:55:48 495682] InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2006-04-02 23:15:37 114688] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588] Timer Recording Manager.lnk - C:\Program Files\Sony\Giga Pocket\ReserveModule.exe [2004-08-07 03:42:45 245760] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 C:\WINXP\system32\ssqro [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04] C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2006-02-08 17:03 278528 E:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] R0 si3112;SiI-3112 SATALink Controller;C:\WINXP\system32\drivers\si3112.sys [2004-06-14 21:03] R1 SonyFanC;FAN Control Device Service;C:\WINXP\system32\Drivers\SonyFanC.sys [2001-12-03 11:53] R2 AutoUpdate__Cisco;AutoUpdate: Cisco Apps;"C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe" [2004-10-28 11:58] R2 CvlCdpPacket;Cisco VT Advantage CDP Packet Driver;C:\WINXP\system32\DRIVERS\CdpPacketWdmCvl.sys [2004-10-28 11:59] R2 V7;V7;C:\WINXP\system32\drivers\V7.sys [2000-03-09 13:24] R3 SMBE;Sony MPEG2 Encoder Board (WDM);C:\WINXP\system32\Drivers\SMBE.SYS [2001-09-21 11:16] S1 ac97intcc;ac97intcc;C:\WINXP\system32\drivers\ac97intcc.sys [] S3 CiscoCam8116;Cisco VT Camera(1);C:\WINXP\system32\DRIVERS\CamDrC21.sys [2004-10-27 17:12] S3 Cpmt;Cisco Media Termination;C:\WINXP\system32\Drivers\Cpmt.sys [2004-10-28 11:51] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINXP\system32\DRIVERS\wdcsam.sys [2006-09-07 16:16]
. Contents of the 'Scheduled Tasks' folder "2008-01-29 23:44:54 C:\WINXP\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-29 18:42:34 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-29 18:45:31 ComboFix-quarantined-files.txt 2008-01-29 23:45:29 . 2008-01-25 10:51:01 --- E O F ---
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: jabuck
Date: January 28, 2008 at 19:29:44 Pacific
|
Reply: (edit)Open Notepad and copy/paste everything between the X"s into it and make sure "File::" is at the very top of the page. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX RenV:: ----a-w 192,512 2008-01-28 17:35:21 C:\Program Files\Citi Virtual Account Numbers\CitiVAN .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:30 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 39,264 2008-01-28 17:35:33 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe ----a-w 69,632 2008-01-28 17:35:18 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe ----a-w 132,496 2008-01-28 17:35:24 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 1,289,000 2008-01-17 21:24:23 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 1,289,000 2008-01-28 16:10:36 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 5,674,352 2008-01-28 17:35:37 C:\Program Files\MSN Messenger\msnmsgr .exe ----a-w 155,648 2008-01-28 16:10:37 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:38 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 866,584 2008-01-28 17:35:28 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 15,360 2008-01-28 17:35:29 C:\WINXP\system32\ctfmon .exe ----a-w 348,160 2008-01-28 03:43:42 C:\WINXP\system32\hphmon04 .exe ----a-w 153,088 2008-01-17 21:24:02 C:\WINXP\system32\VOBREGCheck .exe ----a-w 139,264 2008-01-28 17:35:27 C:\WINXP\system32\spool\drivers\w32x86\3\E_FATIBNA .EXE ----a-w 188,416 2008-01-28 03:43:41 C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb07 .exe File:: C:\WINXP\system32\ewmkdxis.dll C:\WINXP\system32\drodfrrf.dll Driver:: Folder:: C:\WINXP\VmlkZW8 C:\WINXP\system32\edcA18 C:\temp\Ryuan1 Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0c7c24-cd6f-43e6-bfa7-d0c3977e69f9}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "f043a0bf"=- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it CFScript.txt then save it to your desktop. Then drag/drop the CFScript.txt onto ComboFix.exe (the red X on your desktop) if combofix does not auto start click "run". Post a new Combofix log and a new Hijack This log please. Please go to Virus Total and upload the following file for analysis: C:\WINXP\system32\vbzip10.dll Post the results in your reply.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: canon5d
Date: January 28, 2008 at 19:50:01 Pacific
|
Reply: (edit) File vbzip10.dll received on 03.29.2007 13:49:41 (CET) Current status: finished Result: 2/32 (6.25%) Compact Compact Print results Print results Antivirus Version Last Update Result AhnLab-V3 - - - AntiVir - - - Authentium - - - Avast - - - AVG - - - BitDefender - - - CAT-QuickHeal - - - ClamAV - - - DrWeb - - - eSafe - - - eTrust-Vet - - - Ewido - - - FileAdvisor - - No threat detected Fortinet - - - F-Prot - - - F-Secure - - - Ikarus - - - Kaspersky - - - McAfee - - - Microsoft - - - NOD32v2 - - - Norman - - - Panda - - - Prevx1 - - - Sophos - - - Sunbelt - - - Symantec - - - TheHacker - - - UNA - - Backdoor.IRCBot.E96F VBA32 - - - VirusBuster - - - Webwasher-Gateway - - - Additional information MD5: 5b25690cc2e55a6d4bc965068a7ba1ef http://www.virustotal.com/analisis/...
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: jabuck
Date: January 28, 2008 at 19:54:37 Pacific
|
Reply: (edit)Open Notepad and copy/paste everything between the X"s into it and make sure "File::" is at the very top of the page. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX File:: C:\WINXP\system32\vbzip10.dll XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it CFScript.txt then save it to your desktop. Then drag/drop the CFScript.txt onto ComboFix.exe (the red X on your desktop) if combofix does not auto start click "run". Post a new Combofix log.
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: canon5d
Date: January 28, 2008 at 21:14:17 Pacific
|
Reply: (edit)ComboFix 08-01-29.2 - Gneco 2008-01-28 23:58:02.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.578 [GMT -5:00] Running from: C:\Documents and Settings\Gneco\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gneco\Desktop\CFScript.txt * Created a new restore point [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] FILE C:\WINXP\system32\vbzip10.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINXP\system32\vbzip10.dll . ((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 ))))))))))))))))))))))))))))))) . 2008-01-28 02:26 . 2008-01-28 12:29 <DIR> d-------- C:\Documents and Settings\Gneco\.housecall6.6 2008-01-28 00:00 . 2008-01-28 11:10 <DIR> d-------- C:\VundoFix Backups 2008-01-25 22:57 . 2008-01-27 11:28 <DIR> d-------- C:\WINXP\system32\SysDriversBak 2008-01-17 16:28 . 2008-01-29 18:39 <DIR> d-------- C:\Program Files\Windows Defender 2008-01-17 16:24 . 2008-01-28 12:35 15,360 --a------ C:\WINXP\system32\ctfmon .exe 2008-01-17 15:43 . 2008-01-26 00:02 <DIR> d-a------ C:\Documents and Settings\All Users.WINXP\Application Data\TEMP 2008-01-17 13:05 . 2008-01-27 22:43 348,160 --a------ C:\WINXP\system32\hphmon04 .exe 2008-01-17 13:05 . 2008-01-17 16:24 153,088 --a------ C:\WINXP\system32\VOBREGCheck .exe 2008-01-17 00:34 . 2008-01-24 07:11 <DIR> d--hs---- C:\WINXP\VmlkZW8 2008-01-17 00:34 . 2008-01-17 00:34 <DIR> d-------- C:\WINXP\system32\edcA18 2008-01-17 00:34 . 2008-01-17 00:34 <DIR> d-------- C:\temp\Ryuan1 2008-01-11 23:44 . 2008-01-12 12:59 54,156 --ah----- C:\WINXP\QTFont.qfn 2008-01-11 23:44 . 2008-01-11 23:44 1,409 --a------ C:\WINXP\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-29 23:39 --------- d-----w C:\Program Files\QuickTime 2008-01-29 23:39 --------- d-----w C:\Program Files\MSN Messenger 2008-01-29 23:39 --------- d-----w C:\Program Files\Citi Virtual Account Numbers 2008-01-28 18:47 --------- d-----w C:\Program Files\Quicken 2008-01-28 05:42 --------- d-----w C:\Program Files\Java 2008-01-26 05:01 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-01-26 04:58 --------- d-----w C:\Program Files\ItsDeductibleEX 2008-01-17 17:02 --------- d-----w C:\Program Files\Real 2008-01-17 17:02 --------- d-----w C:\Program Files\QUICKENW 2008-01-12 17:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-01-11 23:14 --------- d-----w C:\Program Files\Symantec 2008-01-11 23:06 --------- d-----w C:\Documents and Settings\All Users.WINXP\Application Data\Symantec 2007-12-19 22:52 --------- d-----w C:\Documents and Settings\Gneco\Application Data\Snapfish 2007-12-05 00:02 --------- d-----w C:\Program Files\InterActual . [code] ----a-w 192,512 2008-01-28 17:35:21 C:\Program Files\Citi Virtual Account Numbers\CitiVAN .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:30 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 39,264 2008-01-28 17:35:33 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe ----a-w 69,632 2008-01-28 17:35:18 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe ----a-w 132,496 2008-01-28 17:35:24 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 1,289,000 2008-01-17 21:24:23 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 1,289,000 2008-01-28 16:10:36 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 5,674,352 2008-01-28 17:35:37 C:\Program Files\MSN Messenger\msnmsgr .exe ----a-w 155,648 2008-01-28 16:10:37 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:38 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 866,584 2008-01-28 17:35:28 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 15,360 2008-01-28 17:35:29 C:\WINXP\system32\ctfmon .exe ----a-w 348,160 2008-01-28 03:43:42 C:\WINXP\system32\hphmon04 .exe ----a-w 153,088 2008-01-17 21:24:02 C:\WINXP\system32\VOBREGCheck .exe ----a-w 139,264 2008-01-28 17:35:27 C:\WINXP\system32\spool\drivers\w32x86\3\E_FATIBNA .EXE ----a-w 188,416 2008-01-28 03:43:41 C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb07 .exe
[/code] -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0c7c24-cd6f-43e6-bfa7-d0c3977e69f9}] C:\WINXP\system32\drodfrrf.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ] "ctfmon.exe"="C:\WINXP\system32\ctfmon.exe" [2004-08-04 02:56 15360] "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ] "EPSON Stylus Photo R260 Series"="C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBNA.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPDJ Taskbar Utility"="C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb07.exe" [ ] "Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [ ] "HPHmon04"="C:\WINXP\System32\hphmon04.exe" [ ] "PtiuPbmd"="ptipbm.dll" [2003-05-20 16:56 24576 C:\WINXP\system32\ptipbm.dll] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "CitiVAN"="C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe" [ ] "WD Button Manager"="WDBtnMgr.exe" [2007-06-03 13:01 364544 C:\WINXP\system32\WDBtnMgr.exe] "UserFaultCheck"="C:\WINXP\system32\dumprep 0 -u" [ ] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ] "f043a0bf"="C:\WINXP\system32\ewmkdxis.dll" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [ ] C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2005-12-30 00:01:21 43520] Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-08-08 00:28:49 113664] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Giga Pocket Initialize.lnk - C:\Program Files\Sony\Giga Pocket\initovl.exe [2004-08-07 03:42:45 20480] Giga Pocket Remocon Driver.lnk - C:\Program Files\Sony\Giga Pocket\usbsircs.exe [2004-08-07 03:03:06 94208] HPAiODevice(hp officejet 7100 series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 19:55:48 495682] InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2006-04-02 23:15:37 114688] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588] Timer Recording Manager.lnk - C:\Program Files\Sony\Giga Pocket\ReserveModule.exe [2004-08-07 03:42:45 245760] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 C:\WINXP\system32\ssqro [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04] C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2006-02-08 17:03 278528 E:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] R0 si3112;SiI-3112 SATALink Controller;C:\WINXP\system32\drivers\si3112.sys [2004-06-14 21:03] R1 SonyFanC;FAN Control Device Service;C:\WINXP\system32\Drivers\SonyFanC.sys [2001-12-03 11:53] R2 AutoUpdate__Cisco;AutoUpdate: Cisco Apps;"C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe" [2004-10-28 11:58] R2 CvlCdpPacket;Cisco VT Advantage CDP Packet Driver;C:\WINXP\system32\DRIVERS\CdpPacketWdmCvl.sys [2004-10-28 11:59] R2 V7;V7;C:\WINXP\system32\drivers\V7.sys [2000-03-09 13:24] R3 SMBE;Sony MPEG2 Encoder Board (WDM);C:\WINXP\system32\Drivers\SMBE.SYS [2001-09-21 11:16] S1 ac97intcc;ac97intcc;C:\WINXP\system32\drivers\ac97intcc.sys [] S3 CiscoCam8116;Cisco VT Camera(1);C:\WINXP\system32\DRIVERS\CamDrC21.sys [2004-10-27 17:12] S3 Cpmt;Cisco Media Termination;C:\WINXP\system32\Drivers\Cpmt.sys [2004-10-28 11:51] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINXP\system32\DRIVERS\wdcsam.sys [2006-09-07 16:16]
. Contents of the 'Scheduled Tasks' folder "2008-01-29 05:06:00 C:\WINXP\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-29 00:03:34 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . r Running Proce . C:\Program Files\Windows Defender\MsMpEng.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe C:\Documents and Settings\All Users.WINXP\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINXP\System32\nvsvc32.exe C:\Program Files\Linksys\WUSB300N\WLService.exe C:\Program Files\Linksys\WUSB300N\WUSB300N.exe C:\WINXP\system32\WDBtnMgr.exe C:\WINXP\system32\rundll32.exe C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Sony\Giga Pocket\usbsircs.exe C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Sony\Giga Pocket\ReserveModule.exe C:\Program Files\Sony\Giga Pocket\gps.exe C:\WINXP\System32\rundll32.exe C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe C:\WINXP\system32\hpoipm07.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe . ************************************************************************** . Completion time: 2008-01-29 0:06:34 - machine was rebooted ComboFix-quarantined-files.txt 2008-01-29 05:06:31 ComboFix2.txt 2008-01-29 23:45:32 . 2008-01-25 10:51:01 --- E O F ---
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: jabuck
Date: January 29, 2008 at 03:40:52 Pacific
|
Reply: (edit)Open Notepad and copy/paste everything between the X"s into it and make sure "File::" is at the very top of the page. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX RenV::----a-w 192,512 2008-01-28 17:35:21 C:\Program Files\Citi Virtual Account Numbers\CitiVAN .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:30 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 39,264 2008-01-28 17:35:33 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe ----a-w 69,632 2008-01-28 17:35:18 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe ----a-w 132,496 2008-01-28 17:35:24 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 1,289,000 2008-01-17 21:24:23 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 1,289,000 2008-01-28 16:10:36 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 5,674,352 2008-01-28 17:35:37 C:\Program Files\MSN Messenger\msnmsgr .exe ----a-w 155,648 2008-01-28 16:10:37 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:38 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 866,584 2008-01-28 17:35:28 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 15,360 2008-01-28 17:35:29 C:\WINXP\system32\ctfmon .exe ----a-w 348,160 2008-01-28 03:43:42 C:\WINXP\system32\hphmon04 .exe ----a-w 153,088 2008-01-17 21:24:02 C:\WINXP\system32\VOBREGCheck .exe ----a-w 139,264 2008-01-28 17:35:27 C:\WINXP\system32\spool\drivers\w32x86\3\E_FATIBNA .EXE ----a-w 188,416 2008-01-28 03:43:41 C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb07 .exe File:: C:\WINXP\system32\drodfrrf.dll C:\WINXP\system32\ewmkdxis.dll Driver:: f043a0bf ewmkdxis Folder:: C:\WINXP\VmlkZW8 C:\WINXP\system32\edcA18 C:\temp\Ryuan1 C:\WINXP\system32\ssqro Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0c7c24-cd6f-43e6-bfa7-d0c3977e69f9}] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "f043a0bf"=- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it CFScript.txt then save it to your desktop. Then drag/drop the CFScript.txt onto ComboFix.exe (the red X on your desktop) if combofix does not auto start click "run". Post a new Combofix log.
Report Offensive Follow Up For Removal
|
|
Response Number 9
|
Name: canon5d
Date: February 2, 2008 at 14:30:22 Pacific
|
Reply: (edit)Sorry for the delayed response...I have been on a business trip away from the (infected) desktop computer. I just returned today. Here is the Combofix log that you requested: ComboFix 08-01-29.2 - Gneco 2008-02-02 17:17:46.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.596 [GMT -5:00] Running from: C:\Documents and Settings\Gneco\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gneco\Desktop\CFScript.txt * Created a new restore point [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] FILE C:\WINXP\system32\drodfrrf.dll C:\WINXP\system32\ewmkdxis.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\temp\Ryuan1 C:\temp\Ryuan1\tepU.log C:\WINXP\system32\edcA18 C:\WINXP\system32\edcA18\edcA182328.exe C:\WINXP\VmlkZW8 . ((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 ))))))))))))))))))))))))))))))) . 2008-01-28 02:26 . 2008-01-28 12:29 <DIR> d-------- C:\Documents and Settings\Gneco\.housecall6.6 2008-01-28 00:00 . 2008-01-28 11:10 <DIR> d-------- C:\VundoFix Backups 2008-01-25 22:57 . 2008-01-27 11:28 <DIR> d-------- C:\WINXP\system32\SysDriversBak 2008-01-17 16:28 . 2008-01-29 18:39 <DIR> d-------- C:\Program Files\Windows Defender 2008-01-17 16:24 . 2008-01-28 12:35 15,360 --a------ C:\WINXP\system32\ctfmon .exe 2008-01-17 15:43 . 2008-01-26 00:02 <DIR> d-a------ C:\Documents and Settings\All Users.WINXP\Application Data\TEMP 2008-01-17 13:05 . 2008-01-27 22:43 348,160 --a------ C:\WINXP\system32\hphmon04 .exe 2008-01-17 13:05 . 2008-01-17 16:24 153,088 --a------ C:\WINXP\system32\VOBREGCheck .exe 2008-01-11 23:44 . 2008-01-12 12:59 54,156 --ah----- C:\WINXP\QTFont.qfn 2008-01-11 23:44 . 2008-01-11 23:44 1,409 --a------ C:\WINXP\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-29 23:39 --------- d-----w C:\Program Files\QuickTime 2008-01-29 23:39 --------- d-----w C:\Program Files\MSN Messenger 2008-01-29 23:39 --------- d-----w C:\Program Files\Citi Virtual Account Numbers 2008-01-28 18:47 --------- d-----w C:\Program Files\Quicken 2008-01-28 05:42 --------- d-----w C:\Program Files\Java 2008-01-26 05:01 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-01-26 04:58 --------- d-----w C:\Program Files\ItsDeductibleEX 2008-01-17 17:02 --------- d-----w C:\Program Files\Real 2008-01-17 17:02 --------- d-----w C:\Program Files\QUICKENW 2008-01-12 17:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-01-11 23:14 --------- d-----w C:\Program Files\Symantec 2008-01-11 23:06 --------- d-----w C:\Documents and Settings\All Users.WINXP\Application Data\Symantec 2007-12-19 22:52 --------- d-----w C:\Documents and Settings\Gneco\Application Data\Snapfish 2007-12-05 00:02 --------- d-----w C:\Program Files\InterActual . [code] ----a-w 192,512 2008-01-28 17:35:21 C:\Program Files\Citi Virtual Account Numbers\CitiVAN .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:28 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:29 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 218,032 2008-01-28 16:10:30 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 39,264 2008-01-28 17:35:33 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe ----a-w 69,632 2008-01-28 17:35:18 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe ----a-w 132,496 2008-01-28 17:35:24 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 1,289,000 2008-01-17 21:24:23 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 1,289,000 2008-01-28 16:10:36 C:\Program Files\Microsoft ActiveSync\wcescomm .exe ----a-w 5,674,352 2008-01-28 17:35:37 C:\Program Files\MSN Messenger\msnmsgr .exe ----a-w 155,648 2008-01-28 16:10:37 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:38 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:39 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:40 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 155,648 2008-01-28 16:10:41 C:\Program Files\QuickTime\qttask .exe ----a-w 866,584 2008-01-28 17:35:28 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 15,360 2008-01-28 17:35:29 C:\WINXP\system32\ctfmon .exe ----a-w 348,160 2008-01-28 03:43:42 C:\WINXP\system32\hphmon04 .exe ----a-w 153,088 2008-01-17 21:24:02 C:\WINXP\system32\VOBREGCheck .exe ----a-w 139,264 2008-01-28 17:35:27 C:\WINXP\system32\spool\drivers\w32x86\3\E_FATIBNA .EXE ----a-w 188,416 2008-01-28 03:43:41 C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb07 .exe
[/code] -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ] "ctfmon.exe"="C:\WINXP\system32\ctfmon.exe" [2004-08-04 02:56 15360] "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ] "EPSON Stylus Photo R260 Series"="C:\WINXP\System32\spool\DRIVERS\W32X86\3\E_FATIBNA.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPDJ Taskbar Utility"="C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb07.exe" [ ] "Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [ ] "HPHmon04"="C:\WINXP\System32\hphmon04.exe" [ ] "PtiuPbmd"="ptipbm.dll" [2003-05-20 16:56 24576 C:\WINXP\system32\ptipbm.dll] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "CitiVAN"="C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe" [ ] "WD Button Manager"="WDBtnMgr.exe" [2007-06-03 13:01 364544 C:\WINXP\system32\WDBtnMgr.exe] "UserFaultCheck"="C:\WINXP\system32\dumprep 0 -u" [ ] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [ ] C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2005-12-30 00:01:21 43520] Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-08-08 00:28:49 113664] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Giga Pocket Initialize.lnk - C:\Program Files\Sony\Giga Pocket\initovl.exe [2004-08-07 03:42:45 20480] Giga Pocket Remocon Driver.lnk - C:\Program Files\Sony\Giga Pocket\usbsircs.exe [2004-08-07 03:03:06 94208] HPAiODevice(hp officejet 7100 series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 19:55:48 495682] InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2006-04-02 23:15:37 114688] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588] Timer Recording Manager.lnk - C:\Program Files\Sony\Giga Pocket\ReserveModule.exe [2004-08-07 03:42:45 245760] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 C:\WINXP\system32\ssqro [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04] C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2006-02-08 17:03 278528 E:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] R0 si3112;SiI-3112 SATALink Controller;C:\WINXP\system32\drivers\si3112.sys [2004-06-14 21:03] R1 SonyFanC;FAN Control Device Service;C:\WINXP\system32\Drivers\SonyFanC.sys [2001-12-03 11:53] R2 AutoUpdate__Cisco;AutoUpdate: Cisco Apps;"C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe" [2004-10-28 11:58] R2 CvlCdpPacket;Cisco VT Advantage CDP Packet Driver;C:\WINXP\system32\DRIVERS\CdpPacketWdmCvl.sys [2004-10-28 11:59] R2 V7;V7;C:\WINXP\system32\drivers\V7.sys [2000-03-09 13:24] R2 WUSB300NSvc;WUSB300NSvc;"C:\Program Files\Linksys\WUSB300N\WLService.exe" "WUSB300N.exe" [] R3 SMBE;Sony MPEG2 Encoder Board (WDM);C:\WINXP\system32\Drivers\SMBE.SYS [2001-09-21 11:16] S1 ac97intcc;ac97intcc;C:\WINXP\system32\drivers\ac97intcc.sys [] S3 CiscoCam8116;Cisco VT Camera(1);C:\WINXP\system32\DRIVERS\CamDrC21.sys [2004-10-27 17:12] S3 Cpmt;Cisco Media Termination;C:\WINXP\system32\Drivers\Cpmt.sys [2004-10-28 11:51] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINXP\system32\DRIVERS\wdcsam.sys [2006-09-07 16:16]
. Contents of the 'Scheduled Tasks' folder "2008-02-02 22:27:06 C:\WINXP\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-02 17:24:42 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . r Running Proce . C:\Program Files\Windows Defender\MsMpEng.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Cisco Systems\AutoUpdate\AutoUpdate.exe C:\Documents and Settings\All Users.WINXP\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINXP\System32\nvsvc32.exe C:\Program Files\Linksys\WUSB300N\WLService.exe C:\Program Files\Linksys\WUSB300N\WUSB300N.exe C:\WINXP\system32\WDBtnMgr.exe C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Sony\Giga Pocket\usbsircs.exe C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Sony\Giga Pocket\ReserveModule.exe C:\Program Files\Sony\Giga Pocket\gps.exe C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe C:\WINXP\system32\hpoipm07.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe . ************************************************************************** . Completion time: 2008-02-02 17:27:30 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-02 22:27:27 ComboFix2.txt 2008-01-29 05:06:34 ComboFix3.txt 2008-01-29 23:45:32 . 2008-02-02 21:20:09 --- E O F ---
Report Offensive Follow Up For Removal
|
|
Response Number 10
|
Name: jabuck
Date: February 2, 2008 at 18:47:31 Pacific
|
Reply: (edit)Go to start> control panel> aadd/remove programs and uninstall Quicktime. Run an online scan with Kaspersky from the following link: Kaspersky Online Scanner Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component Click Yes, when prompted to install its ActiveX component. (Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.) The program launches and downloads the latest definition files. Once the files are downloaded click on Next Click on Scan Settings and configure as follows: Scan using the following Anti-Virus database: Extended Scan Options: Scan Archives Scan Mail Base Click OK and, under select a target to scan, select My Computer When the scan is done, in the Scan is completed window (below), any infection is displayed. There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As (above - red blinking arrow) Next, in the Save as prompt, Save in area, select: Desktop In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt] Then, click: Save Please post the Kaspersky Online Scanner Report in your reply.
Report Offensive Follow Up For Removal
|
|
Response Number 11
|
Name: canon5d
Date: February 2, 2008 at 20:21:59 Pacific
|
Reply: (edit)I was unable to uninstall Quicktime through the Control Panel nor through running the Quicktime uninstall program in the >Start>All Programs>Quick Time folder. I got this error message dialogue box while attempting to uninstall Quicktime: Unhandled Exception Error Number: 0x80040707 Description: DLL function call crashed: QTInstallCode.QuickTimeUninstallProc Setup will now terminate. Is there another way to uninstall Quicktime? Do you still want me to download/run Kaspersky without uninstalling Quicktime?
Please advise....
Report Offensive Follow Up For Removal
|
|
Response Number 12
|
Name: jabuck
Date: February 3, 2008 at 14:54:36 Pacific
|
Reply: (edit)Lets see if this will kill it. Open Notepad and copy/paste everything between the X"s into it and make sure "Folder::" is at the very top of the page. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Folder:: C:\Program Files\QuickTime XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it CFScript.txt then save it to your desktop. Then drag/drop the CFScript.txt onto ComboFix.exe (the red X on your desktop) if combofix does not auto start click "run". Post a new Combofix log.
Report Offensive Follow Up For Removal
|
|
Response Number 13
|
Name: canon5d
Date: February 3, 2008 at 20:40:18 Pacific
|
Reply: (edit)ComboFix 08-01-29.2 - Gneco 2008-02-03 19:19:25.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.602 [GMT -5:00] Running from: C:\Documents and Settings\Gneco\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gneco\Desktop\CFScript.txt * Created a new restore point [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\QuickTime C:\Program Files\QuickTime\PictureViewer.exe C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\no.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\no.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\PictureViewer.qtr C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj\PictureViewerLocalized.dll C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj\PictureViewerLocalized.qtr C:\Program Files\QuickTime\Plugins\npqtplugin.dll C:\Program Files\QuickTime\Plugins\npqtplugin2.dll C:\Program Files\QuickTime\Plugins\npqtplugin3.dll C:\Program Files\QuickTime\Plugins\npqtplugin4.dll C:\Program Files\QuickTime\Plugins\npqtplugin5.dll C:\Program Files\QuickTime\Plugins\npqtplugin6.dll C:\Program Files\QuickTime\Plugins\npqtplugin7.dll C:\Program Files\QuickTime\Plugins\nsIQTScriptablePlugin.xpt C:\Program Files\QuickTime\Plugins\QuickTimePlugin.class C:\Program Files\QuickTime\PropertyPanels\annoanno.pdef C:\Program Files\QuickTime\PropertyPanels\moovaudi.pdef C:\Program Files\QuickTime\PropertyPanels\moovpres.pdef C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.qpa C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\da.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\de.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\en.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\es.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fi.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fr.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\it.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ja.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ko.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nl.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\no.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\PanelHelperBase.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\sv.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_CN.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_TW.lproj\PanelHelperBaseLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropertyPanels.plist C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.qpa C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\da.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\de.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\en.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\es.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fi.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fr.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\it.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ja.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ko.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nl.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\no.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\PropPanelHelpers.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\sv.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_CN.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_TW.lproj\PropPanelHelpersLocalized.qtr C:\Program Files\QuickTime\PropertyPanels\rsrcrsrc.pdef C:\Program Files\QuickTime\PropertyPanels\trakaudi.pdef C:\Program Files\QuickTime\PropertyPanels\trakothr.pdef C:\Program Files\QuickTime\PropertyPanels\trakstrm.pdef C:\Program Files\QuickTime\PropertyPanels\trakvisl.pdef C:\Program Files\QuickTime\QTInfo.exe C:\Program Files\QuickTime\QTOControl.dll C:\Program Files\QuickTime\QTOLibrary.dll C:\Program Files\QuickTime\QTPlugin.ocx C:\Program Files\QuickTime\QTSystem\CFCharacterSetBitmaps.bitmap C:\Program Files\QuickTime\QTSystem\CFUniCharPropertyDatabase.data C:\Program Files\QuickTime\QTSystem\CFUnicodeData-B.mapping C:\Program Files\QuickTime\QTSystem\CFUnicodeData-L.mapping C:\Program Files\QuickTime\QTSystem\CoreVideo.qtx C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\CoreVideo.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\da.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\de.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\es.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fi.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fr.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\it.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ja.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ko.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\nl.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\no.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\sv.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj\CoreVideoLocalized.qtr C:\Program Files\QuickTime\QTSystem\Indeo4.qtx C:\Program Files\QuickTime\QTSystem\Ir41_qc.dll C:\Program Files\QuickTime\QTSystem\Ir41_qcx.dll C:\Program Files\QuickTime\QTSystem\QTJava.dll C:\Program Files\QuickTime\QTSystem\QTJava.zip C:\Program Files\QuickTime\QTSystem\QTJavaNative.dll C:\Program Files\QuickTime\QTSystem\QTMLClient.dll C:\Program Files\QuickTime\QTSystem\QTPluginInstaller.exe C:\Program Files\QuickTime\QTSystem\QuickTime.cpl C:\Program Files\QuickTime\QTSystem\QuickTime.qts C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\da.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\de.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\es.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fi.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fr.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\it.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ja.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ko.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\nl.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\no.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\QuickTime.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\sv.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_TW.lproj\QuickTimeLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.qtx C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\da.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\de.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fi.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\it.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ko.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\no.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\sv.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_TW.lproj\QuickTime3GPPLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\da.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\de.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\en.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\es.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fi.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fr.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\it.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ja.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ko.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nl.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\no.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\QuickTime3GPPAuthoring.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\sv.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_CN.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_TW.lproj\QuickTime3GPPAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.qtx C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\da.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\de.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\es.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fi.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fr.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\it.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ja.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ko.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\nl.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\no.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\sv.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_TW.lproj\QuickTimeAudioSupportLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.qtx C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\da.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\de.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\en.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\es.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fi.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fr.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\it.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ja.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ko.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\nl.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\no.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\QuickTimeAuthoring.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\sv.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_CN.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_TW.lproj\QuickTimeAuthoringLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.qtx C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\da.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\de.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\en.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\es.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\fi.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\fr.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\it.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\ja.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\ko.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\nl.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\no.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\QuickTimeCapture.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\sv.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_CN.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_TW.lproj\QuickTimeCaptureLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.qtx C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\da.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\de.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\en.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\es.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\fi.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\fr.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\it.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\ja.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\ko.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\nl.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\no.lproj\QuickTimeEffectsLocalized.qtr C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\Quick
| |