Also help with resycled\ntldr.com e

Fujitsu siemens / D1826-g
February 4, 2009 at 13:35:40
Specs: Microsoft Windows XP Home Edition, 3.401 GHz / 3070 MB
I'm new to this. So I start my own tread.
Please bare with me.
I've got Norton 360, found Greybird.backdoor the other day. Nothing is the same anymore.
After a couple of "Norton is treating treat..." I finally did not have to re-boot every 15 min.

I do not find the resycled folder. So I did the reg-scan:


Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 2009-02-04 21:54:42 for strings:
; 'resycled\ntldr.com'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d720e54-0980-11da-a70a-806d6172696f}\Shell\AutoRun\command]
@="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\\ntldr.com c:"

[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f05291be-510d-11da-913c-0007ca04cfcf}\Shell\AutoRun\command]
@="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\\ntldr.com d:"

[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f05291be-510d-11da-913c-0007ca04cfcf}\Shell\Open\command]
@="resycled\\ntldr.com d:"

; End Of The Log...

I can see the problem. It's in there.
Please help me.

Best,

/Alex



See More: Also help with resycled\ntldr.com e

Report •


#1
February 6, 2009 at 02:41:48
My computer is dying on me. Pls Help!

Best,

/Alex


Report •

#2
February 6, 2009 at 03:42:35
We need the results from these scans.

Please download Malwarebytes' Anti-Malware from one of these sites:

MalwareBytes1

MalwareBytes2

Rename the setup file, mbam-setup.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename mbam-setup.exe to tool.exe> click save.

1. Double Click tool.exe to install the application.
2. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
3. If an update is found, it will download and install the latest version.
4. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient.
5. When the scan is complete, click OK, then Show Results to view the results.
6. Make sure that everything found is checked, and click Remove Selected.
7. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
8. The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
9. Copy&Paste the entire report in your next reply.


If Malwarebytes installed but will not run navigate to this folder:

C:\Programs Files\Malwarebytes' AntiMalware

Rename all the .exe files in the MAlwarebytes' Anti-Malware folder and try to run it again.

Please download and install the latest version of HijackThis v2.0.2:


Download the "HijackThis" Installer from this link:
Hijack This

Rename the setup file, HJTInstall.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename HJTInstall.exe to tools.exe> click save.
1. Save " tools.exe" to your desktop.
2. Double click on tools.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


Report •

#3
February 7, 2009 at 04:05:32
Hi Jabuck,

Impressive help!
I installed Malware in Swedish, but I'm pretty sure you will manage. If not, just ask me and I will translate:

Malwarebytes' Anti-Malware 1.33
Databasversion: 1736
Windows 5.1.2600 Service Pack 3

2009-02-07 12:53:26
mbam-log-2009-02-07 (12-53-26).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 62837
Förfluten tid: 10 minute(s), 49 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 1
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 1
Infekterade filer: 2

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
HKEY_CLASSES_ROOT\aquaplay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Infekterade filer:
C:\WINDOWS\system32\drivers\gaopdxfeubddvr.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gaopdxserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

---------------------------


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:02:21, on 2009-02-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program\TVersity\Media Server\MediaServer.exe
C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\iid.exe
C:\Program\Ideazon\ZEngine\Zboard.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program\Canon\CAL\CALMAIN.exe
C:\Program\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alex\Mina dokument\Mina mottagna filer\tool.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsidan.telia.se
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [PCLEPCI] C:\Program\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [Net iD] C:\WINDOWS\system32\iid.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Zboard] C:\Program\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "D:\Program\Norton360\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Program\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Hamachi.lnk = C:\Program\Hamachi\hamachi.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Hamachi.lnk = C:\Program\Hamachi\hamachi.exe (User 'Default user')
O4 - Startup: Hamachi.lnk = C:\Program\Hamachi\hamachi.exe
O4 - Global Startup: SetPointII.lnk = ?
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/ac...
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInsta...
O16 - DPF: {5BF56AD2-E297-416E-BC49-000004010012} - https://cve.trust.telia.com/TeliaElegUpgrade/iidsetup.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fsc...
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.co...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/g...
O17 - HKLM\System\CCS\Services\Tcpip\..\{D33B47ED-49ED-4806-8F13-3D199C7DA4EA}: NameServer = 195.67.199.18,195.67.199.19
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program\TVersity\Media Server\MediaServer.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

--
End of file - 12888 bytes

What next?

Best regards,

/Alex


Report •

Related Solutions

#4
February 7, 2009 at 07:00:22
Please download ComboFix to the desktop from one of the following links:

Link1

Link 2

Link 3

Rename the setup file, combofix.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename combofix.exe to toolb.exe> click save.

Combofix is a powerful tool so follow the instructions exactly or you could damage your computer.

Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with Combofix and remove some of its embedded files which may cause "unpredictable results".
Click on This Link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

In your case to run Combofix do the following:
1. Go offline turn off your Norton antivirus, and any antispyware that you may have.
2. Run Combofix by double clicking the toolb.exe icon on your desktop and save its log.
3. Restart the computer to get the antivirus running again but leave the antispyware programs off until we get the computer cleaned.
4. Post the Combofix log.


Remember to re-enable the protection again afterwards before connecting to the Internet.


Report •

#5
February 7, 2009 at 08:04:57
Done.

ComboFix 09-02-06.02 - Alex 2009-02-07 16:48:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1053.18.3070.2417 [GMT 1:00]
Körs från: c:\documents and settings\Alex\Mina dokument\Mina mottagna filer\toolb.exe
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *disabled*
* Skapade en ny återställningspunkt
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\windows\system32\drivers\RKHit.sys
D:\Autorun.inf
D:\resycled

.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_RkHit


(((((((((((((((((((((((( Filer Skapade från 2009-01-07 till 2009-02-07 ))))))))))))))))))))))))))))))
.

2009-02-07 13:12 . 2009-02-07 13:12 <KAT> d-------- c:\program\Windows Installer Clean Up
2009-02-07 13:11 . 2009-02-07 13:11 <KAT> d-------- c:\program\MSECACHE
2009-02-07 12:40 . 2009-02-07 12:40 <KAT> d-------- c:\program\Malwarebytes' Anti-Malware
2009-02-07 12:40 . 2009-02-07 12:40 <KAT> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-07 12:40 . 2009-02-07 12:40 <KAT> d-------- c:\documents and settings\Alex\Application Data\Malwarebytes
2009-02-07 12:40 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-07 12:40 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-04 21:29 . 2009-02-04 21:29 <KAT> d-------- c:\program\Bonjour
2009-02-04 20:56 . 2009-02-04 20:56 <KAT> d-------- C:\fsaua.data
2009-01-29 22:59 . 2009-01-29 22:59 0 --a------ c:\windows\ativpsrm.bin
2009-01-27 19:52 . 2009-01-27 19:52 <KAT> d-------- c:\program\VS Revo Group
2009-01-27 00:03 . 2009-01-27 00:03 <KAT> d-------- c:\program\CCleaner
2009-01-26 23:10 . 2009-01-26 23:10 42 --a------ c:\windows\system32\AK083E209605E394C.lie
2009-01-26 19:35 . 2009-01-26 19:35 <KAT> d-------- c:\program\Spotify
2009-01-26 19:35 . 2009-02-07 16:30 <KAT> d-------- c:\documents and settings\Alex\Application Data\Spotify
2009-01-15 22:40 . 2009-01-15 22:40 <KAT> d-------- c:\documents and settings\Alex\Application Data\Canon
2009-01-14 05:05 . 2009-01-14 05:05 79,008 --a------ c:\windows\system32\ativvaxx.cap
2009-01-14 04:50 . 2009-01-14 04:50 48,640 --a------ c:\windows\system32\amdpcom32.dll
2009-01-14 04:44 . 2009-01-14 04:44 110,592 --a------ c:\windows\system32\atiadlxx.dll
2009-01-14 03:36 . 2009-01-14 03:36 45,056 --a------ c:\windows\system32\amdcalrt.dll
2009-01-14 03:36 . 2009-01-14 03:36 45,056 --a------ c:\windows\system32\amdcalcl.dll
2009-01-14 03:34 . 2009-01-14 03:34 3,227,648 --a------ c:\windows\system32\Amdcaldd.dll
2009-01-08 11:11 . 2009-01-08 11:11 <KAT> d-------- c:\documents and settings\Alex\Application Data\ZoomBrowser EX
2009-01-08 10:54 . 2009-01-08 11:19 <KAT> d-------- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-01-08 10:51 . 2009-01-08 10:51 <KAT> d-------- c:\program\Delade filer\Canon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 15:55 --------- d-----w c:\program\Delade filer\Symantec Shared
2009-02-07 15:55 --------- d-----w c:\documents and settings\Alex\Application Data\Hamachi
2009-02-07 15:52 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-02-01 22:33 --------- d-----w c:\documents and settings\Alex\Application Data\Skype
2009-01-29 22:02 --------- d-----w c:\documents and settings\Alex\Application Data\ATI
2009-01-29 21:57 --------- d-----w c:\documents and settings\standard\Application Data\ATI
2009-01-29 21:57 --------- d-----w c:\documents and settings\LUKAS\Application Data\ATI
2009-01-29 21:56 --------- d--h--w c:\program\InstallShield Installation Information
2009-01-27 18:52 --------- d-----w c:\program\VS Revo Group
2009-01-24 19:13 --------- d-----w c:\program\Google
2009-01-24 19:13 --------- d-----w c:\documents and settings\LUKAS\Application Data\Skype
2009-01-21 13:43 --------- d-----w c:\documents and settings\standard\Application Data\Symantec
2009-01-14 07:14 3,455,488 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-01-11 13:26 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-11 13:26 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-11 13:26 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-11 13:26 --------- d-----w c:\program\Symantec
2009-01-08 09:55 --------- d-----w c:\program\Canon
2008-12-21 17:25 --------- d-----w c:\program\Logitech
2008-12-21 17:25 --------- d-----w c:\program\Delade filer\Logishrd
2008-12-21 17:25 --------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2008-12-17 18:37 --------- d-----w c:\documents and settings\standard\Application Data\Move Networks
2008-12-16 20:33 --------- d-----w c:\program\Delade filer\Logitech
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 14:58 --------- d-----w c:\program\iTunes
2008-12-10 14:58 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-10 14:57 --------- d-----w c:\program\iPod
2008-12-10 14:57 --------- d-----w c:\program\Delade filer\Apple
2008-12-10 14:55 --------- d-----w c:\program\QuickTime
2008-12-09 20:37 138,464 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-08 18:32 --------- d-----w c:\documents and settings\LUKAS\Application Data\AdobeUM
2008-12-07 19:15 --------- d-----w c:\program\Java
2008-12-07 17:08 22,328 ----a-w c:\documents and settings\Alex\Application Data\PnkBstrK.sys
2008-06-30 12:44 324,976 ----a-w c:\program\mozilla firefox\components\coFFPlgn.dll
2008-11-04 15:57 32,768 --sha-w c:\windows\system32\config\systemprofile\Lokala inställningar\Tidigare\History.IE5\MSHist012008110420081105\index.dat
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-10-31 12:24 576352 --a------ c:\program\Delade filer\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-10-31 12:24 576352 --a------ c:\program\Delade filer\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-10-31 12:24 576352 --a------ c:\program\Delade filer\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"DAEMON Tools"="c:\program\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]
"SBDrvDet"="c:\program\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"Easy-PrintToolBox"="c:\program\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"PCLEPCI"="c:\program\Pinnacle\PPE\PPE.EXE" [2004-02-03 49152]
"SunJavaUpdateSched"="c:\program\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-09-01 221184]
"LogitechCameraAssistant"="c:\program\Logitech\Video\CameraAssistant.exe" [2005-09-07 434176]
"LogitechVideo[inspector]"="c:\program\Logitech\Video\InstallHelper.exe" [2005-09-07 06:39 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"Net iD"="c:\windows\system32\iid.exe" [2006-03-02 65536]
"ATICCC"="c:\program\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Zboard"="c:\program\Ideazon\ZEngine\Zboard.exe" [2006-12-16 61440]
"ccApp"="c:\program\Delade filer\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="d:\program\Norton360\osCheck.exe" [2008-02-26 988512]
"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"CTHelper"="CTHELPER.EXE" [2003-10-06 c:\windows\system32\CTHELPER.EXE]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Alex\Start-meny\Program\Autostart\
Hamachi.lnk - c:\program\Hamachi\hamachi.exe [2008-11-19 625952]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
SetPointII.lnk - c:\program\Logitech\SetPoint II\SetpointII.exe [2007-08-30 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"telia"="c:\program\Telia\Supportassistent\bin\sprtcmd.exe" /P Telia

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program\\GameSpy Arcade\\Aphex.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program\\Messenger\\msmsgs.exe"=
"d:\\Program\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program\\SmartFTP Client 2.0\\SmartFTP.exe"=
"c:\\Program\\SiSoftware\\SiSoftware Sandra Lite 2007\\sandra.exe"=
"c:\\Program\\SiSoftware\\SiSoftware Sandra Lite 2007\\RpcSandraSrv.exe"=
"c:\\Program\\SiSoftware\\SiSoftware Sandra Lite 2007\\Win32\\RpcDataSrv.exe"=
"c:\\Program\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"d:\\Program\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"d:\\Program\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"d:\\Program\\Ubisoft\\Tom Clancy's Splinter Cell Double Agent\\SCDA-Offline\\System\\SplinterCell4.exe"=
"d:\\Program\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"d:\\Program\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"d:\\Program\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program\\Joost\\xulrunner\\tvprunner.exe"=
"d:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"c:\\Program\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\Program\\TVersity\\Media Server\\MediaServer.exe"=
"d:\\Program\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"d:\\Program\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"d:\\Program\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program\\iTunes\\iTunes.exe"=
"c:\\Program\\Spotify\\spotify.exe"=
"c:\\Program\\Skype\\Phone\\Skype.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27900:UDP"= 27900:UDP:UDP27900
"29900:TCP"= 29900:TCP:TCP 29900
"29900:UDP"= 29900:UDP:UDP29900
"80:TCP"= 80:TCP:TCP 80
"4711:TCP"= 4711:TCP:TCP 4711
"27901:UDP"= 27901:UDP:UDP 27901
"16567:UDP"= 16567:UDP:UDP 16567
"28910:TCP"= 28910:TCP:TCP 28910
"29901:TCP"= 29901:TCP:TCP 29901
"29920:TCP"= 29920:TCP:TCP 29920
"29910:UDP"= 29910:UDP:UDP 29910
"55123:UDP"= 55123:UDP:UDP 55123
"55124:UDP"= 55124:UDP:UDP 55124
"55215:UDP"= 55215:UDP:UDP 55215
"6881:TCP"= 6881:TCP:6881
"6881:UDP"= 6881:UDP:6881udp
"5353:UDP"= 5353:UDP:Bonjour

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program\Delade filer\Symantec Shared\CCSVCHST.EXE [2008-02-18 149352]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2008-01-27 14976]
R3 3xHybrid;Pinnacle PCTV 300i Stereo DVB-T;c:\windows\system32\drivers\3xHybrid.sys [2005-08-09 969728]
R3 Alpham;Ideazon Merc Composite Keyboard Driver;c:\windows\system32\drivers\Alpham.sys [2006-03-12 37248]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-10-29 99376]
S2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;c:\program\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-21 238968]
S3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\Alex\LOKALA~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\Alex\LOKALA~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [2005-08-10 15840]
S3 pohci13F;pohci13F;\??\c:\docume~1\Alex\LOKALA~1\Temp\pohci13F.sys --> c:\docume~1\Alex\LOKALA~1\Temp\pohci13F.sys [?]
S3 PRISM_A00;CREATIX 802.11g Driver;c:\windows\system32\drivers\PRISMA00.sys [2005-08-09 362688]

--- Övriga tjänster/drivrutiner i minnet ---

*NewlyCreated* - COMHOST
.
Innehållet i mappen 'Schemalagda aktiviteter':

2009-02-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://www.startsidan.telia.se
uInternet Settings,ProxyOverride = *.local
IE: E&xportera till Microsoft Excel - c:\program\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
TCP: {D33B47ED-49ED-4806-8F13-3D199C7DA4EA} = 195.67.199.18,195.67.199.19
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} - hxxp://www.turntool.com/ViewerInstall.exe
DPF: {5BF56AD2-E297-416E-BC49-000004010012} - hxxps://cve.trust.telia.com/TeliaElegUpgrade/iidsetup.cab
FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\wa7m45j2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.dn.se/DNet/jsp/polopoly.jsp?d=144|http://fenixflyg.se/|http://www.google.se/
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\wa7m45j2.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program\FilePlanet\Download Manager\npfpdlm.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\np_prsnl.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\npiidplg.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\npJoostPlugin.dll

---- FIREFOX POLICY ----
c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 16:54:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------

[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:62,74,2c,98,8a,91,1a,4e,72,59,0f,64,93,00,44,8b,b6,36,8b,fe,84,9a,b4,
a9,90,72,a1,a4,a2,db,31,93,b7,78,8c,c1,f0,1e,03,7f,f7,62,f7,43,0a,1e,fc,7c,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49

[HKEY_USERS\S-1-5-21-1786162832-3482737836-1744936881-1008\Software\SecuROM\License information*]
"datasecu"=hex:45,e5,04,86,7e,8a,7f,e1,09,87,93,a4,11,a2,0b,4e,78,c4,3f,a0,67,
50,78,7e,9e,63,ae,1d,dc,2e,a3,5d,38,94,a2,22,eb,e9,8f,c7,9d,6d,9f,a1,e0,27,\
"rkeysecu"=hex:8f,44,c6,11,aa,9e,f4,0e,5c,d3,bb,c8,48,05,87,86

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,27,56,c6,0f,3d,
a2,6b,4d,c8,28,51,af,b0,29,a3,98,73,c3,d5,26,b5,15,6b,07,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,1c,a9,ee,b4,25,
54,3d,2e,71,3b,04,66,8b,46,0d,96,89,de,1a,07,bf,2d,bb,e1,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,31,20,e9,20,09,
2c,14,d8,25,da,ec,7e,55,20,c9,26,9c,3d,6c,db,7e,83,df,41,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,17,c6,80,10,d1,
98,03,5a,3e,1e,9e,e0,57,5a,93,61,af,26,d6,c9,19,ad,1c,3f,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,82,57,de,11,a2,
c4,0e,de,cd,44,cd,b9,a6,33,6c,cd,f1,d4,c6,59,ad,f3,d2,54,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,6a,5e,8a,bb,6e,
21,a9,b6,b0,18,ed,a7,3f,8d,37,a4,b2,b7,00,3e,59,05,9d,31,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,7d,7c,8e,e1,34,
7e,6e,a5,31,77,e1,ba,b1,f8,68,02,b3,8e,f4,16,5c,74,55,1e,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,a5,db,11,f7,53,
8f,5e,34,83,6c,56,8b,a0,85,96,ab,27,2d,a5,00,aa,db,c6,e1,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,29,38,d6,e6,73,
9c,ed,03,51,fa,6e,91,28,9e,14,cc,da,9d,74,6a,30,7c,91,3e,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,b6,c2,8f,d6,2e,
3e,ed,4e,b1,cd,45,5a,a8,c4,f8,b9,11,eb,9c,ac,6d,15,f7,56,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,db,f4,a2,c1,26,
0f,c6,e2,e3,0e,66,d5,eb,bc,2f,6b,50,53,79,69,15,de,1f,8b,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,6b,ed,c5,6e,f4,
ee,42,11,fa,ea,66,7f,d4,3b,6b,70,6e,2b,55,b7,ed,21,b5,23,6c,43,2d,1e,aa,22,\
.
--------------------- DLLer som "laddats" under processer som körs ---------------------

- - - - - - - > 'winlogon.exe'(1124)
c:\windows\system32\Ati2evxx.dll
.
a processer som k
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program\Java\jre6\bin\jqs.exe
c:\program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program\TVersity\Media Server\MediaServer.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\MsPMSPSv.exe
c:\program\Canon\CAL\CALMAIN.exe
c:\program\Delade filer\Logishrd\KHAL2\KHALMNPR.exe
c:\program\iPod\bin\iPodService.exe
.
**************************************************************************
.
Sluttid: 2009-02-07 17:01:30 - datorn startades om.
ComboFix-quarantined-files.txt 2009-02-07 16:01:21

F÷re genoms÷kningen: 82ÿ672ÿ119ÿ808 byte ledigt
Efter genoms÷kningen: 83,489,853,440 byte ledigt

WindowsXP-KB310994-SP2-Home-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

376 --- E O F --- 2009-01-13 20:41:15


Report •

#6
February 7, 2009 at 08:10:24
Hi again,

The resycled/ntldr.com varning is gone. At least when I browse the explorer. Are there still problems?

You seem like a registry genious!

From the log, can you see why I cant uninstall the following games: RB6LV, Splinter cell, Middle earth (midgård), Boog & Eliott and Silent Hunter 4?

Thanks!

/Alex


Report •

#7
February 7, 2009 at 08:53:43
Try uninstalling them from safe mode.

If there uninstaller file is damaged you may have to reinstalll them the uninstall them, try that one at the time.

Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.


Download ATF Cleaner from this link:
http://www.majorgeeks.com/ATF_Cleaner_d4949.html
Run ATF-Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Run an online scan with Kaspersky from the following link:
Kaspersky Online Scanner

Note: If you have used this particular scanner before, you MAY HAVE TO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
3.Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
4. Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
5. Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
6. Click View scan report at the bottom.
7. Click the Save Report As... button.
8. Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
**Note**

To optimize scanning time and produce a more sensible report for review:
Close any open programs.
Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


Report •

#8
February 7, 2009 at 23:09:56
Done. More problems?

----------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, February 8, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, February 07, 2009 16:55:54
Records in database: 1765596
----------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\

Scan statistics:
Files scanned: 347712
Threat name: 5
Infected objects: 29
Suspicious objects: 0
Duration of the scan: 07:52:08


File name / Threat name / Threats count
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\backup.pst Infected: Email-Worm.VBS.KakWorm 2
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\backup.pst Infected: Trojan.Win32.Dialer.oi 2
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Email-Worm.Win32.BadtransII 1
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Email-Worm.VBS.KakWorm 2
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Trojan.Win32.Dialer.oi 2
C:\Documents and Settings\Alex\Mina dokument\Alex\bacup\outlook.pst Infected: Trojan.Win32.Dialer.oi 4
D:\Files_bacup\backup_Alex_0511.pst Infected: Trojan-Spy.HTML.Bayfraud.hn 2
D:\Files_bacup\bacup_barbar_1105.pst Infected: Email-Worm.Win32.Bagle.bq 1
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\backup.pst Infected: Email-Worm.VBS.KakWorm 2
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\backup.pst Infected: Trojan.Win32.Dialer.oi 2
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Email-Worm.Win32.BadtransII 1
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Email-Worm.VBS.KakWorm 2
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\backup3.pst Infected: Trojan.Win32.Dialer.oi 2
L:\Backup_020209\Alex\Mina dokument\Alex\bacup\outlook.pst Infected: Trojan.Win32.Dialer.oi 4

The selected area was scanned.


Report •

#9
February 8, 2009 at 07:53:36
I don't use outlook so I can't tell you how to remove the infected files from the .pst or bacup files but I think that you can research that online and and find out how easily. They need to be cleaned up.

Your computer appears to be clean other that the item found by Kaspersky, mostly Outlook files.


Go to start> run> type in combofix /u (note the space after combofix) then press enter> run. This will uninstall combofix so give the uninstaller a minute to run.

Go to start> control panel> add/remove programs and uninstall these programs:

Hijack This

Malwarebytes

Kaspersky

You should keep AFT Cleaner and run it weekly.


You should consider adding "Spywareblaster" to your arsenol of antispyware tools, you can download it from this link Spywareblaster

Just download it,install it, and update it. Its free and runs in the background, so you don't actually run it, and re-writes malicious script before it can install on your computer. Look for updates weekly as there is no auto-update on the free version.

How is the computer operating?


Report •

#10
February 8, 2009 at 09:01:38
Jabuck,

You did magic. I was on the verge of a clean XP install. Major disaster.

You saved the day!

You probably hear this all the time: But you'r the man!

Thank you so much for all the time and effort.

If you're ever in Stockholm, you have a full day, dinner, beer/vine, all included!
Just "Alert me" :-)

Thanks a bunch!

/Alex

(Now, I'm off to my manual uninstalls. Yuck.)


Report •


Ask Question