Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Im sure its spyware, but im not sure
   
BullGuard Antivirus Forum > General Security > Spyware > Im sure its spyware, but im not sure  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Im sure its spyware, but im not sure
[ << Previous Thread | Next Thread >> ]

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-30-2007 10:02 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
i cant download java, or anything from microsoft website, the yellow bar doesnt want to show up, please help. the other forums i tryed are all baffled. really need help. ive ran avg antivirus and anti spyware on my computer, and i even scanned in safe mode, i located a few viruses and removed them. one was called soundman.exe which is a worm. and a launcher.exe which was also removed, ive used panda scan, ive used sdfix.exe and it didnt find anything, ive ran sophos antivirus trial and it didnt find anything either. ive disabled my antivirus and anti spyware and i still cant downlaod java. should i post a  hijack this log now? please reply soon.
 
thank you
 
P.S this is a family computer and not my home one and im sure it has quite a few viruses on it.

Post Edited (close) : 30-07-2007 21:05:26 GMT

Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 7-30-2007 10:06 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
Hello.

Please go to this thread.
Then post the required logs so we can analyze.

Regards,


Andrei M
Microsoft Certified Professional
BullGuard Support Team | support[at]bullguard[dot]com

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-30-2007 10:31 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure

SDFix: Version 1.94
Run by «©ں¤ on Mon 07/30/2007 at 11:20 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:

Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...

Normal Mode:
Checking Files:
No Trojan Files Found
 

Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
 
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
 

                                 Final Check:
Remaining Services:
------------------
 
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------

Files with Hidden Attributes:
C:\Program Files\!!!! NFO Viewer\LangDLLs\!!!!_NFO_Viewer_ENG.dll
C:\WINDOWS\system32\kbda1.dll
C:\WINDOWS\system32\kbda2.dll
C:\WINDOWS\system32\kbda3.dll
C:\WINDOWS\system32\KBDAL.DLL
C:\WINDOWS\system32\kbdarme.dll
C:\WINDOWS\system32\kbdarmw.dll
C:\WINDOWS\system32\kbdaze.dll
C:\WINDOWS\system32\kbdazel.dll
C:\WINDOWS\system32\kbdblr.dll
C:\WINDOWS\system32\kbdbu.dll
C:\WINDOWS\system32\kbdcr.dll
C:\WINDOWS\system32\kbdcz.dll
C:\WINDOWS\system32\kbdcz1.dll
C:\WINDOWS\system32\kbdcz2.dll
C:\WINDOWS\system32\kbddiv1.dll
C:\WINDOWS\system32\kbddiv2.dll
C:\WINDOWS\system32\kbdest.dll
C:\WINDOWS\system32\kbdfa.dll
C:\WINDOWS\system32\kbdgeo.dll
C:\WINDOWS\system32\kbdgkl.dll
C:\WINDOWS\system32\kbdhe.dll
C:\WINDOWS\system32\kbdhe220.dll
C:\WINDOWS\system32\kbdhe319.dll
C:\WINDOWS\system32\kbdheb.dll
C:\WINDOWS\system32\kbdhela2.dll
C:\WINDOWS\system32\kbdhela3.dll
C:\WINDOWS\system32\kbdhept.dll
C:\WINDOWS\system32\kbdhu.dll
C:\WINDOWS\system32\kbdhu1.dll
C:\WINDOWS\system32\kbdindev.dll
C:\WINDOWS\system32\kbdinguj.dll
C:\WINDOWS\system32\kbdinhin.dll
C:\WINDOWS\system32\kbdinkan.dll
C:\WINDOWS\system32\kbdinmar.dll
C:\WINDOWS\system32\kbdinpun.dll
C:\WINDOWS\system32\kbdintam.dll
C:\WINDOWS\system32\kbdintel.dll
C:\WINDOWS\system32\kbdkaz.dll
C:\WINDOWS\system32\kbdkyr.dll
C:\WINDOWS\system32\kbdlt.dll
C:\WINDOWS\system32\kbdlt1.dll
C:\WINDOWS\system32\kbdlv.dll
C:\WINDOWS\system32\kbdlv1.dll
C:\WINDOWS\system32\kbdmon.dll
C:\WINDOWS\system32\kbdnepr.dll
C:\WINDOWS\system32\kbdpash.dll
C:\WINDOWS\system32\kbdpl.dll
C:\WINDOWS\system32\kbdpl1.dll
C:\WINDOWS\system32\kbdro.dll
C:\WINDOWS\system32\kbdru.dll
C:\WINDOWS\system32\kbdru1.dll
C:\WINDOWS\system32\kbdsl.dll
C:\WINDOWS\system32\kbdsl1.dll
C:\WINDOWS\system32\kbdsyr1.dll
C:\WINDOWS\system32\kbdsyr2.dll
C:\WINDOWS\system32\kbdtat.dll
C:\WINDOWS\system32\kbdth0.dll
C:\WINDOWS\system32\kbdth1.dll
C:\WINDOWS\system32\kbdth2.dll
C:\WINDOWS\system32\kbdth3.dll
C:\WINDOWS\system32\kbdtuf.dll
C:\WINDOWS\system32\kbdtuq.dll
C:\WINDOWS\system32\kbdur.dll
C:\WINDOWS\system32\kbdurdu.dll
C:\WINDOWS\system32\kbduzb.dll
C:\WINDOWS\system32\kbdvntc.dll
C:\WINDOWS\system32\kbdycc.dll
C:\WINDOWS\system32\kbdycl.dll
C:\Program Files\!!!! NFO Viewer\!!!! NFO Viewer.exe
C:\WINDOWS\SET21.tmp
C:\WINDOWS\SET22.tmp
C:\WINDOWS\SET23.tmp
C:\WINDOWS\SET24.tmp
C:\WINDOWS\SET25.tmp
C:\WINDOWS\SET26.tmp
C:\WINDOWS\SET27.tmp
C:\WINDOWS\SET28.tmp
C:\WINDOWS\SET29.tmp
C:\WINDOWS\SET2A.tmp
C:\WINDOWS\SET2B.tmp
C:\WINDOWS\SET2C.tmp
C:\WINDOWS\SET2D.tmp
C:\WINDOWS\SET2E.tmp
C:\WINDOWS\SET2F.tmp
C:\WINDOWS\SET3.tmp
C:\WINDOWS\SET30.tmp
C:\WINDOWS\SET31.tmp
C:\WINDOWS\SET32.tmp
C:\WINDOWS\SET33.tmp
C:\WINDOWS\SET34.tmp
C:\WINDOWS\SET35.tmp
C:\WINDOWS\SET36.tmp
C:\WINDOWS\SET37.tmp
C:\WINDOWS\SET38.tmp
C:\WINDOWS\SET39.tmp
C:\WINDOWS\SET3A.tmp
C:\WINDOWS\SET3B.tmp
C:\WINDOWS\SET3C.tmp
C:\WINDOWS\SET3D.tmp
C:\WINDOWS\SET3E.tmp
C:\WINDOWS\SET3F.tmp
C:\WINDOWS\SET4.tmp
C:\WINDOWS\SET40.tmp
C:\WINDOWS\SET41.tmp
C:\WINDOWS\SET42.tmp
C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET44.tmp
C:\WINDOWS\SET45.tmp
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET47.tmp
C:\WINDOWS\SET48.tmp
C:\WINDOWS\SET49.tmp
C:\WINDOWS\SET4A.tmp
C:\WINDOWS\SET4B.tmp
C:\WINDOWS\SET4C.tmp
C:\WINDOWS\SET4D.tmp
C:\WINDOWS\SET4E.tmp
C:\WINDOWS\SET4F.tmp
C:\WINDOWS\SET50.tmp
C:\WINDOWS\SET51.tmp
C:\WINDOWS\SET52.tmp
C:\WINDOWS\SET53.tmp
C:\WINDOWS\SET54.tmp
C:\WINDOWS\SET55.tmp
C:\WINDOWS\SET56.tmp
C:\WINDOWS\SET57.tmp
C:\WINDOWS\SET58.tmp
C:\WINDOWS\SET59.tmp
C:\WINDOWS\SET5A.tmp
C:\WINDOWS\SET5B.tmp
C:\WINDOWS\SET5C.tmp
C:\WINDOWS\SET5D.tmp
C:\WINDOWS\SET5E.tmp
C:\WINDOWS\SET5F.tmp
C:\WINDOWS\SET60.tmp
C:\WINDOWS\SET61.tmp
C:\WINDOWS\SET62.tmp
C:\WINDOWS\SET63.tmp
C:\WINDOWS\SET64.tmp
C:\WINDOWS\SET65.tmp
C:\WINDOWS\SET66.tmp
C:\WINDOWS\SET67.tmp
C:\WINDOWS\SET68.tmp
C:\WINDOWS\SET69.tmp
C:\WINDOWS\SET6A.tmp
C:\WINDOWS\SET6B.tmp
C:\WINDOWS\SET6C.tmp
C:\WINDOWS\SET6D.tmp
C:\WINDOWS\SET6E.tmp
C:\WINDOWS\SET6F.tmp
C:\WINDOWS\SET70.tmp
C:\WINDOWS\SET72.tmp
C:\WINDOWS\SET73.tmp
C:\WINDOWS\SET74.tmp
C:\WINDOWS\SET75.tmp
C:\WINDOWS\SET76.tmp
C:\WINDOWS\SET77.tmp
C:\WINDOWS\SET78.tmp
C:\WINDOWS\SET79.tmp
C:\WINDOWS\SET7A.tmp
C:\WINDOWS\SET7B.tmp
C:\WINDOWS\SET7C.tmp
C:\WINDOWS\SET7D.tmp
C:\WINDOWS\SET7E.tmp
C:\WINDOWS\SET7F.tmp
C:\WINDOWS\SET8.tmp
C:\WINDOWS\SET80.tmp
C:\WINDOWS\SET81.tmp
C:\WINDOWS\SET82.tmp
C:\WINDOWS\SET83.tmp
C:\WINDOWS\SET84.tmp
C:\WINDOWS\SET85.tmp
C:\WINDOWS\SET86.tmp
C:\WINDOWS\SET87.tmp
C:\WINDOWS\SET88.tmp
C:\WINDOWS\SET89.tmp
C:\WINDOWS\SET8A.tmp
C:\WINDOWS\SET8B.tmp
C:\WINDOWS\SET8C.tmp
C:\WINDOWS\SET8D.tmp
C:\WINDOWS\SET8E.tmp
C:\WINDOWS\SET8F.tmp
C:\WINDOWS\SET90.tmp
C:\WINDOWS\SET91.tmp
C:\WINDOWS\SET92.tmp
C:\WINDOWS\SET93.tmp
C:\WINDOWS\SET94.tmp
C:\WINDOWS\SET95.tmp
C:\WINDOWS\SET96.tmp
C:\WINDOWS\SET97.tmp
C:\WINDOWS\SET98.tmp
C:\WINDOWS\SET99.tmp
C:\WINDOWS\SET9A.tmp
C:\WINDOWS\SET9B.tmp
C:\WINDOWS\SET9C.tmp
C:\WINDOWS\SET9D.tmp
C:\WINDOWS\SET9E.tmp
C:\WINDOWS\SET9F.tmp
C:\WINDOWS\SETA0.tmp
C:\WINDOWS\SETA1.tmp
C:\WINDOWS\SETA2.tmp
C:\WINDOWS\SETA3.tmp
C:\WINDOWS\SETA4.tmp
C:\WINDOWS\SETA5.tmp
C:\WINDOWS\SETA6.tmp
C:\WINDOWS\SETA7.tmp
C:\WINDOWS\SETA8.tmp
C:\WINDOWS\SETA9.tmp
C:\WINDOWS\SETAA.tmp
C:\WINDOWS\SETAB.tmp
C:\WINDOWS\SETAC.tmp
C:\WINDOWS\SoftwareDistribution\Download\e3c4136556c17e58256c9c04abea4fc8\BIT384.tmp
C:\WINDOWS\SoftwareDistribution\Download\eabf4d5c34535a00aa7d0d27e1ffc96b\BIT26.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\05c77e1ed88a1e6e6bd081f27fbe6953\BIT76.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2d77f1a5229333ccfd2b320fc9e3286c\BIT30.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2f5091478db83d722d22c4811bef3fca\BIT6.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2f9842441d37acc66b89543d164cf107\BIT15D.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\3070351b7b7b1b5a00cb7c20e2fa282b\BIT81.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\58675f2156719c45f98dc95fffc5d048\BITA.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\9b6de1cddd5d4d86811ab127dd0acdc6\BIT80.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\ba2c42f86cb91f566ad3d44de1ccc5dd\BIT2.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\be39201e9a2f608fe8161babfd096dbb\BIT2E.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\d7dd76e634f314785a93df60f3553144\BIT13.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f0da280f56f415f6b1d44ca99367c4eb\BIT5.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f6f8361327e35c14e817813fcf25808a\BIT7B.tmp
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\asf96ohd.TMP
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\foccjdni.TMP
                                 Finished
 
hears my sdfix log, im now going to run hijackthis and post the log
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-30-2007 10:39 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
Logfile of HijackThis v1.99.1
Scan saved at 11:40:18 PM, on 7/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\سراج\Local Settings\Temporary Internet Files\Content.IE5\ZA11ZJJ8\alternativ.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O15 - Trusted Zone: www.java.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5BFB5EE-E239-4A30-9402-19FAAEA67562}: NameServer = 62.68.42.2 62.240.32.5
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - Unknown owner - hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,0...00,47,00,72,00,6f,00,75,00,70,00,00,00 (file missing)

any ideas?

Post Edited (Andrei M) : 30-07-2007 22:08:48 GMT

Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 7-30-2007 11:06 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
Please download Combofix from here

and save it to the desktop.

Close all other browser windows.
Double click on combo.exe & follow the prompts.
When finished, it will produce a logfile located at C:\ComboFix.txt.

Post the contents of that log in your next reply with a new hijackthis log.

Note:
Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.


Andrei M
Microsoft Certified Professional
BullGuard Support Team | support[at]bullguard[dot]com

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 9:39 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
ok, sorry for the late reply
 
ComboFix 07-07-30.2 - "«©ں¤" 2007-07-31 10:51:34.1 [GMT 3:00] - NTFS
Microsoft Windows XP Professional  5.1.2600.2.1256.966.1033.18.True
 * Created a new restore point

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

C:\DOCUME~1\4C9C~1\Desktop\internet.lnk

(((((((((((((((((((((((((   Files Created from 2007-06-28 to 2007-07-31  )))))))))))))))))))))))))))))))

2007-07-31 10:50 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-30 16:12 <DIR> d-------- C:\stdtsa
2007-07-29 23:23 <DIR> d-------- C:\DOCUME~1\8CF5~1\APPLIC~1\BSplayer
2007-07-28 16:26 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-28 16:23 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-28 15:01 <DIR> d-------- C:\DOCUME~1\4C9C~1\APPLIC~1\Media Player Classic
2007-07-28 14:34 0 --a------ C:\WINDOWS\nsreg.dat
2007-07-28 12:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-27 14:16 <DIR> d-------- C:\Program Files\Google
2007-07-27 14:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-27 14:16 <DIR> d-------- C:\DOCUME~1\4C9C~1\APPLIC~1\Google
2007-07-26 14:58 <DIR> d-------- C:\WINDOWS\ERUNT
2007-07-26 14:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-26 13:40 <DIR> d-------- C:\DOCUME~1\4C9C~1\Phone Browser
2007-07-26 12:33 <DIR> d---s---- C:\DOCUME~1\4C9C~1\UserData
2007-07-25 12:09 <DIR> d-------- C:\Program Files\Project64 1.6
2007-07-25 12:06 <DIR> d-------- C:\WINDOWS\system32\VirtualExpander
2007-07-25 12:00 <DIR> d-------- C:\Program Files\APO Usb Autorun
2007-07-25 11:11 1,572,864 --ah----- C:\DOCUME~1\4C9C~1\NTUSER.DAT
2007-07-25 11:11 <DIR> d-------- C:\DOCUME~1\4C9C~1\APPLIC~1\PC Suite
2007-06-22 18:18 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-20 15:03 <DIR> d-------- C:\DOCUME~1\FORZAM~1\WINDOWS

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-30 23:13 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-30 10:51 --------- d-------- C:\Program Files\Realtek AC97
2007-07-26 15:51 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-05-16 18:32 683520 --a------ C:\WINDOWS\system32\inetcomm.dll

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
 
 
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-11 18:33 C:\WINDOWS\system32\VTTrayp.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-26 00:01]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 12:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 19:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
VTtrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys
R1 BIOS;BIOS;\??\C:\WINDOWS\system32\drivers\BIOS.sys
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys
S3 Nokia USB Generic;Nokia USB Generic;C:\WINDOWS\system32\drivers\nmwcdc.sys
S3 Nokia USB Modem;Nokia USB Modem;C:\WINDOWS\system32\drivers\nmwcdcm.sys
S3 Nokia USB Phone Parent;Nokia USB Phone Parent;C:\WINDOWS\system32\drivers\nmwcd.sys
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b918140-3bc9-11dc-8a40-00e04cfe5b2d}]
AutoRun\command- RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb7b6e6f-3a8c-11dc-8a35-00e04cfe5b2d}]
AutoRun\command- \runzip

**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-31 10:54:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DocFolderPaths]
"3\0061\6'\6,\6"="C:\Documents and Settings\\x633\x631\x627\x62c\My Documents"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Hints\3\0061\6'\6,\6]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Hints\9\6(\6/\6'\6D\6E\6$\6E\6F\6 ]
"PictureSource"="C:\Documents and Settings\\x639\x628\x62f\x627\x644\x645\x624\x645\x646   \x627\x644\x639\x645\x631\x64a\My Documents\My Pictures\\x631\x633\x648\x645\x627\x62a + \x62d\x64a\x648\x646\x627\x62a\7146BRD.JPG"
@="731694"
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
Completion time: 2007-07-31 10:55:13
C:\ComboFix-quarantined-files.txt ... 2007-07-31 10:54
 --- E O F ---

 
i forgot to save it to desktop i just pressed run accidently is that alright?

Post Edited (close) : 31-07-2007 09:04:51 GMT

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 10:22 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
here is some more information, on another forum they suggested i should download another browser and try to download java, i downloaded firefox and when i tryed to download java it came up with error -228

i searched this and it said either my antivirus or a spyware program is blocking me from downloading, or i dont have enough memory, and i have 5 gb free memory in C

and 50 gb free in my E drive.

how can i move disk space from one drive to another?
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 1:49 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
here are the threats i removed :-

launcher.exe (x2)
soundman.exe (W32/Agobot-JS)
some type of malware (x2)
new folder.exe
PsKill (im not sure what type of program this is, it can be used for malicious purposes but its a program made by sysinternals)

Post Edited (close) : 31-07-2007 12:51:55 GMT

Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 7-31-2007 2:12 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
Log looks clean.
What exactly can't you download, the Java Runtime Environment? Try this website:
http://java.sun.com/javase/downloads/index.jsp

Download where it says:

Java Runtime Environment (JRE) 6 Update 2
The Java SE Runtime Environment (JRE) allows end-users to run Java applications

Let me know the errror message you receive when trying to download the JRE from above.

Also you can trust the sysinternals programs,they're safe, but only use them when advised by someone.


Andrei M
Microsoft Certified Professional
BullGuard Support Team | support[at]bullguard[dot]com

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 2:49 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
ok, heres the error:

Get the latest Java Runtime Environment to use Sun Download Manager

Internet Explorer Users: Check the top of this page for a "Java(TM) Web Start ActiveX Control" message in the information bar. If it appears, click it to finish detecting your Java version.

We were unable to detect a recent version of Java Runtime Environment (JRE) on your system. With the latest JRE, you can automatically download, install, and run Sun Download Manager (SDM) directly from this page. We highly recommend SDM to easily manage your downloads (pause, resume, restart, verify, and more). Visit java.com for the latest JRE.

if i try to download java from java.com i get this error:

We encountered an issue while trying to automatically install Java software onto your machine.

(picture here)

If you encounter an error, check the top of the browser (see image above) for a yellow bar that reads "This site might require the following ActiveX control: J2SE Runtime Environment 6 Update 2 from 'Sun Microsystems, Inc.'. Click here to install..." Click the yellow bar and choose "Install ActiveX Control..." to allow installation to proceed.

if i try to download anything from microsoft website after it does the genuine validation check it says page not found...
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 2:50 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
if i try to downlaod the offline version of java from java.com it says 2 words on a blank page

Export denied

i have a feeling this has been caused by the last anti virus on the computer if it wasnt spyware
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 7-31-2007 2:57 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
i also cant access the security part of the control panel.
and sometimes when i log on avg anti spyware is turned off...

should i try and download java through a proxy?

Post Edited (close) : 31-07-2007 16:03:29 GMT

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 8-1-2007 10:15 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
if all this doesnt work would a system restart work?
 
ive tried downloading it with netscape and firefox, java still doesnt want to download.

Post Edited (close) : 01-08-2007 10:13:52 GMT

Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 8-1-2007 2:45 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
i cant download it with opera either...


 
this guy is mental!!!
 
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 8-1-2007 10:17 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
hmm, ive tryed downloading it on another computer at a friends house, same problem, could it be we're both infected by the same virus, we both have different antivirus'. or could it be that you cant run activeX in this country, im currently in libya, can the goverment change what you can download? can they block activeX or try to find information from this computer. reply soon please


 
this guy is mental!!!
 
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 8-2-2007 9:09 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
erm, whenever i scan with avg the first thing that comes up is hosts and the result is the hosts file gets changed, hosts file is in C:\windows\system32\drivers\etc\hosts

what should i do?


 
this guy is mental!!!
 
Back to Top
 

close
New Member


Date Joined Jun 2007
Total Posts : 26
 
   Posted 8-5-2007 6:26 (GMT +1)    Quote: Im sure its spyware, but im not sureAlert an admin about: Im sure its spyware, but im not sure
if your not going to reply can you at least lock this post?


 
this guy is mental!!!
 
Back to Top
 
New Topic Locked Topic Printable version of : Im sure its spyware, but im not sure
 
Forum Information
Currently it is Thursday, December 04, 2008 7:59 PM (GMT +1)
There are a total of 64.634 posts in 15.923 threads.
In the last 3 days there were 21 new threads and 135 reply posts. View Active Threads
Who's Online
This forum has 27355 registered members. Please welcome our newest member, bigstu.
63 Guest(s), 1 Registered Member(s) are currently online.  Details
chazz
5 Latest Threads
Virtrigger removal (27)04-12-2008 18:41:49 (JHT)
About a worm "recycled/boot.com" (0)04-12-2008 18:27:11 (Wello)
Vundo. BG & Generic 10.AMUY Trojan Horse...How do I get rid of them? (6)04-12-2008 17:25:37 (arusell)
Used MBAM to remove Virtrigger... But (2)04-12-2008 17:24:19 (Churrosgomoo)
Command Service (10)04-12-2008 17:21:11 (yogendra)