Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

help plz i have trojan horse proxy. AHIY

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 19th, 2009, 9:52 am

sorry for double post didnt think it sent first time
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm
Advertisement
Register to Remove

Re: help plz i have trojan horse proxy. AHIY

Unread postby muppy03 » September 19th, 2009, 6:54 pm

Has the computer beed rebooted since?
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 19th, 2009, 9:05 pm

yes its been rebooted a few times
the only way i can get on the net now is through windows live messenger,
if i hit the internet explorer or mozzila firefox it gives me same message,
so when i go into messenger i can carry on useing internt explorer through that. :?
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby muppy03 » September 20th, 2009, 2:17 am

Hi there,
Lets see if we can find out what’s going on. Could you please post the Combofix quarantine log for me. It can be found in the c:\Qoobox folder.
ComboFix-quarantined-files.txt

Also is Spybot - Search and Destroy/TeaTimer still disabled, or was re-enabled after running ComboFix.

Thanks
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 20th, 2009, 9:29 am

2009-09-19 12:42:50 . 2009-09-19 12:42:50 160 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NBKeyScan.reg.dat
2009-09-19 12:42:47 . 2009-09-19 12:42:47 167 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-iowmjosoi.reg.dat
2009-09-19 12:29:59 . 2009-09-19 12:29:59 1,162 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_NPF.reg.dat
2009-09-19 12:29:59 . 2009-09-19 12:29:59 1,032 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_NPF.reg.dat
2009-09-19 12:29:39 . 2009-09-19 12:29:39 10,045 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-09-19 12:17:54 . 2009-09-19 12:20:54 82 ----a-w- C:\Qoobox\Quarantine\catchme.log
2009-09-12 13:48:10 . 2006-10-30 12:46:02 3,654 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\drivers\Sonyhcp.dll.vir
2009-06-04 00:55:26 . 2009-06-04 00:54:49 873,398 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\oem28.inf.vir
2008-07-09 21:05:53 . 2008-07-09 21:07:47 25 ----a-w- C:\Qoobox\Quarantine\C\Windows\SW_Win2000X48.DLL.vir
2007-12-16 11:37:43 . 2009-05-25 10:42:17 87,608 ----a-w- C:\Qoobox\Quarantine\C\Users\User\AppData\Roaming\inst.exe.vir
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 20th, 2009, 9:33 am

just spybot sd resident shield started up
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby muppy03 » September 21st, 2009, 6:58 am

Hi Deemon, sorry for keeping you waiting, just checking out a couple of issues and I will get back to you as soon as I am able.
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 21st, 2009, 6:59 am

no probs mate ;)
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby muppy03 » September 22nd, 2009, 3:59 pm

Disable Spybot's TeaTimer. This is a two step process.

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. Please leave disabled until the machine is completely clean. Once the All clean is given it can be re-enabled.

First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.
Don't forget to re-enable it, when your computer is clean.

Next Using Internet Explorer, download Ttwipe.bat

If you are using Firefox, right click the above link and choose ‘Save As’. Save it to your desktop.

Right click> run as administrator TTWipe.bat to remove all entries set by TeaTimer.

Next COMBOFIX-Script
A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.

Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". This includes your AVG Antivirus and Antispyware Please also disable Windows defender and of course Teatimer has been disabled in step 1.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Code: Select all
    DirLook:: 
    c:\programdata\23D1
    C:\ProgramData\532F
    
    

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    Image
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

We'd like to get a closer look at a file. Open Notepad and copy/paste the contents in the code box below, into Notepad.

Code: Select all
@echo off
for %%g in (
"C:\QooBox\Quarantine\c\windows\system32\drivers\Sonyhcp.dll.vir"
) do zip Files_for_submission %%g
del %0


Save this as submit.bat Choose to "Save type as - All Files" and save it to your desktop.

It should look like this:Image

Double click on submit.bat & allow it to run. A file, Files_for_submission.zip will be created on your desktop.

Please upload that file here and kindly let me know when it has been uploaded.

Please reply with:-
  • Combofix log
  • New HJT log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 22nd, 2009, 6:48 pm

ComboFix 09-09-18.02 - User 22/09/2009 23:20.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1013.283 [GMT 1:00]
Running from: c:\users\User\Desktop\ComboFix.exe
Command switches used :: c:\users\User\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: AVG Anti-Virus *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.

2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\User\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-19 11:52 . 2009-09-19 11:52 -------- d-----w- c:\programdata\23D1
2009-09-18 18:08 . 2009-09-18 18:09 -------- d-----w- C:\rsit
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2009-09-18 14:01 . 2009-09-22 21:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\programdata\Malwarebytes
2009-09-18 12:35 . 2009-09-18 12:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-12 14:21 . 2009-09-12 14:21 -------- d-----w- c:\users\User\AppData\Roaming\Sony Corporation
2009-09-12 13:48 . 2006-10-30 12:46 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-09-12 13:48 . 2006-10-30 12:46 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-09-12 13:48 . 2006-10-30 12:46 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-09-12 13:48 . 2006-10-30 12:46 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-09-12 13:48 . 2006-10-30 12:46 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
2009-09-12 13:48 . 2009-09-12 13:48 -------- d-----w- C:\Drivers
2009-09-12 13:47 . 2006-11-02 15:57 36624 ----a-w- c:\windows\system32\drivers\pxhelp20.sys
2009-09-12 13:47 . 2006-11-02 15:57 118520 ----a-w- c:\windows\system32\PxInsI64.exe
2009-09-12 13:47 . 2006-08-28 20:48 2560 ----a-w- c:\windows\system32\drivers\cdralw2k.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_xp.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_2k.sys
2009-09-12 13:47 . 2006-10-18 18:43 115960 ----a-w- c:\windows\system32\PxCpyI64.exe
2009-09-12 13:42 . 2009-09-12 13:42 -------- d-----w- c:\program files\Sony
2009-09-10 23:27 . 2009-09-11 00:09 -------- d-----w- c:\users\User\.SunDownloadManager
2009-09-09 23:03 . 2009-09-09 23:03 -------- d-----w- c:\program files\Trend Micro
2009-09-09 16:23 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 16:23 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 16:23 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 16:23 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 16:23 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 16:23 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 16:23 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 16:23 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 16:23 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 16:23 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 16:20 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 16:20 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 16:20 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 16:20 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 16:19 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-02 21:42 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:42 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\users\User\AppData\Local\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\programdata\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\program files\TVUPlayer
2009-08-28 16:10 . 2009-08-28 16:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-26 13:14 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 21:59 . 2009-06-10 17:55 -------- d-----w- c:\programdata\avg8
2009-09-22 21:51 . 2007-09-24 12:56 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-22 12:18 . 2009-06-02 23:29 3308 ----a-w- c:\windows\bthservsdp.dat
2009-09-22 12:06 . 2009-03-25 22:07 -------- d-----w- c:\programdata\Google Updater
2009-09-20 01:24 . 2008-02-15 22:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-09-18 19:25 . 2007-11-04 12:17 -------- d-----w- c:\users\User\AppData\Roaming\uTorrent
2009-09-12 13:51 . 2008-01-15 14:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 12:32 . 2008-02-15 22:06 -------- d-----w- c:\programdata\Yahoo! Companion
2009-09-10 11:15 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 16:37 . 2009-05-25 10:40 -------- d-----w- c:\programdata\DVD Shrink
2009-09-08 16:35 . 2007-12-16 11:37 -------- d-----w- c:\users\User\AppData\Roaming\Vso
2009-08-19 19:05 . 2009-08-19 19:04 -------- d-----w- c:\program files\TVAnts
2009-08-19 15:23 . 2009-08-19 15:23 -------- d-----w- c:\program files\KLC
2009-08-18 17:05 . 2009-08-18 16:59 -------- d-----w- c:\users\User\AppData\Roaming\ImgBurn
2009-08-18 16:54 . 2009-08-18 16:54 -------- d-----w- c:\program files\ImgBurn
2009-08-14 12:37 . 2009-06-10 17:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-14 12:37 . 2009-06-10 17:55 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-14 12:37 . 2009-06-10 17:55 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-28 12:43 . 2009-07-27 19:05 -------- d-----w- c:\programdata\Driving Test Success
2009-07-27 19:05 . 2009-07-27 19:05 -------- d-----w- c:\program files\Driving Test Success 2006-2007
2009-07-25 16:33 . 2009-07-25 16:33 -------- d-----w- c:\program files\DVD Decrypter
2009-07-18 16:06 . 2009-07-29 21:26 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-29 21:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-29 21:26 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-14 12:58 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-14 12:57 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-14 12:57 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-14 12:57 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-14 12:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\23D1 ----

2009-09-19 11:52 . 2009-07-07 14:19 2329 ----a-w- c:\programdata\23D1\{B08BDCB2-5017-4C09-905C-C5ECECF75103}.swf

---- Directory of c:\programdata\532F ----



((((((((((((((((((((((((((((( SnapShot@2009-09-19_12.37.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-09-24 15:29 . 2009-09-22 21:43 56924 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-22 21:43 78216 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-09-24 12:49 . 2009-09-22 21:43 15422 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2556230271-85685182-2986242697-1000_UserData.bin
- 2006-11-02 13:02 . 2009-09-19 12:13 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-22 21:41 . 2009-09-22 21:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-22 21:41 . 2009-09-22 21:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 608706 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 608706 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 109542 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 109542 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-02 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-20 148888]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1021224]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-29 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-29 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-29 133656]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2022680]

c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-9-12 344064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{012EF020-255B-44F2-8E33-F7C236857C4A}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= UDP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"UDP Query User{D7CE9476-2296-43C1-8206-9D9CCAA882FF}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= TCP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"TCP Query User{83DA906D-59CF-43FB-8ED1-D84476250BFD}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{7FD13365-BB45-43F9-81CB-013B981E9C98}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"TCP Query User{EC39B7C4-597E-41A5-BA17-C7A94678EEA0}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{CDEF6486-0AEA-4CD2-B3D3-B7FE03050800}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{34AAE61B-0CEB-4E8B-A313-121A96210DC4}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{1E811BF8-3786-4141-81EC-075886A82B9B}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"{E89967B3-5ED3-45CB-802C-B1C77E417BC1}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{0B859C1B-88FE-45DE-B80F-415D2128176A}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7041346C-5461-4D14-B6D6-FC7947D2F31A}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{20580FE6-6571-431B-94BA-1D8DF1D808CA}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{7C6FE02A-D346-4A97-A601-96501B65573A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E6DEF23E-BA42-4334-9003-B5C87EB82F20}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7FBE0A73-CC67-49DA-9829-A64C5A229F40}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{00E5DFDA-1D3E-4E1B-9C3C-72246BD6FE19}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{FBE54612-A155-4ED5-8753-7184E5EB45E2}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{94341170-8A0B-47E6-8A9F-5DE623E288BB}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{59F91452-3DED-4D86-A2A9-9C34084D5426}c:\\windows\\system32\\rsezmk.exe"= UDP:c:\windows\system32\rsezmk.exe:rsezmk
"UDP Query User{432C9CC9-CBA4-4FB8-B20C-047A7415E3C3}c:\\windows\\system32\\rsezmk.exe"= TCP:c:\windows\system32\rsezmk.exe:rsezmk
"{E471893F-2CD1-4F9E-8691-0276744EA04B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{AA1A4689-684E-40FA-A0F4-6B55CD6E3B9E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{06C73D32-9DE8-497C-ADB2-786292A7CD0C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{06EA8901-9D67-49E4-B20D-5205E2638FB3}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{95068D88-C2E6-421C-9855-506D4389EA62}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{742B496E-65E1-48C9-8142-94D9528052CA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E007E5C1-8FB2-4379-8AFB-6D2ABA613CA9}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{91515220-D4A3-4984-93D3-35FC7D95CF58}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{F6E0A41F-42A0-4EF7-8BD9-1C090BF81945}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{B99D60D0-D6BC-42A2-8C64-055CF3B6FFF1}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{D3F6570E-E718-409D-AE30-D32AB803319E}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{862FD8CA-9431-48B2-BC43-01DE6890011F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{197BF7A8-E8FB-4797-875C-4AFD07F7D3EB}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{1645673B-1CE4-4557-9380-669252860C5D}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{9F8F7FA4-C473-4BBD-9459-C413B2F21CE6}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"TCP Query User{7E662504-E605-45C4-A235-4CA3C1282A7E}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{0FE02598-F776-4BC6-95D1-F96BEEA28A2F}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{C4951CB8-902E-4928-BDE2-1C942C51BFB7}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{7360A712-0467-451B-8997-49059E776F0D}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{1539EED6-B2F5-4E38-97EF-7E030041A9BA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{398D87C3-9BEB-4CE1-8F47-4CB46922A9BC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{21D81B62-1FA0-4B53-A48A-F22D66A4CA74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{00644132-EB98-405E-A653-E1267508DCF0}"= Disabled:UDP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{4EC35746-1028-4FF8-83D1-A5E05E6BE7AD}"= Disabled:TCP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{0828C2C2-7F10-4319-9C08-D4A2BE5E46B3}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FE658A9D-7A31-40BB-9B87-09046AD0CABD}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BB125485-24C3-46FC-AA38-E2D0A97896A2}"= Disabled:c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{6F414882-F2FC-4C70-B0B7-EF53E2B25C46}"= Disabled:c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{5E829439-5FA3-48EE-B0E5-52B6D6E4BB2F}"= Disabled:c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{CD903931-2A4B-4A99-B232-8550589EF3D0}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{258A4B77-A6B8-4224-B0EB-4C54A8D6C7FF}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{5245D0F1-FC93-4824-A59B-261B485618E2}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{663CED64-0635-4691-9114-7F7F83F5987D}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{185F2579-F7F3-44B1-BCDB-E8E5D129908B}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:UDP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{B104C8A3-075D-41F9-A497-3120C45F26EF}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:TCP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [10/06/2009 18:55 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/06/2009 18:55 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/06/2009 18:55 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/06/2009 20:37 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [18/09/2009 13:35 1153368]
S3 bthav;Bluetooth AV Profile;c:\windows\System32\drivers\bthav.sys [10/07/2008 15:43 34816]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [10/07/2008 15:43 15872]
S3 Flash1;Flash1;c:\program files\SP39371\winphlash\FLASH1.sys [01/03/2006 17:54 3456]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [28/06/2008 11:12 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [28/06/2008 11:12 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [28/06/2008 11:12 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [28/06/2008 11:12 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [28/06/2008 11:12 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [28/06/2008 11:12 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [28/06/2008 11:12 110120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-09-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-28 22:06]

2009-09-22 c:\windows\Tasks\User_Feed_Synchronization-{8349D560-D684-456B-B276-DD56D090348D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-02 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/ ... module.exe
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex ... 0-27-0.cab
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\
FF - prefs.js: browser.search.selectedEngine - BearShare Web Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/webResults.html?src=ffb&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-22 23:28
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C115AF44-6E90-1295-68F7-04E621200DE6}*]
"bbpakpmpckmggkpnjclblchnbpempejppoeh"=hex:61,62,63,6e,6b,6f,6a,62,64,6c,66,6e,
63,67,62,6e,6a,6e,6f,69,67,63,66,63,65,64,70,63,6e,6b,65,65,6a,69,00,6a
"abpakpmpckmggkpnjceaocimokbagphdpa"=hex:65,62,70,61,64,6b,65,64,70,64,70,67,
70,6b,6e,61,66,61,67,64,61,70,63,6e,6d,66,6d,67,62,65,6f,6d,62,63,69,6a,6b,\

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7e,a2,e9,25,84,93,b2,38,02,ab,76,df,58,e8,8b,e9,cd,be,65,c2,46,0e,9d,
dc,2f,28,71,5e,ab,5f,cf,0c,84,28,7d,ff,c9,39,0b,f3,fb,63,b1,c6,e4,fd,f9,6a,\
"??"=hex:78,09,28,45,b1,92,33,70,86,4e,8b,08,23,8d,cd,82

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Completion time: 2009-09-22 23:31
ComboFix-quarantined-files.txt 2009-09-22 22:31
ComboFix2.txt 2009-09-19 12:45

Pre-Run: 78,679,015,424 bytes free
Post-Run: 78,663,655,424 bytes free

317 --- E O F --- 2009-09-22 10:04
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 22nd, 2009, 6:48 pm

ComboFix 09-09-18.02 - User 22/09/2009 23:20.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1013.283 [GMT 1:00]
Running from: c:\users\User\Desktop\ComboFix.exe
Command switches used :: c:\users\User\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: AVG Anti-Virus *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.

2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\User\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-22 22:28 . 2009-09-22 22:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-19 11:52 . 2009-09-19 11:52 -------- d-----w- c:\programdata\23D1
2009-09-18 18:08 . 2009-09-18 18:09 -------- d-----w- C:\rsit
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2009-09-18 14:01 . 2009-09-22 21:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\programdata\Malwarebytes
2009-09-18 12:35 . 2009-09-18 12:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-12 14:21 . 2009-09-12 14:21 -------- d-----w- c:\users\User\AppData\Roaming\Sony Corporation
2009-09-12 13:48 . 2006-10-30 12:46 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-09-12 13:48 . 2006-10-30 12:46 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-09-12 13:48 . 2006-10-30 12:46 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-09-12 13:48 . 2006-10-30 12:46 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-09-12 13:48 . 2006-10-30 12:46 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
2009-09-12 13:48 . 2009-09-12 13:48 -------- d-----w- C:\Drivers
2009-09-12 13:47 . 2006-11-02 15:57 36624 ----a-w- c:\windows\system32\drivers\pxhelp20.sys
2009-09-12 13:47 . 2006-11-02 15:57 118520 ----a-w- c:\windows\system32\PxInsI64.exe
2009-09-12 13:47 . 2006-08-28 20:48 2560 ----a-w- c:\windows\system32\drivers\cdralw2k.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_xp.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_2k.sys
2009-09-12 13:47 . 2006-10-18 18:43 115960 ----a-w- c:\windows\system32\PxCpyI64.exe
2009-09-12 13:42 . 2009-09-12 13:42 -------- d-----w- c:\program files\Sony
2009-09-10 23:27 . 2009-09-11 00:09 -------- d-----w- c:\users\User\.SunDownloadManager
2009-09-09 23:03 . 2009-09-09 23:03 -------- d-----w- c:\program files\Trend Micro
2009-09-09 16:23 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 16:23 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 16:23 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 16:23 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 16:23 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 16:23 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 16:23 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 16:23 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 16:23 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 16:23 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 16:20 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 16:20 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 16:20 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 16:20 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 16:19 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-02 21:42 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:42 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\users\User\AppData\Local\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\programdata\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\program files\TVUPlayer
2009-08-28 16:10 . 2009-08-28 16:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-26 13:14 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 21:59 . 2009-06-10 17:55 -------- d-----w- c:\programdata\avg8
2009-09-22 21:51 . 2007-09-24 12:56 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-22 12:18 . 2009-06-02 23:29 3308 ----a-w- c:\windows\bthservsdp.dat
2009-09-22 12:06 . 2009-03-25 22:07 -------- d-----w- c:\programdata\Google Updater
2009-09-20 01:24 . 2008-02-15 22:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-09-18 19:25 . 2007-11-04 12:17 -------- d-----w- c:\users\User\AppData\Roaming\uTorrent
2009-09-12 13:51 . 2008-01-15 14:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 12:32 . 2008-02-15 22:06 -------- d-----w- c:\programdata\Yahoo! Companion
2009-09-10 11:15 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 16:37 . 2009-05-25 10:40 -------- d-----w- c:\programdata\DVD Shrink
2009-09-08 16:35 . 2007-12-16 11:37 -------- d-----w- c:\users\User\AppData\Roaming\Vso
2009-08-19 19:05 . 2009-08-19 19:04 -------- d-----w- c:\program files\TVAnts
2009-08-19 15:23 . 2009-08-19 15:23 -------- d-----w- c:\program files\KLC
2009-08-18 17:05 . 2009-08-18 16:59 -------- d-----w- c:\users\User\AppData\Roaming\ImgBurn
2009-08-18 16:54 . 2009-08-18 16:54 -------- d-----w- c:\program files\ImgBurn
2009-08-14 12:37 . 2009-06-10 17:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-14 12:37 . 2009-06-10 17:55 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-14 12:37 . 2009-06-10 17:55 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-28 12:43 . 2009-07-27 19:05 -------- d-----w- c:\programdata\Driving Test Success
2009-07-27 19:05 . 2009-07-27 19:05 -------- d-----w- c:\program files\Driving Test Success 2006-2007
2009-07-25 16:33 . 2009-07-25 16:33 -------- d-----w- c:\program files\DVD Decrypter
2009-07-18 16:06 . 2009-07-29 21:26 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-29 21:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-29 21:26 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-14 12:58 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-14 12:57 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-14 12:57 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-14 12:57 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-14 12:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\23D1 ----

2009-09-19 11:52 . 2009-07-07 14:19 2329 ----a-w- c:\programdata\23D1\{B08BDCB2-5017-4C09-905C-C5ECECF75103}.swf

---- Directory of c:\programdata\532F ----



((((((((((((((((((((((((((((( SnapShot@2009-09-19_12.37.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-09-24 15:29 . 2009-09-22 21:43 56924 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-22 21:43 78216 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-09-24 12:49 . 2009-09-22 21:43 15422 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2556230271-85685182-2986242697-1000_UserData.bin
- 2006-11-02 13:02 . 2009-09-19 12:13 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 21:45 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-22 21:41 . 2009-09-22 21:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-22 21:41 . 2009-09-22 21:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 608706 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 608706 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 109542 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 109542 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-02 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-20 148888]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1021224]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-29 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-29 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-29 133656]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2022680]

c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-9-12 344064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{012EF020-255B-44F2-8E33-F7C236857C4A}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= UDP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"UDP Query User{D7CE9476-2296-43C1-8206-9D9CCAA882FF}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= TCP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"TCP Query User{83DA906D-59CF-43FB-8ED1-D84476250BFD}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{7FD13365-BB45-43F9-81CB-013B981E9C98}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"TCP Query User{EC39B7C4-597E-41A5-BA17-C7A94678EEA0}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{CDEF6486-0AEA-4CD2-B3D3-B7FE03050800}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{34AAE61B-0CEB-4E8B-A313-121A96210DC4}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{1E811BF8-3786-4141-81EC-075886A82B9B}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"{E89967B3-5ED3-45CB-802C-B1C77E417BC1}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{0B859C1B-88FE-45DE-B80F-415D2128176A}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7041346C-5461-4D14-B6D6-FC7947D2F31A}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{20580FE6-6571-431B-94BA-1D8DF1D808CA}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{7C6FE02A-D346-4A97-A601-96501B65573A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E6DEF23E-BA42-4334-9003-B5C87EB82F20}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7FBE0A73-CC67-49DA-9829-A64C5A229F40}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{00E5DFDA-1D3E-4E1B-9C3C-72246BD6FE19}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{FBE54612-A155-4ED5-8753-7184E5EB45E2}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{94341170-8A0B-47E6-8A9F-5DE623E288BB}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{59F91452-3DED-4D86-A2A9-9C34084D5426}c:\\windows\\system32\\rsezmk.exe"= UDP:c:\windows\system32\rsezmk.exe:rsezmk
"UDP Query User{432C9CC9-CBA4-4FB8-B20C-047A7415E3C3}c:\\windows\\system32\\rsezmk.exe"= TCP:c:\windows\system32\rsezmk.exe:rsezmk
"{E471893F-2CD1-4F9E-8691-0276744EA04B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{AA1A4689-684E-40FA-A0F4-6B55CD6E3B9E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{06C73D32-9DE8-497C-ADB2-786292A7CD0C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{06EA8901-9D67-49E4-B20D-5205E2638FB3}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{95068D88-C2E6-421C-9855-506D4389EA62}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{742B496E-65E1-48C9-8142-94D9528052CA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E007E5C1-8FB2-4379-8AFB-6D2ABA613CA9}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{91515220-D4A3-4984-93D3-35FC7D95CF58}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{F6E0A41F-42A0-4EF7-8BD9-1C090BF81945}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{B99D60D0-D6BC-42A2-8C64-055CF3B6FFF1}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{D3F6570E-E718-409D-AE30-D32AB803319E}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{862FD8CA-9431-48B2-BC43-01DE6890011F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{197BF7A8-E8FB-4797-875C-4AFD07F7D3EB}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{1645673B-1CE4-4557-9380-669252860C5D}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{9F8F7FA4-C473-4BBD-9459-C413B2F21CE6}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"TCP Query User{7E662504-E605-45C4-A235-4CA3C1282A7E}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{0FE02598-F776-4BC6-95D1-F96BEEA28A2F}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{C4951CB8-902E-4928-BDE2-1C942C51BFB7}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{7360A712-0467-451B-8997-49059E776F0D}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{1539EED6-B2F5-4E38-97EF-7E030041A9BA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{398D87C3-9BEB-4CE1-8F47-4CB46922A9BC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{21D81B62-1FA0-4B53-A48A-F22D66A4CA74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{00644132-EB98-405E-A653-E1267508DCF0}"= Disabled:UDP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{4EC35746-1028-4FF8-83D1-A5E05E6BE7AD}"= Disabled:TCP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{0828C2C2-7F10-4319-9C08-D4A2BE5E46B3}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FE658A9D-7A31-40BB-9B87-09046AD0CABD}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BB125485-24C3-46FC-AA38-E2D0A97896A2}"= Disabled:c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{6F414882-F2FC-4C70-B0B7-EF53E2B25C46}"= Disabled:c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{5E829439-5FA3-48EE-B0E5-52B6D6E4BB2F}"= Disabled:c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{CD903931-2A4B-4A99-B232-8550589EF3D0}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{258A4B77-A6B8-4224-B0EB-4C54A8D6C7FF}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{5245D0F1-FC93-4824-A59B-261B485618E2}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{663CED64-0635-4691-9114-7F7F83F5987D}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{185F2579-F7F3-44B1-BCDB-E8E5D129908B}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:UDP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{B104C8A3-075D-41F9-A497-3120C45F26EF}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:TCP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [10/06/2009 18:55 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/06/2009 18:55 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/06/2009 18:55 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/06/2009 20:37 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [18/09/2009 13:35 1153368]
S3 bthav;Bluetooth AV Profile;c:\windows\System32\drivers\bthav.sys [10/07/2008 15:43 34816]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [10/07/2008 15:43 15872]
S3 Flash1;Flash1;c:\program files\SP39371\winphlash\FLASH1.sys [01/03/2006 17:54 3456]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [28/06/2008 11:12 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [28/06/2008 11:12 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [28/06/2008 11:12 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [28/06/2008 11:12 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [28/06/2008 11:12 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [28/06/2008 11:12 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [28/06/2008 11:12 110120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-09-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-28 22:06]

2009-09-22 c:\windows\Tasks\User_Feed_Synchronization-{8349D560-D684-456B-B276-DD56D090348D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-02 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/ ... module.exe
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex ... 0-27-0.cab
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\
FF - prefs.js: browser.search.selectedEngine - BearShare Web Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/webResults.html?src=ffb&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-22 23:28
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C115AF44-6E90-1295-68F7-04E621200DE6}*]
"bbpakpmpckmggkpnjclblchnbpempejppoeh"=hex:61,62,63,6e,6b,6f,6a,62,64,6c,66,6e,
63,67,62,6e,6a,6e,6f,69,67,63,66,63,65,64,70,63,6e,6b,65,65,6a,69,00,6a
"abpakpmpckmggkpnjceaocimokbagphdpa"=hex:65,62,70,61,64,6b,65,64,70,64,70,67,
70,6b,6e,61,66,61,67,64,61,70,63,6e,6d,66,6d,67,62,65,6f,6d,62,63,69,6a,6b,\

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7e,a2,e9,25,84,93,b2,38,02,ab,76,df,58,e8,8b,e9,cd,be,65,c2,46,0e,9d,
dc,2f,28,71,5e,ab,5f,cf,0c,84,28,7d,ff,c9,39,0b,f3,fb,63,b1,c6,e4,fd,f9,6a,\
"??"=hex:78,09,28,45,b1,92,33,70,86,4e,8b,08,23,8d,cd,82

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Completion time: 2009-09-22 23:31
ComboFix-quarantined-files.txt 2009-09-22 22:31
ComboFix2.txt 2009-09-19 12:45

Pre-Run: 78,679,015,424 bytes free
Post-Run: 78,663,655,424 bytes free

317 --- E O F --- 2009-09-22 10:04
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 22nd, 2009, 6:57 pm

here is the file_for_submission.zip
You do not have the required permissions to view the files attached to this post.
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 22nd, 2009, 7:19 pm

ComboFix 09-09-18.02 - User 23/09/2009 0:01.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1013.301 [GMT 1:00]
Running from: c:\users\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: AVG Anti-Virus *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.

2009-09-22 23:10 . 2009-09-22 23:10 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-09-22 23:10 . 2009-09-22 23:10 -------- d-----w- c:\users\User\AppData\Local\temp
2009-09-22 23:10 . 2009-09-22 23:10 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-22 23:10 . 2009-09-22 23:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-19 11:52 . 2009-09-19 11:52 -------- d-----w- c:\programdata\23D1
2009-09-18 18:08 . 2009-09-18 18:09 -------- d-----w- C:\rsit
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\programdata\Malwarebytes
2009-09-18 12:35 . 2009-09-18 12:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-12 14:21 . 2009-09-12 14:21 -------- d-----w- c:\users\User\AppData\Roaming\Sony Corporation
2009-09-12 13:48 . 2006-10-30 12:46 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-09-12 13:48 . 2006-10-30 12:46 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-09-12 13:48 . 2006-10-30 12:46 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-09-12 13:48 . 2006-10-30 12:46 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-09-12 13:48 . 2006-10-30 12:46 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
2009-09-12 13:48 . 2009-09-12 13:48 -------- d-----w- C:\Drivers
2009-09-12 13:47 . 2006-11-02 15:57 36624 ----a-w- c:\windows\system32\drivers\pxhelp20.sys
2009-09-12 13:47 . 2006-11-02 15:57 118520 ----a-w- c:\windows\system32\PxInsI64.exe
2009-09-12 13:47 . 2006-08-28 20:48 2560 ----a-w- c:\windows\system32\drivers\cdralw2k.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_xp.sys
2009-09-12 13:47 . 2006-08-28 20:48 2432 ----a-w- c:\windows\system32\drivers\cdr4_2k.sys
2009-09-12 13:47 . 2006-10-18 18:43 115960 ----a-w- c:\windows\system32\PxCpyI64.exe
2009-09-12 13:42 . 2009-09-12 13:42 -------- d-----w- c:\program files\Sony
2009-09-10 23:27 . 2009-09-11 00:09 -------- d-----w- c:\users\User\.SunDownloadManager
2009-09-09 23:03 . 2009-09-09 23:03 -------- d-----w- c:\program files\Trend Micro
2009-09-09 16:23 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 16:23 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 16:23 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 16:23 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 16:23 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 16:23 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 16:23 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 16:23 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 16:23 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 16:23 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 16:20 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 16:20 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 16:20 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 16:20 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 16:19 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-02 21:42 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:42 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\users\User\AppData\Local\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\programdata\TVU Networks
2009-08-29 14:12 . 2009-08-29 14:12 -------- d-----w- c:\program files\TVUPlayer
2009-08-28 16:10 . 2009-08-28 16:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-26 13:14 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 22:41 . 2009-06-02 23:29 3308 ----a-w- c:\windows\bthservsdp.dat
2009-09-22 21:59 . 2009-06-10 17:55 -------- d-----w- c:\programdata\avg8
2009-09-22 21:51 . 2007-09-24 12:56 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-22 12:06 . 2009-03-25 22:07 -------- d-----w- c:\programdata\Google Updater
2009-09-20 01:24 . 2008-02-15 22:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-09-18 19:25 . 2007-11-04 12:17 -------- d-----w- c:\users\User\AppData\Roaming\uTorrent
2009-09-12 13:51 . 2008-01-15 14:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 12:32 . 2008-02-15 22:06 -------- d-----w- c:\programdata\Yahoo! Companion
2009-09-10 11:15 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 16:37 . 2009-05-25 10:40 -------- d-----w- c:\programdata\DVD Shrink
2009-09-08 16:35 . 2007-12-16 11:37 -------- d-----w- c:\users\User\AppData\Roaming\Vso
2009-08-19 19:05 . 2009-08-19 19:04 -------- d-----w- c:\program files\TVAnts
2009-08-19 15:23 . 2009-08-19 15:23 -------- d-----w- c:\program files\KLC
2009-08-18 17:05 . 2009-08-18 16:59 -------- d-----w- c:\users\User\AppData\Roaming\ImgBurn
2009-08-18 16:54 . 2009-08-18 16:54 -------- d-----w- c:\program files\ImgBurn
2009-08-14 12:37 . 2009-06-10 17:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-14 12:37 . 2009-06-10 17:55 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-14 12:37 . 2009-06-10 17:55 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-28 12:43 . 2009-07-27 19:05 -------- d-----w- c:\programdata\Driving Test Success
2009-07-27 19:05 . 2009-07-27 19:05 -------- d-----w- c:\program files\Driving Test Success 2006-2007
2009-07-25 16:33 . 2009-07-25 16:33 -------- d-----w- c:\program files\DVD Decrypter
2009-07-18 16:06 . 2009-07-29 21:26 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-29 21:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-29 21:26 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-14 12:58 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-14 12:57 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-14 12:57 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-14 12:57 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-14 12:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.

((((((((((((((((((((((((((((( SnapShot@2009-09-19_12.37.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-09-24 15:29 . 2009-09-22 22:44 56940 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-22 22:44 78216 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-09-24 12:49 . 2009-09-22 22:44 15422 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2556230271-85685182-2986242697-1000_UserData.bin
- 2006-11-02 13:02 . 2009-09-19 12:13 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-09-22 22:50 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 22:50 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-22 22:50 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-19 12:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-22 22:42 . 2009-09-22 22:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-19 12:35 . 2009-09-19 12:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-22 22:42 . 2009-09-22 22:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 608706 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 608706 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-19 19:48 109542 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-09-14 22:51 109542 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-02 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-20 148888]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1021224]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-29 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-29 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-29 133656]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2022680]

c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-9-12 344064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{012EF020-255B-44F2-8E33-F7C236857C4A}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= UDP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"UDP Query User{D7CE9476-2296-43C1-8206-9D9CCAA882FF}c:\\users\\user\\appdata\\local\\temp\\cry800.tmp\\install.exe"= TCP:c:\users\user\appdata\local\temp\cry800.tmp\install.exe:install.exe
"TCP Query User{83DA906D-59CF-43FB-8ED1-D84476250BFD}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{7FD13365-BB45-43F9-81CB-013B981E9C98}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"TCP Query User{EC39B7C4-597E-41A5-BA17-C7A94678EEA0}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{CDEF6486-0AEA-4CD2-B3D3-B7FE03050800}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{34AAE61B-0CEB-4E8B-A313-121A96210DC4}c:\\program files\\william hill poker\\ua.exe"= UDP:c:\program files\william hill poker\ua.exe:UA Application
"UDP Query User{1E811BF8-3786-4141-81EC-075886A82B9B}c:\\program files\\william hill poker\\ua.exe"= TCP:c:\program files\william hill poker\ua.exe:UA Application
"{E89967B3-5ED3-45CB-802C-B1C77E417BC1}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{0B859C1B-88FE-45DE-B80F-415D2128176A}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7041346C-5461-4D14-B6D6-FC7947D2F31A}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{20580FE6-6571-431B-94BA-1D8DF1D808CA}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{7C6FE02A-D346-4A97-A601-96501B65573A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E6DEF23E-BA42-4334-9003-B5C87EB82F20}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7FBE0A73-CC67-49DA-9829-A64C5A229F40}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{00E5DFDA-1D3E-4E1B-9C3C-72246BD6FE19}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{FBE54612-A155-4ED5-8753-7184E5EB45E2}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{94341170-8A0B-47E6-8A9F-5DE623E288BB}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{59F91452-3DED-4D86-A2A9-9C34084D5426}c:\\windows\\system32\\rsezmk.exe"= UDP:c:\windows\system32\rsezmk.exe:rsezmk
"UDP Query User{432C9CC9-CBA4-4FB8-B20C-047A7415E3C3}c:\\windows\\system32\\rsezmk.exe"= TCP:c:\windows\system32\rsezmk.exe:rsezmk
"{E471893F-2CD1-4F9E-8691-0276744EA04B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{AA1A4689-684E-40FA-A0F4-6B55CD6E3B9E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{06C73D32-9DE8-497C-ADB2-786292A7CD0C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{06EA8901-9D67-49E4-B20D-5205E2638FB3}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{95068D88-C2E6-421C-9855-506D4389EA62}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{742B496E-65E1-48C9-8142-94D9528052CA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E007E5C1-8FB2-4379-8AFB-6D2ABA613CA9}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{91515220-D4A3-4984-93D3-35FC7D95CF58}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{F6E0A41F-42A0-4EF7-8BD9-1C090BF81945}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{B99D60D0-D6BC-42A2-8C64-055CF3B6FFF1}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{D3F6570E-E718-409D-AE30-D32AB803319E}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{862FD8CA-9431-48B2-BC43-01DE6890011F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{197BF7A8-E8FB-4797-875C-4AFD07F7D3EB}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{1645673B-1CE4-4557-9380-669252860C5D}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{9F8F7FA4-C473-4BBD-9459-C413B2F21CE6}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"TCP Query User{7E662504-E605-45C4-A235-4CA3C1282A7E}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{0FE02598-F776-4BC6-95D1-F96BEEA28A2F}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{C4951CB8-902E-4928-BDE2-1C942C51BFB7}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{7360A712-0467-451B-8997-49059E776F0D}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{1539EED6-B2F5-4E38-97EF-7E030041A9BA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{398D87C3-9BEB-4CE1-8F47-4CB46922A9BC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{21D81B62-1FA0-4B53-A48A-F22D66A4CA74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{00644132-EB98-405E-A653-E1267508DCF0}"= Disabled:UDP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{4EC35746-1028-4FF8-83D1-A5E05E6BE7AD}"= Disabled:TCP:c:\users\User\Desktop\fm.exe:Football Manager 2008
"{0828C2C2-7F10-4319-9C08-D4A2BE5E46B3}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FE658A9D-7A31-40BB-9B87-09046AD0CABD}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BB125485-24C3-46FC-AA38-E2D0A97896A2}"= Disabled:c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{6F414882-F2FC-4C70-B0B7-EF53E2B25C46}"= Disabled:c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{5E829439-5FA3-48EE-B0E5-52B6D6E4BB2F}"= Disabled:c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{CD903931-2A4B-4A99-B232-8550589EF3D0}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{258A4B77-A6B8-4224-B0EB-4C54A8D6C7FF}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{5245D0F1-FC93-4824-A59B-261B485618E2}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{663CED64-0635-4691-9114-7F7F83F5987D}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{185F2579-F7F3-44B1-BCDB-E8E5D129908B}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:UDP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{B104C8A3-075D-41F9-A497-3120C45F26EF}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= Disabled:TCP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [10/06/2009 18:55 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/06/2009 18:55 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/06/2009 18:55 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/06/2009 20:37 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [18/09/2009 13:35 1153368]
S3 bthav;Bluetooth AV Profile;c:\windows\System32\drivers\bthav.sys [10/07/2008 15:43 34816]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [10/07/2008 15:43 15872]
S3 Flash1;Flash1;c:\program files\SP39371\winphlash\FLASH1.sys [01/03/2006 17:54 3456]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [28/06/2008 11:12 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [28/06/2008 11:12 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [28/06/2008 11:12 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [28/06/2008 11:12 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [28/06/2008 11:12 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [28/06/2008 11:12 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [28/06/2008 11:12 110120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-09-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-28 22:06]

2009-09-22 c:\windows\Tasks\User_Feed_Synchronization-{8349D560-D684-456B-B276-DD56D090348D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-02 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/ ... module.exe
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex ... 0-27-0.cab
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\
FF - prefs.js: browser.search.selectedEngine - BearShare Web Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/webResults.html?src=ffb&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\g55tcjn2.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C115AF44-6E90-1295-68F7-04E621200DE6}*]
"bbpakpmpckmggkpnjclblchnbpempejppoeh"=hex:61,62,63,6e,6b,6f,6a,62,64,6c,66,6e,
63,67,62,6e,6a,6e,6f,69,67,63,66,63,65,64,70,63,6e,6b,65,65,6a,69,00,6a
"abpakpmpckmggkpnjceaocimokbagphdpa"=hex:65,62,70,61,64,6b,65,64,70,64,70,67,
70,6b,6e,61,66,61,67,64,61,70,63,6e,6d,66,6d,67,62,65,6f,6d,62,63,69,6a,6b,\

[HKEY_USERS\S-1-5-21-2556230271-85685182-2986242697-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7e,a2,e9,25,84,93,b2,38,02,ab,76,df,58,e8,8b,e9,cd,be,65,c2,46,0e,9d,
dc,2f,28,71,5e,ab,5f,cf,0c,84,28,7d,ff,c9,39,0b,f3,fb,63,b1,c6,e4,fd,f9,6a,\
"??"=hex:78,09,28,45,b1,92,33,70,86,4e,8b,08,23,8d,cd,82

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Completion time: 2009-09-22 0:12
ComboFix-quarantined-files.txt 2009-09-22 23:12
ComboFix2.txt 2009-09-22 22:31
ComboFix3.txt 2009-09-19 12:45

Pre-Run: 78,815,637,504 bytes free
Post-Run: 78,759,391,232 bytes free

308 --- E O F --- 2009-09-22 10:04
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby deemon » September 22nd, 2009, 7:20 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:06, on 18/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\User\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\User.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=70001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [iowmjosoi] rundll32.exe "C:\Users\User\AppData\Roaming\hmcencx.dll",bpbudske
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Custo ... anager.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/ ... module.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resourc ... den-gb.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex ... 0-27-0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - http://www.spvod.com/soft/vjocx-ch-spvod.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10533 bytes
deemon
Regular Member
 
Posts: 79
Joined: August 1st, 2007, 3:17 pm

Re: help plz i have trojan horse proxy. AHIY

Unread postby muppy03 » September 22nd, 2009, 11:12 pm

Hi there,

The file for submission is to be uploaded to the link I gave you, (click the word ‘here’ in the post explaining what to do)

Is there a reason you ran Combofix the third time?

Also, can I have an update on the computer. Are you still having the same problem with opening programs from the desktop?
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4782
Joined: December 4th, 2007, 5:30 am
Location: Australia
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 33 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware