|
|
#1 (permalink) |
|
Bronze Member
![]() Join Date: Jan 2008
Location: NY, NY
Posts: 93
|
OK where do I start? I am going to have to make some confessions here and I assume there are some people who might want to help me and others who will judge me quite harshly. They might consider my situation well deserved. What can I say? I'm a bad person for BT-ing. Yes, I engage in this behavior. I was turned on by a certain someone and now I'm a BIT addicted. It's quite Torren-tial indeed. Anyway, I was trying to find keygens for Norton, duplicate email removing, avi converter for my ipod and a couple of other things. UHM, now...Norton hasn't reported any problems, however, AVAST is raging with trojan warnings.
Can anyone help me? Does anyone WANT to help me? ![]() Last edited by Hey it's me; 03-16-2008 at 12:31 AM. |
|
|
|
|
|
#2 (permalink) | |
|
Diamond Member
![]() Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,854
|
Yes, hello!
Click here to download HJTsetup.exe
__________________
dznutz: Quote:
|
|
|
|
|
|
|
#6 (permalink) | |
|
Diamond Member
![]() Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,854
|
OK, that definetely means you have some Trojans.
Download SDFix and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following :
(If you can't install it in normal mode, try to do it in safe mode ).
__________________
dznutz: Quote:
|
|
|
|
|
|
|
#7 (permalink) |
|
Bronze Member
![]() Join Date: Jan 2008
Location: NY, NY
Posts: 93
|
Avast detected like FIVE Trojans and I allowed them to be placed in "THE CHEST" of AVAST. I'm going to start another scan with avast while I await some news from you Oh great GAME MASTER. I am now ON my computer (where's as up till now I've been out and about in the world). I will be looking for your directions from now on often.
Thanks for the help. ![]() OK so, here is a report generated by SDFix. System Report ************* Run on Mon 03/17/2008 at 04:31 PM Microsoft Windows XP [Version 5.1.2600] Current user is an administrator Running Processes: \SystemRoot\System32\smss.exe [156] \??\C:\WINDOWS\system32\csrss.exe [204] \??\C:\WINDOWS\system32\winlogon.exe [228] C:\WINDOWS\system32\services.exe [272] C:\WINDOWS\system32\lsass.exe [284] C:\WINDOWS\system32\svchost.exe [444] C:\WINDOWS\system32\svchost.exe [504] C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [560] C:\WINDOWS\system32\svchost.exe [632] Drivers - Running: ACPI Afc atapi Beep catchme Cdfs Cdrom Disk dmboot dmio dmload FltMgr Ftdisk GEARAspiWDM HDAudBus HidUsb i2omgmt Imapi isapnp Kbdclass kbdhid KSecDD Mouclass mouhid MountMgr Msfs mssmbios Mup NDIS Npfs Ntfs Null PartMgr PCI PCIIde pfc PxHelp20 rdpdr redbook sr swenum TermDD Update usbehci usbhub usbuhci VgaSave VolSnap Drivers - Stopped: Aavmker4 Abiosdsk abp480n5 ACPIEC adpu160m aec AFD agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 aswMon2 aswRdr aswTdi AsyncMac Atdisk Atmarpc audstub BOCDRIVE bvrp_pci cbidf cbidf2k CCDECODE cd20xrnt Cdaudio cercsr6 Changer CmdIde COH_Mon Cpqarray CxLPT dac2w2k dac960nt DMusic dpti2o drmkaud E100B eeCtrl EraserUtilRebootDrv Fastfat Fdc Fips Flpydisk Gpc hpn HTTP i2omp i8042prt ialm ini910u IntelC51 IntelC52 IntelC53 IntelIde intelppm Ip6Fw IpFilterDriver IpInIp IpNat IPSec IRENUM Jukebox kmixer lbrtfdc MHNDRV mnmdd Modem MODEMCSA mohfilt mraid35x MRxDAV MRxSmb MSKSSRV MSPCLOCK MSPQM MSTEE NABTSFEC NAVENG NAVEX15 NdisIP NdisTapi Ndisuio NdisWan NDProxy NetBIOS NetBT nv NwlnkFlt NwlnkFwd P0630VID Parport ParVdm PCIDump Pcmcia PDCOMP PDFRAME PDRELI PDRFRAME perc2 perc2hib PptpMiniport PSched Ptilink ql1080 Ql10wnt ql12160 ql1240 ql1280 RasAcd Rasl2tp RasPppoe Raspti Rdbss RDPCDD RDPWD ROOTMODEM SASDIFSV SASENUM SASKUTIL Secdrv Ser2pl serenum Serial Sfloppy Simbad sisagp SLIP Sparrow SPBBCDrv splitter SRTSP SRTSPL SRTSPX Srv STHDA streamip swmidi symc810 symc8xx SYMDNS SymEvent SYMFW SYMIDS SYMIDSCO SymIM SymIMMP SYMNDIS SYMREDRV SYMTDI sym_hi sym_u3 sysaudio Tcpip TDPIPE TDTCP tmcomm TosIde Udfs ultra USBAAPL usbccgp usbprint usbscan usbser usbsermpt USBSTOR viaagp ViaIde Wanarp wanatw WDICA wdmaud WSTCODEC Services - Running: aawservice CryptSvc DcomLaunch dmserver Eventlog helpsvc PlugPlay RpcSs srservice winmgmt Services - Stopped: Alerter ALG Apple AppMgmt aspnet_state aswUpdSv AudioSrv Automatic avast! avast! avast! BITS BOCore Browser ccEvtMgr ccSetMgr CiSvc ClipSrv clr_optimization_v2.0.50727_32 CLTNetCnService COMSysApp Dhcp dmadmin Dnscache ehRecvr ehSched ERSvc EventSystem FastUserSwitchingCompatibility Fax HidServ HTTPFilter IDriverT ImapiService iPod lanmanserver lanmanworkstation LiveUpdate LiveUpdate LmHosts Messenger MHN mnmsrvc MSDTC MSIServer NetDDE NetDDEdsdm Netlogon Netman NetSvc Nla NMSAccessU NtLmSsp NtmsSvc ose PolicyAgent ProtectedStorage RasAuto RasMan RDSessMgr RemoteAccess RemoteRegistry RpcLocator RSVP SamSs SCardSvr Schedule seclogon SENS SharedAccess ShellHWDetection Spooler SSDPSRV stisvc SwPrv Symantec SysmonLog TapiSrv TermService Themes TlntSvr TrkWks UMWdf upnphost UPS usnjsvc VSS w32time WebClient WmdmPmSN Wmi WmiApSrv wscsvc wuauserv WZCSVC xmlprov Files Created/Modified - 60 Days: C:\ C:\WINDOWS\ C:\Program Files\ Files with hidden attributes: Catchme: catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-17 16:24:25 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... IPC error: 2 The system cannot find the file specified. scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Program Folders: C:\Program Files\ AIM6 Apple Software Update ArcSoft Avast4 Azureus CCleaner Common Files Comodo ComPlus Applications Creative CyberLink Dell Dell Inc Dell Support epson Eusing Free Registry Cleaner FireTrust Flash Foxit Software Grisoft iDumpPro InstallShield Installation Information Intel Internet Explorer iPod itunes Jasc Software Inc Java Lavasoft MAPILab Ltd Messenger MetaStream Microsoft ActiveSync Microsoft CAPICOM 2.1.0.2 microsoft frontpage Microsoft Office Microsoft Plus! Digital Media Edition Microsoft Plus! Photo Story 2 LE Microsoft.NET Modem Helper Modem On Hold Motorola Phone Tools Movie Maker Mozilla Firefox MSECACHE MSN MSN Gaming Zone MSN Messenger MySpace NetMeeting Norton AntiVirus Online Services Outlook Express Quickbooks QuickTime Real RGB Sigmatel Skype SmitfraudFix Sonic Soulseek Spybot - Search & Destroy StickerPIX SUPERAntiSpyware Symantec Trend Micro Uninstall Information uTorrent Video Converters VideoLAN Viewpoint Windows Media Player Windows NT Windows Plus Windows Sidebar WindowsUpdate WinRAR WordPerfect Office 12 xerox C:\Program Files\Common Files\ Adobe AOL Apple ArcSoft Borland Shared Corel DESIGNER DVDVideoSoft InstallShield Intuit Jasc Software Inc Java MAPILab Ltd Microsoft Shared MSSoap Nikon Nullsoft ODBC Real Services Skype Sonic Shared SpeechEngines SWF Studio Symantec Shared System Wise Installation Wizard xing shared Add/Remove Programs: Adobe Flash Player Plugin AIM 6 avast! Antivirus BOClean Creative WebCam Live! Driver (1.01.01.0730) Creative WebCam Center Dell Digital Jukebox Driver Dell DJ Explorer EPSON Printer Software EPSON Scan Eusing Free Registry Cleaner Foxit PDF Editor Foxit Reader Free YouTube to iPod Converter version 2.8 iDump Build: 24 iDumpPro Intel(R) 537EP V9x DF PCI Modem Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows XP Media Center Edition 2005 KB895198 Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for CAPICOM (KB931906) Microsoft .NET Framework 1.1 Hotfix (KB928366) Macromedia Shockwave Player MailWasher Pro Update Rollup 1 for Windows XP Media Center Edition 2005 with HDTV Support (KB873369) MemObj Microsoft .NET Framework 1.1 Mozilla Firefox (2.0.0.12) Intel(R) PRO Network Connections Drivers LiveUpdate (Symantec Corporation) RealPlayer Adobe Flash Player 9 ActiveX EPSON CX8400 User's Guide SoulSeek Client 156c StickerPIX Norton AntiVirus (Symantec Corporation) Viewpoint Media Player VideoLAN VLC media player 0.8.6c Windows Genuine Advantage Validation Tool (KB892130) Windows Genuine Advantage Notifications (KB905474) Windows Media Format Runtime Windows Media Player 10 WinRAR archiver Macromedia Flash Player Sonic RecordNow Data ArcSoft Print Creations Microsoft Plus! Photo Story 2 LE Security Update for CAPICOM (KB931906) Qualxserve Service Agreement Sonic DLA EPSON Stylus CX8400 Series Scanner Driver Update SymNet Sonic Update Manager Component Framework Java(TM) SE Runtime Environment 6 Update 1 Java(TM) 6 Update 2 Java(TM) 6 Update 3 Windows Media Player 10 Norton AntiVirus Help Internet Explorer Default Page MSXML 4.0 SP2 (KB927978) Modem On Hold Dell Support 3.1 Windows Live Messenger Dell Driver Reset Tool Skype™ 3.6 Norton Protection Center AOLIcon Windows Genuine Advantage v1.3.0254.0 PowerDVD 5.5 Digital Content Portal Microsoft Plus! Digital Media Edition Installer QuickTime Java 2 Runtime Environment, SE v1.4.2_03 Microsoft Visual C++ 2005 Redistributable Dell System Restore SPBBC 32bit Norton AntiVirus Modem Event Monitor Duplicate Email Remover Modem Helper Intel(R) PROSet for Wired Connections Microsoft Silverlight Intel(R) Graphics Media Accelerator Driver Microsoft Office Professional Edition 2003 Sonic Encoders Windows Messenger 5.1 EducateU Sonic RecordNow Audio Dell Picture Studio v3.0 WordPerfect Office 12 Sonic RecordNow Copy ccCommon Microsoft .NET Framework 2.0 Service Pack 1 Apple Software Update iTunes Motorola Phone Tools MSXML 4.0 SP2 (KB936181) Microsoft .NET Framework 1.1 ArcSoft PhotoImpression 6 Symantec Real Time Storage Protection Component Apple Mobile Device Support ArcSoft Multimedia Email Ad-Aware 2007 LiveUpdate (Symantec Corporation) Windows Rights Management Client Backwards Compatibility ArcSoft Software Suite AppCore Jasc Paint Shop Pro 9 ArcSoft PhotoImpression 5 µTorrent |
|
|
|
|
|
#8 (permalink) |
|
Bronze Member
![]() Join Date: Jan 2008
Location: NY, NY
Posts: 93
|
This report was too long for one posting. so....
Run Values: [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run] "avast!"="C:\\PROGRA~1\\Avast4\\ALWILS~1\\ashDisp. exe" "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.ex e" "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe" "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.ex e" "SigmatelSysTrayApp"="stsystra.exe" "ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "osCheck"="\"C:\\Program Files\\Norton AntiVirus\\osCheck.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MSFS] "Installed"="1" Bot Check: SERVICE_NAME: wscsvc DISPLAY_NAME : Security Center START_TYPE : 4 DISABLED SERVICE_NAME: sharedaccess DISPLAY_NAME : Windows Firewall/Internet Connection Sharing (ICS) START_TYPE : 2 AUTO_START SERVICE_NAME: wuauserv DISPLAY_NAME : Automatic Updates START_TYPE : 2 AUTO_START SERVICE_NAME: srservice DISPLAY_NAME : System Restore Service START_TYPE : 2 AUTO_START [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole] "EnableDCOM"="Y" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Lsa] "restrictanonymous"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update] "AUOptions"=dword:00000004 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify"=dword:00000000 "FirewallDisableNotify"=dword:00000000 "UpdatesDisableNotify"=dword:00000000 "AntiVirusOverride"=dword:00000000 "FirewallOverride"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "WaitToKillServiceTimeout"="20000" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "SFCDisable"=dword:00000000 "Shell"="Explorer.exe" "Userinit"="C:\\WINDOWS\\system32\\userinit.ex e," [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\shell extensions] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\NetBT\Parameters] "TransportBindName"="\\Device\\" ShellExecuteHooks: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="" "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" Environment: HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager\environment ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\sy stem32\WBEM;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\ windir REG_EXPAND_SZ %SystemRoot% OS REG_SZ Windows_NT PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH TEMP REG_EXPAND_SZ %SystemRoot%\TEMP TMP REG_EXPAND_SZ %SystemRoot%\TEMP SonicCentral REG_SZ C:\Program Files\Common Files\Sonic Shared\Sonic Central\ CLASSPATH REG_SZ .;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip QTJAVA REG_SZ C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip SAFEBOOT_OPTION REG_SZ MINIMAL SecurityProviders: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SecurityProviders SecurityProviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll Authentication Packages: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Subsystem Startup: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Session Manager\SubSystems] "Windows"="%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16" Midi Drivers: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midi"="wdmaud.drv" Non-Default IFEO Debugger: HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360safe.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\agentsvr.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\appsvc32.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\auto.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autorun.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avmonitor.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccenter.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccsvchst.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\cross.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\discovery.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\filedsty.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ftcleanershell.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\guangd.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\hijackthis.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\icesword.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmor.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ispwdsvc.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kascrscn.scr Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kasmain.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kastask.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kav32.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavdx.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavpfw.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavsetup.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavstart.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kislnchr.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kmailmon.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kmfilter.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kpfw32.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kpfw32x.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kpfwsvc.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kregex.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\krepair.com Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ksloader.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvcenter.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvdetect.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvfwmcl.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvmonxp.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvmonxp_1.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvreport.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvsrvxp.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvstub.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvxp.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kwatch.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kwatch9x.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kwatchx.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\magicset.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\navsetup.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\pfw.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\pfwliveupdate.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\qhset.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ras.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rav.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravmon.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravmond.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravstub.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravtask.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regclean.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwmain.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwproxy.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rsagent.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rsaupd.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sdgames.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\servet.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shuiniu.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\smartup.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sos.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sreng.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\svch0st.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\syssafe.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\systom.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\tnt.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\trojandetector.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\trojanwall.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\trojdie.kxp Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\txomou.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ufo.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\uihost.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\umxagent.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\umxattachment.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\umxcfg.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\umxfwhlp.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\umxpol.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\uplive.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\wopticlean.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\wsyscheck.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\xp.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zxsweep.exe Debugger REG_SZ C:\WINDOWS\system32\Flower.exe Non-Default Installed Components: Non-Default Safeboot Minimal: HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\safeboot\minimal\aawservice <NO NAME> REG_SZ Service File Associations: [HKEY_CLASSES_ROOT\batfile\shell\open\command] @="\"%1\" %*" [HKEY_CLASSES_ROOT\cmdfile\shell\open\command] @="\"%1\" %*" [HKEY_CLASSES_ROOT\comfile\shell\open\command] @="\"%1\" %*" [HKEY_CLASSES_ROOT\exefile\shell\open\command] @="\"%1\" %*" [HKEY_CLASSES_ROOT\htafile\shell\open\command] @="C:\\WINDOWS\\system32\\mshta.exe \"%1\" %*" [HKEY_CLASSES_ROOT\htmlfile\shell\open\command] @="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome" [HKEY_CLASSES_ROOT\regedit\shell\open\command] @="regedit.exe %1" [HKEY_CLASSES_ROOT\regfile\shell\open\command] @="regedit.exe \"%1\"" [HKEY_CLASSES_ROOT\scrfile\shell\open\command] @="\"%1\" /S" [HKEY_CLASSES_ROOT\txtfile\shell\open\command] @="%SystemRoot%\system32\NOTEPAD.EXE %1" Finished! |
|
|
|
|
|
#9 (permalink) |
|
Bronze Member
![]() Join Date: Jan 2008
Location: NY, NY
Posts: 93
|
Scanning of selected files
------------------------------------------------------------------------------------------ Program will try to scan 1 selected file(s) in the Chest Move files to temporary folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp24936267 5.tmp FileID: 0000000030 Original file name: C:\Documents and Settings\Eve\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarant ine\Quarantine - 01-15-2008 - 09-29-57\{12E926DE-1F48-4D8A-97CB-2E4C6A923EAD} New folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp24936267 5.tmp\30 Scan files in the temporary folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp24936267 5.tmp C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp24936267 5.tmp\30 Win32:TratBHO [Trj] ------------------------------------------------------------------------------------------ Action was completed successfully! |
|
|
|
|
|
#10 (permalink) |
|
Bronze Member
![]() Join Date: Jan 2008
Location: NY, NY
Posts: 93
|
Scanning of selected files
------------------------------------------------------------------------------------------ Program will try to scan 1 selected file(s) in the Chest Move files to temporary folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp23640911 3.tmp FileID: 0000000029 Original file name: C:\Documents and Settings\Eve\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarant ine\Quarantine - 01-15-2008 - 09-29-57\{11821116-0F8D-4FF5-A8D5-330C23399D3D} New folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp23640911 3.tmp\29 Scan files in the temporary folder: C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp23640911 3.tmp C:\DOCUME~1\Eve\LOCALS~1\Temp\_avast4_\unp23640911 3.tmp\29 Win32:TratBHO [Trj] ------------------------------------------------------------------------------------------ Action was completed successfully! |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Puper, Puper KV, Puper KJ Trojans??!! | matthew.fitchett | Computer Security | 1 | 01-22-2008 10:24 AM |
| Viri, Trojans & Pings | jackz4000 | Computer Security | 1 | 09-27-2006 10:59 AM |
| AVG Found 2 trojans....Hijack this log | r3dh3adkid | Computer Security | 1 | 08-26-2006 09:47 AM |
| trojans and spyware, oh my. Check my HJT log plz | lynx6200 | Computer Security | 10 | 10-29-2005 08:47 PM |
| Ad-Aware updates & Trojans, anyone confirm? | Greg J. | Computer Security | 12 | 03-05-2005 04:03 PM |