ComputerForum.com ComputerForum.com  
Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Display Modes
Old 04-08-2008, 09:56 AM   #11 (permalink)
Diamond Member
 
GameMaster's Avatar
 
Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,936
Default

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Code:
    File::
    C:\WINDOWS\system32\fsys.exe
    C:\WINDOWS\system32\Flower.exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\auto.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AutoRun.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\cross.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Discovery.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\guangd.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFWSvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.COM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NAVSetup.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RfwMain.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwProxy.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SDGames.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\servet.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ShuiNiu.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sos.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\svch0st.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Systom.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TNT.Exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TxoMoU.Exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UFO.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.EXE]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Wsyscheck.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\XP.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zxsweep.exe]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall!

Any better???
__________________
dznutz:
Quote:
a firewall is like a gate. it keeps the bad people out and the dog in but it's not fool proof. but lets say you download and run an infected program. that will be like letting in a "friend." if it's infected you run that program you can get malware. that's like a friend raping your family and stealing your money.
GameMaster is offline   Reply With Quote


Old 04-08-2008, 10:58 PM   #12 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

ok! here's the combofix log..


ComboFix 08-04-08.5 - monosphere user 2008-04-08 18:00:44.1 - NTFSx86
Running from: C:\Documents and Settings\monosphere user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\monosphere user\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\Flower.exe
C:\WINDOWS\system32\fsys.exe
.

((((((((((((((((((((((((( Files Created from 2008-03-08 to 2008-04-08 )))))))))))))))))))))))))))))))
.

2008-04-08 17:43 . 2008-04-08 17:43 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-07 18:17 . 2008-04-07 18:17 <DIR> d-------- C:\Deckard
2008-04-04 07:13 . 2008-04-04 07:13 <DIR> d-------- C:\Program Files\Safari
2008-04-04 07:10 . 2008-04-04 07:10 <DIR> d-------- C:\Program Files\iPod
2008-04-04 07:07 . 2008-04-04 07:08 <DIR> d-------- C:\Program Files\QuickTime
2008-04-03 06:51 . 2008-04-07 17:05 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-03 06:51 . 2008-04-03 06:51 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-29 10:33 . 2008-04-06 23:15 <DIR> d-------- C:\Program Files\racer
2008-03-29 10:06 . 2008-03-29 10:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-29 10:06 . 2008-03-29 11:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-03-25 09:23 . 2008-04-08 18:00 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 4
2008-03-23 19:35 . 2008-03-23 19:35 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\ZoomBrowser EX
2008-03-20 00:03 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-20 00:03 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-20 00:03 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-20 00:03 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-20 00:03 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-20 00:03 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-20 00:03 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-20 00:03 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-19 22:15 . 2008-03-20 00:00 2,483 --a------ C:\WINDOWS\system32\bxdkex.KEY
2008-03-17 23:19 . 2008-03-28 15:18 <DIR> d-------- C:\Program Files\Plato Video To iPod Converter
2008-03-17 23:19 . 2007-03-09 09:36 856,064 --a------ C:\WINDOWS\system32\mpgfiltr.ax
2008-03-17 23:19 . 2007-12-06 21:07 615,424 --a------ C:\WINDOWS\system32\XFlower.dll
2008-03-17 23:19 . 2006-08-01 14:01 438,272 --a------ C:\WINDOWS\system32\SkinCrafter.dll
2008-03-17 23:19 . 2007-03-09 09:35 208,896 --a------ C:\WINDOWS\system32\VideoEdit.ocx
2008-03-17 23:19 . 2007-03-09 09:37 139,264 --a------ C:\WINDOWS\system32\viscomqtde.dll
2008-03-17 23:19 . 2007-03-09 09:36 81,920 --a------ C:\WINDOWS\system32\viscomwave.dll
2008-03-17 22:19 . 2008-03-17 22:22 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\Any Video Converter Professional
2008-03-17 22:19 . 2008-03-17 22:20 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-17 21:41 . 2008-03-17 21:52 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-03-17 20:47 . 2005-11-25 07:46 421,888 --a------ C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-17 20:47 . 2004-05-25 17:06 417,792 --a------ C:\WINDOWS\system32\ac3filter.ax
2008-03-17 20:47 . 2004-01-10 17:02 258,048 --a------ C:\WINDOWS\system32\GplMpgDec.ax
2008-03-17 20:42 . 2008-03-17 20:43 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\XnView
2008-03-13 12:01 . 2008-03-13 12:01 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\Snappy Fax Archives
2008-03-13 11:47 . 2008-03-13 13:47 <DIR> d-------- C:\Program Files\Snappy Fax Version 4
2008-03-13 11:47 . 2008-03-13 15:27 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\Snappy Fax
2008-03-12 20:22 . 2008-03-12 20:22 <DIR> d-------- C:\EPSONREG
2008-03-12 20:14 . 2008-03-12 20:14 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-03-12 20:14 . 2008-03-17 20:45 <DIR> d-------- C:\Documents and Settings\monosphere user\Application Data\ArcSoft
2008-03-12 20:14 . 2004-08-04 07:52 413,696 -ra------ C:\WINDOWS\system32\msvcb66f.rra
2008-03-12 20:14 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-03-12 20:14 . 2006-10-20 16:11 126,976 --a------ C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2008-03-12 20:14 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-03-12 20:13 . 2008-03-12 20:14 <DIR> d-------- C:\WINDOWS\system32\PhotoImpression Slideshow
2008-03-12 20:13 . 2008-03-12 20:15 <DIR> d-------- C:\Program Files\ArcSoft
2008-03-12 20:12 . 2008-03-12 20:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EPSON
2008-03-12 20:09 . 2008-03-17 20:46 <DIR> d-------- C:\Program Files\epson
2008-03-12 20:09 . 2007-04-18 00:00 67,072 --a------ C:\WINDOWS\system32\escwiad.dll
2008-03-12 20:08 . 2008-03-12 20:22 44 --a------ C:\WINDOWS\EPCX8400.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-04-07 10:17 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\uTorrent
2008-04-04 20:07 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\Apple Computer
2008-04-04 11:10 --------- d-----w C:\Program Files\iTunes
2008-03-29 14:12 --------- d-----w C:\Program Files\NCH Software
2008-03-28 19:18 --------- d-----w C:\Program Files\pgAdmin III
2008-03-19 17:34 --------- d-----w C:\Program Files\Norton AntiVirus
2008-03-19 17:34 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-19 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-13 19:29 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\Skype
2008-03-13 13:48 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\skypePM
2008-03-13 00:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-06 15:39 --------- d-----w C:\Program Files\iDump
2008-03-04 12:59 --------- d-----w C:\Program Files\Google
2008-03-03 20:24 --------- d-----w C:\Program Files\Skype
2008-03-03 20:24 --------- d-----w C:\Program Files\Java
2008-03-03 19:17 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-03 16:45 --------- d-----w C:\Program Files\Common Files\Skype
2008-03-03 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-03-03 14:01 --------- d-----w C:\Program Files\Bonjour
2008-03-02 13:58 2,141,137 ----a-w C:\Program Files\WeatherBug.rar
2008-03-02 13:05 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\WeatherBug
2008-02-29 17:40 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-02-29 17:31 --------- d-----w C:\Program Files\Alwil Software
2008-02-29 17:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-29 17:03 --------- d-----w C:\Program Files\Avanquest update
2008-02-29 17:03 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\InstallShield
2008-02-29 16:54 --------- d-----w C:\Program Files\IBM
2008-02-29 16:53 --------- d-----w C:\Program Files\Motorola Phone Tools
2008-02-29 16:50 24,192 ----a-w C:\Documents and Settings\monosphere user\usbsermptxp.sys
2008-02-29 16:50 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2008-02-29 16:50 22,768 ----a-w C:\Documents and Settings\monosphere user\usbsermpt.sys
2008-02-29 06:21 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\Move Networks
2008-02-28 20:30 --------- d-----w C:\Program Files\Common Files\eSellerate
2008-02-28 19:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Software
2008-02-28 15:04 --------- d-----w C:\Program Files\WebEx
2008-02-26 20:46 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\Any Video Converter
2008-02-25 19:13 --------- d-----w C:\Program Files\Foxit Software
2008-02-25 19:01 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-25 18:17 --------- d-----w C:\Program Files\uTorrent
2008-02-25 15:29 --------- d-----w C:\Program Files\Symantec
2008-02-25 15:28 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\Symantec
2008-02-25 15:20 94 ----a-w C:\WINDOWS\system32\drivers\IBM_2373_A1U.MRK
2008-02-25 15:19 --------- d-----w C:\Program Files\Lenovo
2008-02-25 15:19 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-02-25 15:00 --------- d-----w C:\Documents and Settings\monosphere user\Application Data\IBM
2008-01-29 16:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
2008-01-13 18:40 21,321,008 ----a-w C:\Program Files\QuickTimeInstaller.exe
2006-09-01 13:59 28,672 ----a-w C:\Documents and Settings\monosphere user\atwbxdet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp. exe" [2007-12-04 08:00 79224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^monosphere user^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=C:\Documents and Settings\monosphere user\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=C:\WINDOWS\pss\Desktop Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2002-10-18 14:07 87751 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
--a------ 2001-09-04 19:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2003-01-16 14:52 294912 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationA gent]
--a------ 2004-08-04 03:56 380416 C:\WINDOWS\system32\irprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMGAG]
--a------ 2003-01-17 04:32 64000 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMLREF]
--a------ 2003-01-17 04:32 20480 C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-03-07 16:02 53408 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 03:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2003-01-10 06:50 106551 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlbxmon.exe]
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX8400 Series]
--a------ 2007-02-15 06:00 179200 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIC EA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
--a------ 2002-12-24 05:01 204800 C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ibmmessages]
--a------ 2003-01-07 17:52 495616 C:\Program Files\IBM\Messages By IBM\ibmmessages.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
C:\PROGRA~1\NORTON~1\Cfgwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3TRAY2]
--a------ 2001-10-12 01:32 69632 C:\WINDOWS\system32\S3Tray2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Snappy Fax]
--a------ 2008-02-28 14:01 13649408 C:\Program Files\Snappy Fax Version 4\sf4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
--a------ 2002-06-18 03:01 155648 c:\Program Files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2003-06-24 17:33 561152 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2003-06-24 17:34 126976 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-12-11 18:36 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TP4EX]
--a------ 2002-09-04 04:05 53248 C:\WINDOWS\system32\TP4EX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPHOTKEY]
--a------ 2003-01-24 20:37 94208 C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPMN]
--a------ 2003-02-17 03:30 32835 C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
--a------ 2007-11-19 15:23 487424 C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UC_SMB]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
--a------ 2006-03-17 09:34 124656 C:\PROGRA~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\Program Files\WeatherBug\Weather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\IBMTOOLS\\Updater\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\drivers\IBMB LDID.SYS [2003-02-24 05:06]
R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2003-01-17 04:32]
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []
S3 PCX504;Cisco Systems Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\PCX504.sys [2002-04-02 07:27]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2006-06-30 17:10]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NATServices REG_MULTI_SZ NATServices

.
Contents of the 'Scheduled Tasks' folder
"2008-03-31 19:18:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-12-26 00:45:50 C:\WINDOWS\Tasks\BMMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE
.
************************************************** ************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-08 18:04:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
Completion time: 2008-04-08 18:05:56
ComboFix-quarantined-files.txt 2008-04-08 22:05:34
Pre-Run: 45,598,097,408 bytes free
Post-Run: 45,584,396,288 bytes free
.
2008-03-21 21:13:51 --- E O F ---
Hey it's me is offline   Reply With Quote
Old 04-08-2008, 11:03 PM   #13 (permalink)
Bronze Member
 
Hey it's me's Avatar
 
Join Date: Jan 2008
Location: NY, NY
Posts: 93
Default

BY JOE!! you did it! Game master? You AMAZE ME! YOU REALLY ARE, "da MANNNNN". what can I say? well, THANK YOU for starters. My registry is back up! I am ever so grateful (once again) you have SAVED the day. how does it feel to be the prince of CF? As a person who's a danger to herself because I know JUST enough to do damage, not enough to fix it, I Need you!
Thank you. Thank you, Thank you!
I'm sending you lots of magical good vibes through cyber space!

hey it's me!
Hey it's me is offline   Reply With Quote
Old 04-09-2008, 08:14 AM   #14 (permalink)
Diamond Member
 
GameMaster's Avatar
 
Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,936
Default

Haha, thanks for your lovely greetings helping anytime here on ComputerForum.com
__________________
dznutz:
Quote:
a firewall is like a gate. it keeps the bad people out and the dog in but it's not fool proof. but lets say you download and run an infected program. that will be like letting in a "friend." if it's infected you run that program you can get malware. that's like a friend raping your family and stealing your money.
GameMaster is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Win Explorer Shortcuts Open In Same Window KlumpDud Operating Systems 9 11-11-2006 03:55 AM
cannot open file once downloaded PLEASE HELP speedaccordinly General Software 8 11-09-2006 06:00 AM
Some files open slow (related to networking) loginn Operating Systems 12 10-31-2006 05:07 AM
Windows Cannot Open This File...... mattizzle General Software 2 10-19-2006 09:03 PM
SPY Ware and not being able to open a window CCsoultions Computer Security 2 04-05-2005 03:06 PM

All times are GMT +1. The time now is 06:43 AM.


Powered by: vBulletin Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 Computer Forum and Web Design Forum