1
BDSsmall.iuj on Sat Aug 14, 2010 11:43 am
Hi! My Avira (free version) seems to be detecting a BDS\small.iuj malware in my explorer.exe. I chose the "remove this file" option and it deleted my explorer.exe. I reformatted my pc but when I installed Avira, it detected this malware again. This time, i chose to ignore it and searched the net for some solutions to remove this. I stumbled upon your site and downloaded the System Look, gave it a run and got this log.
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 23:01 on 15/08/2010 by jalla (Administrator - Elevation successful)
========== filefind ==========
Searching for "explorer.exe"
C:\Documents and Settings\jalla\My Documents\Downloads\explorer.exe --a--- 1033216 bytes [14:39 15/08/2010] [14:39 15/08/2010] 97BD6515465659FF8F3B7BE375B2EA87
C:\WINDOWS\explorer.exe --a--- 1075200 bytes [14:08 15/08/2010] [14:10 15/08/2010] 2DEACA71A7FD77205F59D48D76B2F565
-=End Of File=-
It had the same results with the thread that I read, so I proceeded to download the explorer.exe link posted there and ComboFix.
I opened ComboFix and let it do it's work. When the box disappeared, all of my icons on the desktop disappeared too. So I decided to restart my pc after waiting for a few minutes if my icons will return.
After restarting, ComboFix reappeared again saying that it's preparing the log report.
ComboFix 10-08-12.03 - jalla 08/15/2010 23:45:36.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.644 [GMT 7:00]
Running from: c:\documents and settings\jalla\Desktop\combo-fix.exe.exe
Command switches used :: c:\documents and settings\jalla\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Files Created from 2010-07-15 to 2010-08-15 )))))))))))))))))))))))))))))))
.
2010-08-15 15:04 . 2010-08-15 15:18 -------- d-----w- C:\ComboFix
2010-08-15 14:08 . 2010-08-15 14:10 1075200 ----a-w- c:\windows\explorer.exe
2010-08-15 14:07 . 2010-08-15 14:07 -------- d-----w- c:\documents and settings\jalla\Application Data\Avira
2010-08-15 14:03 . 2010-08-15 14:03 -------- d-----w- c:\windows\system32\KB905474
2010-08-15 12:03 . 2010-08-15 12:07 -------- d-----w- c:\windows\system32\NtmsData
2010-08-15 12:00 . 2010-08-15 12:00 503808 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\msvcp71.dll
2010-08-15 12:00 . 2010-08-15 12:00 499712 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\jmc.dll
2010-08-15 12:00 . 2010-08-15 12:00 348160 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\msvcr71.dll
2010-08-15 12:00 . 2010-08-15 12:00 61440 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-73adf7f2-n\decora-sse.dll
2010-08-15 12:00 . 2010-08-15 12:00 12800 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-73adf7f2-n\decora-d3d.dll
2010-08-15 12:00 . 2010-08-15 12:00 -------- d-----w- c:\program files\Common Files\Java
2010-08-15 12:00 . 2010-08-15 12:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-15 12:00 . 2010-08-15 12:00 -------- d-----w- c:\program files\Java
2010-08-15 11:59 . 2010-08-15 11:59 -------- d-----w- c:\program files\Avira
2010-08-15 11:59 . 2010-08-15 11:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-08-15 11:59 . 2010-03-01 03:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-08-15 11:59 . 2010-02-16 07:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-08-15 11:59 . 2009-05-11 05:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-08-15 11:59 . 2009-05-11 05:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-08-14 14:11 . 2010-08-14 14:11 77184 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-14 14:03 . 2010-08-14 14:03 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2010-08-14 14:00 . 2010-08-14 14:00 -------- d-----w- c:\program files\MSXML 4.0
2010-08-14 13:54 . 2010-08-15 14:27 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Adobe
2010-08-14 13:32 . 2010-08-15 11:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\program files\Common Files\Apple
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Apple
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\program files\Apple Software Update
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-08-14 13:23 . 2010-08-14 13:23 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Apple Computer
2010-08-14 10:45 . 2010-08-14 10:45 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Ahead
2010-08-14 10:42 . 2010-08-14 10:42 -------- d-----w- c:\documents and settings\jalla\Application Data\Ahead
2010-08-14 10:41 . 2010-08-14 10:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2010-08-14 10:38 . 2010-08-15 14:03 -------- d-----w- c:\windows\system32\DllCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-14 14:03 . 2010-08-13 16:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-14 13:59 . 2010-08-13 15:30 -------- d-----w- c:\program files\QuickTime Alternative
2010-08-14 13:24 . 2010-08-13 15:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-14 10:43 . 2010-08-14 10:43 -------- d-----w- c:\program files\Common Files\LightScribe
2010-08-14 10:41 . 2010-08-13 16:35 -------- d-----w- c:\program files\Common Files\Ahead
2010-08-13 16:35 . 2010-08-13 16:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-08-13 16:35 . 2010-08-13 16:35 -------- d-----w- c:\program files\Nero
2010-08-13 16:30 . 2010-08-13 16:30 66144 ----a-w- c:\documents and settings\jalla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-13 16:15 . 2010-08-13 16:15 -------- d-----w- c:\program files\Microsoft Works
2010-08-13 16:15 . 2010-08-13 16:15 -------- d-----w- c:\program files\MSBuild
2010-08-13 16:09 . 2010-08-13 15:28 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-08-13 15:48 . 2010-08-13 15:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-13 15:48 . 2010-08-13 15:48 -------- d-----w- c:\program files\FOXCONN
2010-08-13 15:47 . 2010-08-13 15:47 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-13 15:44 . 2010-08-13 15:44 -------- d-----w- c:\program files\Realtek
2010-08-13 15:44 . 2010-08-13 15:44 -------- d-----w- c:\documents and settings\jalla\Application Data\InstallShield
2010-08-13 15:41 . 2010-08-13 15:41 -------- d-----w- c:\program files\Intel
2010-08-13 15:37 . 2010-08-13 15:37 0 ----a-w- c:\windows\nsreg.dat
2010-08-13 15:30 . 2010-08-13 15:30 107132 ----a-w- c:\windows\UninstallFirefox.exe
2010-08-13 15:30 . 2010-08-13 15:30 2293 ----a-w- c:\windows\mozver.dat
2010-08-13 15:29 . 2010-08-13 15:29 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-13 15:26 . 2010-08-13 15:26 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-08-13 15:26 . 2010-08-13 15:26 -------- d-----w- c:\program files\Unlocker
2010-06-14 14:30 . 2010-08-13 15:27 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
.
------- Sigcheck -------
[-] 2010-08-15 . 2DEACA71A7FD77205F59D48D76B2F565 . 1075200 . . [6.00.2900.2649] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-08-15_15.16.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-15 17:02 . 2010-08-15 17:02 16384 c:\windows\temp\Perflib_Perfdata_79c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 16384000]
"SkyTel"="SkyTel.EXE" [2007-08-03 1826816]
"Gainward"="c:\windows\TBPanel.exe" [2008-01-29 2177576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-08 8523776]
"nwiz"="nwiz.exe" [2008-01-08 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-08 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 1057064]
"NBKeyScan"="c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2007-06-29 1373480]
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2010-03-17 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="c:\windows\system32\msnsc.exe" [2006-01-13 62054]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/15/2010 6:59 PM 135336]
S3 FXDrv32;FXDrv32;\??\d:\fxdrv32.sys --> d:\FXDrv32.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 10:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 05:34]
2010-08-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-15 15:18]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\jalla\Application Data\Mozilla\Firefox\Profiles\8pagwy0d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 00:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4012)
c:\windows\system32\msi.dll
c:\windows\system32\browselc.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\shdoclc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-16 00:04:32 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-15 17:04
Pre-Run: 68,662,476,800 bytes free
Post-Run: 68,649,660,416 bytes free
- - End Of File - - 375E396B5221CED0AB8EBCD2A7B08728
Now, when I checked the thread, it did not have the same results. What should I do next? By the way, I'm using a Windows XP Home Edition Service Pack 3. It's not genuine though.
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 23:01 on 15/08/2010 by jalla (Administrator - Elevation successful)
========== filefind ==========
Searching for "explorer.exe"
C:\Documents and Settings\jalla\My Documents\Downloads\explorer.exe --a--- 1033216 bytes [14:39 15/08/2010] [14:39 15/08/2010] 97BD6515465659FF8F3B7BE375B2EA87
C:\WINDOWS\explorer.exe --a--- 1075200 bytes [14:08 15/08/2010] [14:10 15/08/2010] 2DEACA71A7FD77205F59D48D76B2F565
-=End Of File=-
It had the same results with the thread that I read, so I proceeded to download the explorer.exe link posted there and ComboFix.
I opened ComboFix and let it do it's work. When the box disappeared, all of my icons on the desktop disappeared too. So I decided to restart my pc after waiting for a few minutes if my icons will return.
After restarting, ComboFix reappeared again saying that it's preparing the log report.
ComboFix 10-08-12.03 - jalla 08/15/2010 23:45:36.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.644 [GMT 7:00]
Running from: c:\documents and settings\jalla\Desktop\combo-fix.exe.exe
Command switches used :: c:\documents and settings\jalla\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Files Created from 2010-07-15 to 2010-08-15 )))))))))))))))))))))))))))))))
.
2010-08-15 15:04 . 2010-08-15 15:18 -------- d-----w- C:\ComboFix
2010-08-15 14:08 . 2010-08-15 14:10 1075200 ----a-w- c:\windows\explorer.exe
2010-08-15 14:07 . 2010-08-15 14:07 -------- d-----w- c:\documents and settings\jalla\Application Data\Avira
2010-08-15 14:03 . 2010-08-15 14:03 -------- d-----w- c:\windows\system32\KB905474
2010-08-15 12:03 . 2010-08-15 12:07 -------- d-----w- c:\windows\system32\NtmsData
2010-08-15 12:00 . 2010-08-15 12:00 503808 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\msvcp71.dll
2010-08-15 12:00 . 2010-08-15 12:00 499712 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\jmc.dll
2010-08-15 12:00 . 2010-08-15 12:00 348160 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-58e50266-n\msvcr71.dll
2010-08-15 12:00 . 2010-08-15 12:00 61440 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-73adf7f2-n\decora-sse.dll
2010-08-15 12:00 . 2010-08-15 12:00 12800 ----a-w- c:\documents and settings\jalla\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-73adf7f2-n\decora-d3d.dll
2010-08-15 12:00 . 2010-08-15 12:00 -------- d-----w- c:\program files\Common Files\Java
2010-08-15 12:00 . 2010-08-15 12:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-15 12:00 . 2010-08-15 12:00 -------- d-----w- c:\program files\Java
2010-08-15 11:59 . 2010-08-15 11:59 -------- d-----w- c:\program files\Avira
2010-08-15 11:59 . 2010-08-15 11:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-08-15 11:59 . 2010-03-01 03:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-08-15 11:59 . 2010-02-16 07:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-08-15 11:59 . 2009-05-11 05:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-08-15 11:59 . 2009-05-11 05:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-08-14 14:11 . 2010-08-14 14:11 77184 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-14 14:03 . 2010-08-14 14:03 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2010-08-14 14:00 . 2010-08-14 14:00 -------- d-----w- c:\program files\MSXML 4.0
2010-08-14 13:54 . 2010-08-15 14:27 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Adobe
2010-08-14 13:32 . 2010-08-15 11:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\program files\Common Files\Apple
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Apple
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\program files\Apple Software Update
2010-08-14 13:24 . 2010-08-14 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-08-14 13:23 . 2010-08-14 13:23 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Apple Computer
2010-08-14 10:45 . 2010-08-14 10:45 -------- d-----w- c:\documents and settings\jalla\Local Settings\Application Data\Ahead
2010-08-14 10:42 . 2010-08-14 10:42 -------- d-----w- c:\documents and settings\jalla\Application Data\Ahead
2010-08-14 10:41 . 2010-08-14 10:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2010-08-14 10:38 . 2010-08-15 14:03 -------- d-----w- c:\windows\system32\DllCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-14 14:03 . 2010-08-13 16:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-14 13:59 . 2010-08-13 15:30 -------- d-----w- c:\program files\QuickTime Alternative
2010-08-14 13:24 . 2010-08-13 15:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-14 10:43 . 2010-08-14 10:43 -------- d-----w- c:\program files\Common Files\LightScribe
2010-08-14 10:41 . 2010-08-13 16:35 -------- d-----w- c:\program files\Common Files\Ahead
2010-08-13 16:35 . 2010-08-13 16:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-08-13 16:35 . 2010-08-13 16:35 -------- d-----w- c:\program files\Nero
2010-08-13 16:30 . 2010-08-13 16:30 66144 ----a-w- c:\documents and settings\jalla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-13 16:15 . 2010-08-13 16:15 -------- d-----w- c:\program files\Microsoft Works
2010-08-13 16:15 . 2010-08-13 16:15 -------- d-----w- c:\program files\MSBuild
2010-08-13 16:09 . 2010-08-13 15:28 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-08-13 15:48 . 2010-08-13 15:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-13 15:48 . 2010-08-13 15:48 -------- d-----w- c:\program files\FOXCONN
2010-08-13 15:47 . 2010-08-13 15:47 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-13 15:44 . 2010-08-13 15:44 -------- d-----w- c:\program files\Realtek
2010-08-13 15:44 . 2010-08-13 15:44 -------- d-----w- c:\documents and settings\jalla\Application Data\InstallShield
2010-08-13 15:41 . 2010-08-13 15:41 -------- d-----w- c:\program files\Intel
2010-08-13 15:37 . 2010-08-13 15:37 0 ----a-w- c:\windows\nsreg.dat
2010-08-13 15:30 . 2010-08-13 15:30 107132 ----a-w- c:\windows\UninstallFirefox.exe
2010-08-13 15:30 . 2010-08-13 15:30 2293 ----a-w- c:\windows\mozver.dat
2010-08-13 15:29 . 2010-08-13 15:29 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-13 15:26 . 2010-08-13 15:26 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-08-13 15:26 . 2010-08-13 15:26 -------- d-----w- c:\program files\Unlocker
2010-06-14 14:30 . 2010-08-13 15:27 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
.
------- Sigcheck -------
[-] 2010-08-15 . 2DEACA71A7FD77205F59D48D76B2F565 . 1075200 . . [6.00.2900.2649] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-08-15_15.16.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-15 17:02 . 2010-08-15 17:02 16384 c:\windows\temp\Perflib_Perfdata_79c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 16384000]
"SkyTel"="SkyTel.EXE" [2007-08-03 1826816]
"Gainward"="c:\windows\TBPanel.exe" [2008-01-29 2177576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-08 8523776]
"nwiz"="nwiz.exe" [2008-01-08 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-08 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 1057064]
"NBKeyScan"="c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2007-06-29 1373480]
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2010-03-17 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="c:\windows\system32\msnsc.exe" [2006-01-13 62054]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/15/2010 6:59 PM 135336]
S3 FXDrv32;FXDrv32;\??\d:\fxdrv32.sys --> d:\FXDrv32.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 10:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 05:34]
2010-08-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-15 15:18]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\jalla\Application Data\Mozilla\Firefox\Profiles\8pagwy0d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 00:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4012)
c:\windows\system32\msi.dll
c:\windows\system32\browselc.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\shdoclc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-16 00:04:32 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-15 17:04
Pre-Run: 68,662,476,800 bytes free
Post-Run: 68,649,660,416 bytes free
- - End Of File - - 375E396B5221CED0AB8EBCD2A7B08728
Now, when I checked the thread, it did not have the same results. What should I do next? By the way, I'm using a Windows XP Home Edition Service Pack 3. It's not genuine though.












