Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Virus new folder.exe
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Virus new folder.exe  
Forum Quick Jump
 
New Topic Post reply to : Virus new folder.exe Printable version of : Virus new folder.exe
[ << Previous Thread | Next Thread >> ]

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-8-2008 1:49 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi,
 
I have problems with my PC, it was infected by virus which creates a new folder .exe on my thumb drive everytime that i plug it into my computer and it destroyes all the files in my thumbdrive which is out of a folder. My antivurus has been disbled by this virus, also the taskmanager, command prompt and the registry editor. the file that this virus destroys will become an application with 84 kb size.
On my desktop it creates a folder named files and notepad application and in my drive C there is a calculator icon.
 
Hope you can help me how to remove this virus
 
thanks,
 
rold
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 3-8-2008 6:56 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi roldski smile
 
 
Please download Flash_Disinfector.exe by sUBs and save it to your desktop:

NOTE:
In the event you already have Flash_Disinfector, this is a new version that I need you to download.
  • Double-click Flash_Disinfector.exe to run it.
  • Follow any prompts that may appear.
  • Your desktop will vanish for a while, and then reappear. This is normal.
  • Wait until the program has finished scanning, then please exit the program.
Still with thumbdrive plugged in ->
 
Please download Combofix:
 
and save to the desktop.

Close all other browser windows.
 
 
 
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Go to start --> run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /killall

 
 When finished, it will produce a logfile located at C:\ComboFix.txt.

Post the contents of that log in your next reply.

 Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
 
NB. We ask that you remove any P2P file sharing programs you have installed before we clean your computer. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.
 


Do NOT post your problem in someone elses thread.

Back to Top
 

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-8-2008 11:41 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi,
 
Attached is the log files created by the combo fix .exe, unfortunately it does not delete the virus on my PC, another thing that i have encountered is everytime that i will open the C: \ Windows it will automatically terminated the explorer like the one its done with the task manager, registry editor and  command prompt.
 
thanks,
 
rold

File Attachment :
log.pdf   14KB (application/pdf)
This file has been downloaded 169 time(s).
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 3-9-2008 3:04 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
I´ll be glad to help, when You use - post reply button- for posting log files, meaning that You don´t shall attach them


Do NOT post your problem in someone elses thread.

Back to Top
 

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-10-2008 1:38 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi,
Im sorry for that, below is the log files

ComboFix 08-03-07.4 - Rold ™ 2008-03-08 20:20:19.1 - NTFSx86
Running from: C:\Documents and Settings\Rold ™\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\12.exe
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-08 to 2008-03-08 )))))))))))))))))))))))))))))))
.
2008-03-07 20:43 . 2008-03-07 20:43 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-07 20:42 . 2008-03-07 21:00 <DIR> d-------- C:\SDFix
2008-03-02 21:38 . 2008-03-02 21:38 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
2008-03-02 21:29 . 2000-05-22 22:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-03-02 20:42 . 2008-03-02 21:39 <DIR> d-------- C:\Program Files\Folder Lock
2008-03-02 20:42 . 2005-04-11 16:40 73,728 --a------ C:\WINDOWS\system32\FLKill.exe
2008-03-02 20:42 . 2008-03-02 20:42 53,248 --a------ C:\WINDOWS\system32\suppdll.dll
2008-03-02 13:59 . 2008-03-02 13:58 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-03-02 13:59 . 2008-03-02 13:58 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTimeVR.Resources
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime.Resources
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\Program Files\QuickTime
2008-03-02 13:36 . 2008-03-07 20:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\U3
2008-02-26 19:04 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime(2)
2008-02-26 19:04 . 2008-03-02 13:41 <DIR> d-------- C:\Program Files\QuickTime(2)
2008-02-17 18:58 . 2008-02-17 19:01 78,999 --a------ C:\WINDOWS\hpfins05.dat
2008-02-17 18:58 . 2005-05-24 03:44 1,395 --------- C:\WINDOWS\hpfmdl05.dat
2008-02-17 07:39 . 2008-02-17 07:39 0 --a------ C:\Default.Bmp
2008-02-10 11:22 . 2008-02-10 11:23 <DIR> d-------- C:\Documents and Settings\Chen\Application Data\ViStart
2008-02-10 11:20 . 2008-02-10 11:20 <DIR> d-------- C:\Documents and Settings\Chen\Application Data\Styler
2008-02-09 19:53 . 2008-02-09 19:55 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 19:53 . 2008-02-09 19:55 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 19:53 . 2008-02-09 19:55 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 19:46 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\VisualTooltip
2008-02-09 19:46 . 2008-02-10 11:23 <DIR> d-------- C:\Program Files\ViStart
2008-02-09 19:46 . 2008-02-09 19:54 <DIR> d-------- C:\Program Files\Vista Sidebar
2008-02-09 19:46 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\ViOrb
2008-02-09 19:46 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\LClock
2008-02-09 19:46 . 2007-04-15 01:30 6,181,376 --a------ C:\WINDOWS\system32\vistaui.exe
2008-02-09 19:46 . 2007-11-30 05:56 329,029 --a------ C:\WINDOWS\system32\viwc.exe
2008-02-09 19:46 . 2004-09-20 01:27 172,032 --a------ C:\WINDOWS\system32\LClock.cpl
2008-02-09 19:46 . 2007-11-25 22:11 49,208 --a------ C:\WINDOWS\system32\vistartup.bmp
2008-02-09 19:41 . 2008-02-09 19:41 76,214 --a------ C:\WINDOWS\Icon_3.ico
2008-02-09 19:36 . 2008-02-10 11:23 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2008-02-09 19:14 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\WinFlip
2008-02-09 19:14 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\TrueTransparency
2008-02-09 19:14 . 2008-02-09 19:46 <DIR> d-------- C:\Program Files\Styler
2008-02-09 19:06 . 2008-02-09 19:06 76,214 --a------ C:\WINDOWS\Icon_2.ico
2008-02-08 20:30 . 2008-02-08 20:30 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-08 20:30 . 2008-02-08 20:30 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-08 20:30 . 2008-02-08 20:30 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-08 20:25 . 2008-02-09 19:51 <DIR> d-------- C:\WINDOWS\system32\VITrans
2008-02-08 20:25 . 2008-02-09 19:52 <DIR> d-------- C:\VTPFiles
2008-02-08 20:25 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-02-08 20:25 . 2008-02-08 20:25 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-02-08 20:25 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-02-08 20:25 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 12:04 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-08 12:04 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-08 12:04 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-04 01:13 86,016 ----a-w C:\WINDOWS\ererrrererer.exe
2008-03-02 13:31 --------- d-----w C:\Program Files\Total Video Converter
2008-03-02 12:37 --------- d-----w C:\Program Files\ESET
2008-03-02 12:32 --------- d-----w C:\Documents and Settings\Chen\Application Data\U3
2008-02-16 12:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-03 12:08 --------- d-----w C:\Documents and Settings\Chen\Application Data\vlc
2008-02-03 09:11 --------- d-----w C:\Program Files\3D LOTR Eye of Sauron
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:32 --------- d-----w C:\Program Files\FLVPlayer
2008-01-31 19:31 --------- d-----w C:\Program Files\VideoLAN
.
------- Sigcheck -------
789a67335f801d6d429ae49ad82c5e57 C:\WINDOWS\system32\ntkrnlpa.exe
----a-w 2,027,008 2004-08-04 01:07:00 C:\WINDOWS\system32\ntkrnlpa.exe
----a-w 2,027,008 2004-08-04 01:07:00 C:\WINDOWS\system32\VITrans\ntkrnlpa.exe
5d0f5b34f58a6869b297228ef2405282 C:\WINDOWS\system32\ntoskrnl.exe
----a-w 2,160,128 2004-08-04 01:07:00 C:\WINDOWS\system32\ntoskrnl.exe
----a-w 2,160,128 2004-08-04 01:07:00 C:\WINDOWS\system32\VITrans\ntoskrnl.exe
4b0011b8e35843966a3ce5685058420f C:\WINDOWS\explorer.exe
----a-w 1,422,336 2004-08-04 01:07:00 C:\WINDOWS\explorer.exe
-c--a-w 1,032,192 2004-08-04 01:07:00 C:\WINDOWS\system32\dllcache\explorer.exe
----a-w 1,422,336 2004-08-04 01:07:00 C:\WINDOWS\system32\VITrans\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:07 15360]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-20 01:27 65536]
"Vista Sidebar"="C:\Program Files\Vista Sidebar\sidebar.exe" [2007-11-20 13:51 524288]
"RocketDock"="D:\installer\Software\vista package\RocketDock\RocketDock.exe" [2007-03-18 14:05 630784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-11-01 04:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 22:25 1400944]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"nod32upd"="C:\Program Files\Eset\fc_upd.dll" [2007-05-12 03:39 3584]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"WindowNT"="c:\WINDOWS\system32\exiplorer.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"nav_x"="c:\smss.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 16:22 577536 C:\WINDOWS\soundman.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-16 19:58 114688]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-03-02 13:58 921600]
"NVIDIA Display"="C:\WINDOWS\DisplayMonitor.exe" [ ]
"Win32 Console"="C:\WINDOWS\cmd.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 09:07 15360]
C:\Documents and Settings\Chen\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\Rold T\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
Thoosje Vista Sidebar.lnk - C:\Program Files\Vista Sidebar\sidebar.exe [2008-02-09 19:46:35 524288]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-07-28 23:18:09 25214]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Setup.exe [2008-03-04 09:13:05 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\Program Files\Common Files\Stardock\mcpstub.dll 2003-08-25 11:25 139264 C:\Program Files\Common Files\Stardock\MCPStub.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\SIERRA\\Half-Life\\hl.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 11:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11:39]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05c6174e-1777-11dc-a175-0016ecf01d56}]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0b56d46-e390-11db-a14b-0016ecf01d56}]
\Shell\AutoRun\command - I:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 20:22:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk error: C:\WINDOWS\
**************************************************************************
.
Completion time: 2008-03-08 20:24:13
ComboFix-quarantined-files.txt 2008-03-08 12:23:19
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 3-12-2008 4:27 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
No problem smile
 
 
1. Get this version of Hijackthis from http://danborg.org/spy/hjt/alternativ.exe
 
2
Save it in a permanent folder of your choice, such as C:\HJT\. To create this specific folder on your hard drive: Double click the 'My Computer' icon on your desktop, then under the category hard disk drives: double click Local Disk:, then select file->New -> Folder and name it HJT
3 Run hijackthis.  (alternativ exe).

Choose the "Do a system scan and save a log file" option to perform your scan.
HijackThis will analyze your system, and automatically open a notepad textfile containing the HijackThis log when the scan is finished.
Open the text files containing the logs with a text editor and click Edit -> Select All, followed by Edit -> Copy.
From within the browser window and with the message body text box selected, click Edit -> Paste.
Post  hijackthis log here


Do NOT post your problem in someone elses thread.

Back to Top
 

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-14-2008 3:22 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi Touch,
Below is the log file of Hijack this,
Hope we can solve this soon,
Many thanks,
Rold
Logfile of HijackThis v1.99.1
Scan saved at 3:17:59 PM, on 3/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Vista Sidebar\sidebar.exe
D:\installer\Software\vista package\RocketDock\RocketDock.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Setup.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\alternativ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
F2 - REG:system.ini: Shell=explorer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [nod32upd] rundll32 "C:\Program Files\Eset\fc_upd.dll",NOD32Ioctl
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [WindowNT] c:\WINDOWS\system32\exiplorer.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nav_x] c:\smss.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NVIDIA Display] C:\WINDOWS\DisplayMonitor.exe
O4 - HKLM\..\Run: [Win32 Console] C:\WINDOWS\cmd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKCU\..\Run: [RocketDock] "D:\installer\Software\vista package\RocketDock\RocketDock.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Setup.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe


Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 3-15-2008 7:21 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Please download Free  Version of Superantispyware
 
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it.
close the program
 
 
Please download ATF Cleaner:
 http://www.atribune.org/ccount/click.php?id=1 by Atribune.
This program is for XP and Windows 2000 only
 
 
Download  DrWebCureit:
 
 
to your desktop.
 
 
 
Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked.
F2 - REG:system.ini: Shell=explorer.exe
O4 - HKLM\..\Run: [WindowNT] c:\WINDOWS\system32\exiplorer.exe
O4 - HKLM\..\Run: [nav_x] c:\smss.exe
O4 - HKLM\..\Run: [NVIDIA Display] C:\WINDOWS\DisplayMonitor.exe
O4 - HKLM\..\Run: [Win32 Console] C:\WINDOWS\cmd.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
 
 
 
 
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
 
 
 
 
 
Delete the following files or folders (delete item in bold). Please do not be concerned if
any of the items are not found as they may have been automatically removed by actions I had
you take earlier in the cleaning process.
 
 
Open Folder Options in Controlpanel >view and check your settings:
Select
Show hidden files and folders
Display the contents of system folders
Uncheck: Hide protected operating system files
Delete:
Files:
c:\smss.exe
C:\WINDOWS\DisplayMonitor.exe
C:\WINDOWS\cmd.exe
c:\WINDOWS\system32\exiplorer.exe
 
 
 
 
 
 
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch (Windows XP) only.
Java Cache
Recycle Bin
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.
 
 
Doubleclick the "drweb-cureit.exe" and click "Start" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the Options->Change settings.
 
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select –Rename
Click – Apply - OK
Click on Scan Tab.  Move  dot from Express scan to Complete Scan.  Click on The Green arrow to the right.  It will now scan your  drive(s), say yes to all
 
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
 
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
 
 
 
 
 
Start Superantispyware.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next,
it will scan now. When scan have finished, put a checkmark with  all items it found. Next, after cleaning, allow it to Reboot
 
 
 
Start Superantispyware again –
Click Preferences and then click the statistics/logs tab.
Click the dated log and press view log and a text file will appear.
 
 
 
Post this log along with fresh hijackthis log, Dr.Web log, new combofix log 


Do NOT post your problem in someone elses thread.

Back to Top
 

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-17-2008 1:22 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi Touch,
Below is the log files of hijackthis, Dr.Web and combofix, after doing your instruction on the safe mode I can access the registry CMD and task manager, but when I restarted my PC and run on normal mode I cant access again to the registry CMD and task manager, still I encountered the same problem.
Below is the log files for your review
thanks
Rold


Logfile of HijackThis v1.99.1
Scan saved at 10:41:47 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\HJT\alternativ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKCU\..\Run: [RocketDock] "D:\installer\Software\vista package\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Setup.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
DRWEB LOG
UFYEEHCA.#QF;C:\Program Files\ESET\infected;Adware.Relevant;Renamed.;
Crack.#xe;D:\installer\Games\counterstrike\utilities\No CD Check\Half-Life Opposing Force v1.0.0.1 US No-CD Crack;Tool.GameCrack;Renamed.;
Crack.#xe;D:\installer\Games\counterstrike\utilities\No CD Check\Half-Life v1.0.1.6 US No-CD Crack;Tool.GameCrack;Renamed.;
UFYEEHCA.#QF;H:\ESET\infected;Adware.Relevant;Renamed.; 
 
COMBOFIX LOG
ComboFix 08-03-07.4 - Rold ™ 2008-03-16 22:36:59.3 - NTFSx86 NETWORK
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.86 [GMT 8:00]Running from: C:\Documents and Settings\Rold ™\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((   Files Created from 2008-02-16 to 2008-03-16  )))))))))))))))))))))))))))))))
.
2008-03-16 18:01 . 2008-03-16 18:01 <DIR> d-------- C:\Documents and Settings\Rold ™\DoctorWeb
2008-03-16 18:01 . 2008-03-16 18:01 <DIR> d-------- C:\Documents and Settings\Rold ™\DoctorWeb
2008-03-16 17:35 . 2008-03-16 17:35 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-16 17:35 . 2008-03-16 17:35 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\SUPERAntiSpyware.com
2008-03-16 17:35 . 2008-03-16 17:35 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\SUPERAntiSpyware.com
2008-03-16 17:35 . 2008-03-16 17:35 <DIR> d-------- C:\Documents and Settings\Rold ™\Application Data\SUPERAntiSpyware.com
2008-03-16 17:35 . 2008-03-16 17:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-14 15:16 . 2008-03-16 20:36 <DIR> d-------- C:\HJT
2008-03-12 15:17 . 2008-03-12 15:17 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-03-09 16:45 . 2008-03-09 16:45 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-09 16:45 . 2008-03-09 16:45 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-07 20:43 . 2008-03-07 20:43 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-02 21:38 . 2008-03-02 21:38 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
2008-03-02 21:38 . 2008-03-16 20:28 452 --a------ C:\sccfg.sys
2008-03-02 21:29 . 2000-05-22 22:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-03-02 20:42 . 2008-03-02 21:39 <DIR> d-------- C:\Program Files\Folder Lock
2008-03-02 20:42 . 2005-04-11 16:40 73,728 --a------ C:\WINDOWS\system32\FLKill.exe
2008-03-02 20:42 . 2008-03-02 20:42 53,248 --a------ C:\WINDOWS\system32\suppdll.dll
2008-03-02 13:59 . 2008-03-02 13:58 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-03-02 13:59 . 2008-03-02 13:58 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTimeVR.Resources
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime.Resources
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-03-02 13:41 . 2008-03-02 13:41 <DIR> d-------- C:\Program Files\QuickTime
2008-03-02 13:36 . 2008-03-07 20:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\U3
2008-02-26 19:04 . 2008-03-02 13:41 <DIR> d-------- C:\WINDOWS\system32\QuickTime(2)
2008-02-26 19:04 . 2008-03-02 13:41 <DIR> d-------- C:\Program Files\QuickTime(2)
2008-02-17 18:58 . 2008-02-17 19:01 78,999 --a------ C:\WINDOWS\hpfins05.dat
2008-02-17 18:58 . 2005-05-24 03:44 1,395 --------- C:\WINDOWS\hpfmdl05.dat
2008-02-17 07:39 . 2008-02-17 07:39 0 --a------ C:\Default.Bmp
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 09:35 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-08 12:36 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-08 12:36 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-08 12:36 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\U3
2008-03-02 13:31 --------- d-----w C:\Program Files\Total Video Converter
2008-03-02 12:37 --------- d-----w C:\Program Files\ESET
2008-03-02 12:32 --------- d-----w C:\Documents and Settings\Chen\Application Data\U3
2008-02-16 12:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-10 03:23 --------- d-----w C:\Program Files\ViStart
2008-02-10 03:23 --------- d-----w C:\Documents and Settings\Chen\Application Data\ViStart
2008-02-10 03:20 --------- d-----w C:\Documents and Settings\Chen\Application Data\Styler
2008-02-09 11:55 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 11:55 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 11:55 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\ViStart
2008-02-09 11:54 --------- d-----w C:\Program Files\Vista Sidebar
2008-02-09 11:46 --------- d-----w C:\Program Files\WinFlip
2008-02-09 11:46 --------- d-----w C:\Program Files\VisualTooltip
2008-02-09 11:46 --------- d-----w C:\Program Files\ViOrb
2008-02-09 11:46 --------- d-----w C:\Program Files\TrueTransparency
2008-02-09 11:46 --------- d-----w C:\Program Files\Styler
2008-02-09 11:46 --------- d-----w C:\Program Files\LClock
2008-02-08 12:30 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-08 12:30 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-08 12:30 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\Styler
2008-02-03 12:08 --------- d-----w C:\Documents and Settings\Chen\Application Data\vlc
2008-02-03 09:11 --------- d-----w C:\Program Files\3D LOTR Eye of Sauron
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:35 --------- d-----w C:\Documents and Settings\Rold ™\Application Data\vlc
2008-01-31 19:32 --------- d-----w C:\Program Files\FLVPlayer
2008-01-31 19:31 --------- d-----w C:\Program Files\VideoLAN
.
------- Sigcheck -------
789a67335f801d6d429ae49ad82c5e57  C:\WINDOWS\system32\ntkrnlpa.exe
----a-w         2,027,008 2004-08-04 01:07:00  C:\WINDOWS\system32\ntkrnlpa.exe
----a-w         2,027,008 2004-08-04 01:07:00  C:\WINDOWS\system32\VITrans\ntkrnlpa.exe
5d0f5b34f58a6869b297228ef2405282  C:\WINDOWS\system32\ntoskrnl.exe
----a-w         2,160,128 2004-08-04 01:07:00  C:\WINDOWS\system32\ntoskrnl.exe
----a-w         2,160,128 2004-08-04 01:07:00  C:\WINDOWS\system32\VITrans\ntoskrnl.exe
4b0011b8e35843966a3ce5685058420f  C:\WINDOWS\explorer.exe
----a-w         1,422,336 2004-08-04 01:07:00  C:\WINDOWS\explorer.exe
-c--a-w         1,032,192 2004-08-04 01:07:00  C:\WINDOWS\system32\dllcache\explorer.exe
----a-w         1,422,336 2004-08-04 01:07:00  C:\WINDOWS\system32\VITrans\explorer.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:07 15360]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-20 01:27 65536]
"Vista Sidebar"="C:\Program Files\Vista Sidebar\sidebar.exe" [2007-11-20 13:51 524288]
"RocketDock"="D:\installer\Software\vista package\RocketDock\RocketDock.exe" [2007-03-18 14:05 630784]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-11-01 04:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 22:25 1400944]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 16:22 577536 C:\WINDOWS\soundman.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-16 19:58 114688]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-03-02 13:58 921600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 09:07 15360]
C:\Documents and Settings\Chen\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\Rold T\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
Thoosje Vista Sidebar.lnk - C:\Program Files\Vista Sidebar\sidebar.exe [2008-02-09 19:46:35 524288]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-07-28 23:18:09 25214]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Setup.exe [2008-03-04 09:13:05 86016]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\Program Files\Common Files\Stardock\mcpstub.dll 2003-08-25 11:25 139264 C:\Program Files\Common Files\Stardock\MCPStub.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\SIERRA\\Half-Life\\hl.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 11:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11:39]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05c6174e-1777-11dc-a175-0016ecf01d56}]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0b56d46-e390-11db-a14b-0016ecf01d56}]
\Shell\AutoRun\command - I:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 22:38:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-16 22:39:58
ComboFix2.txt  2008-03-16 12:06:51
ComboFix3.txt  2008-03-08 12:24:14
SPYWARE LOG
 
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 03/16/2008 at 10:31 PM
Application Version : 4.0.1154
Core Rules Database Version : 3412
Trace Rules Database Version: 1404
Scan type       : Complete Scan
Total Scan Time : 00:20:37
Memory items scanned      : 212
Memory threats detected   : 0
Registry items scanned    : 5450
Registry threats detected : 0
File items scanned        : 13738
File threats detected     : 0
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14325
 
   Posted 3-17-2008 2:07 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
It´s obvious You have so many infections - >
Crack.#xe;D:\installer\Games\counterstrike\utilities\No CD Check\Half-Life Opposing Force v1.0.0.1 US No-CD Crack;Tool.GameCrack;Renamed.;
Crack.#xe;D:\installer\Games\counterstrike\utilities\No CD Check\Half-Life v1.0.1.6 US No-CD Crack;Tool.GameCrack;Renamed
.;
"Crack files are a special kind of malware that are specifically designed to hide the activities of other viruses and worms, and compromise the operating system so that it may not be repaired. If your machine is infected by using cracks, you will very likely not be able to regain complete control of the system."
 
Let´s try one more "shot" -
 
 and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
 and save it to your desktop.

When you have done this, please boot into Safe Mode (Tap F8 during startup).

Open the extracted folder  - C:\ SDFix  and doubleclick on RunThis.bat to start the script.

Type Y to begin the script. It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. When you hit any key, your computer will reboot. Your system will take longer that normal to restart as the fixtool will be running and removing files.

When your desktop loads, the utility will complete the removal and display Finished. Press any key again to end the script and load your desktop icons.
 
 
 
 
Finally open the SDFix folder on your desktop and copy and paste the contents of Report.txt back in this thread along with fresh hijackthis log,  and tell how things are running


Do NOT post your problem in someone elses thread.

Back to Top
 

roldski
New Member


Date Joined Mar 2008
Total Posts : 8
 
   Posted 3-18-2008 1:55 (GMT +1)    Quote: Virus new folder.exeAlert an admin about: Virus new folder.exe
Hi touch,
Below is the log files of SDFIX and Hijackthis, i still encountered the same problem after the scanning SDfix hope this help us to solve the problem.
thanks,
Rold



[b]SDFix: Version 1.158 [/b]
Run by Rold ™ on Tue 03/18/2008 at 03:27 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:

Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting

[b]Checking Files [/b]:
Trojan Files Found:


Could Not Remove C:\autorun.inf


R