Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
May 16th, 2008, 1:59am
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Unable To Move or Copy Files
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Unable To Move or Copy Files  (Read 474 times)
case
Newbie
*





   


Posts: 8
Unable To Move or Copy Files
« on: Mar 3rd, 2008, 4:46pm »
Quote Quote  Modify Modify

In a huge error of judgment, I ended up downloading a Trojan of my own a few days back. It seems that its primary purpose was to disable/delete my internet gateways (as well as browsers), damage my System Restore function, and lock up all of my files. As a result I am forced to use my fiance's computer to upload the necessary programs to try and restore my computer.
 
I stumbled onto your website the other day in search of help, and I am ever so grateful for the wealth of information present. Using the programs made accessible from your forums, I've run numerous scans, and I thought to have been able to rid myself of the virus. The scans keep coming back clean though I am still in lock-down. I am attempting more scans in order to get the logs onto my flash drive so I can post them.
 
Thanks greatly in advance for your time. Smiley
IP Logged
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #1 on: Mar 3rd, 2008, 6:37pm »
Quote Quote  Modify Modify

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:07 PM, on 3/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.1660Cool
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe
C:\DOCUME~1\Casey\LOCALS~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http:/ /www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http:/ /www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http:/ /www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http:/ /www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http:/ /www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: (no name) - {B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1} - C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [svvkshhzyek] C:\WINDOWS\System32\bjhbsw.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [THIS MIX PLAN BAT] C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [Steam]  (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: []  (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - S-1-5-21-4132917964-2341797327-442734669-1006 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User '?')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS11389X42US
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.1.87.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
 
--
End of file - 11389 bytes
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5270
Re: Unable To Move or Copy Files
« Reply #2 on: Mar 4th, 2008, 12:17am »
Quote Quote  Modify Modify

Welcome to the forum case  Cheesy
 
Yes, it looks like you have a few nasties on your system.  Not knowing what scans you have performed, I would like you to go this first:
 
1.  Please download Combofix.exe and save it on your desktop.
 
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
 
2.  Close all open windows including your browser
 
3.  De-activate all security programs Except your software firewall.
 
4.  Close down as many programs as you can that are in your lower right Notification Tray (next to the clock).  
 
5.  Double click on the ComboFix.exe icon on your desktop to start it running.
 
Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
 
6.  Combofix will create a log when it is completed.  Please post the Combofix log back here.
 
7.  Post a new Hijackthis log.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #3 on: Mar 4th, 2008, 1:57pm »
Quote Quote  Modify Modify

ComboFix 08-03-03.17 - Casey 2008-03-04 11:33:53.1 - NTFSx86
Running from: C:\Documents and Settings\Casey\Desktop\ComboFix.exe
 
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
C:\WINDOWS\system32\uninstall.exe
 
.
(((((((((((((((((((((((((   Files Created from 2008-02-04 to 2008-03-04  )))))))))))))))))))))))))))))))
.
 
2008-03-03 15:11 . 2008-03-03 15:11<DIR>d--------C:\Program Files\Trend Micro
2008-03-03 11:13 . 2008-03-03 11:13<DIR>d--------C:\Documents and Settings\Casey\Application Data\TrojanHunter
2008-03-03 09:53 . 2008-03-03 09:53<DIR>d--------C:\Program Files\CCleaner
2008-03-03 09:52 . 2008-03-03 09:52<DIR>d--------C:\Program Files\TrojanHunter 5.0
2008-02-28 18:15 . 2008-02-28 18:15<DIR>d--------C:\Documents and Settings\Administrator\Application Data\teamspeak2
2008-02-26 23:40 . 2008-03-04 11:19<DIR>d--------C:\Documents and Settings\Casey\Application Data\AVG7
2008-02-26 23:40 . 2008-02-26 23:40110,592--a------C:\WINDOWS\system32\avgfwafu.dll
2008-02-26 23:39 . 2008-02-29 18:49<DIR>d--------C:\Documents and Settings\All Users\Application Data\avg7
2008-02-26 23:24 . 2008-02-26 23:24<DIR>d--------C:\Documents and Settings\Casey\Application Data\Grisoft
2008-02-26 23:24 . 2008-02-26 23:29<DIR>d--------C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-26 23:24 . 2007-05-30 04:1010,872--a------C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-26 16:32 . 2004-06-01 13:37<DIR>d--------C:\Documents and Settings\Administrator\WINDOWS
2008-02-26 16:32 . 2004-06-01 13:48<DIR>d--------C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-26 16:32 . 2004-06-01 15:08<DIR>d--------C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-02-26 13:08 . 2008-02-26 13:22<DIR>d--------C:\Program Files\Antivirus Protection
2008-02-25 12:48 . 2008-02-25 20:23824--a------C:\WINDOWS\system32\svchost
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 19:1817,962----a-wC:\WINDOWS\system32\drivers\GVTDrv.sys
2008-03-03 22:50---------d-----wC:\Program Files\Common Files\Wise Installation Wizard
2008-03-03 17:54---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:01---------d-----wC:\Program Files\Yahoo!
2008-02-26 20:57---------d-----wC:\Program Files\Game Elements
2008-02-26 20:56---------d-----wC:\Program Files\Half Life 2
2008-02-26 20:39---------d-----wC:\Program Files\Spybot - Search & Destroy
2008-02-05 09:01---------d-----wC:\Documents and Settings\Casey\Application Data\Skype
2008-01-30 20:39---------d-----wC:\Program Files\World of Warcraft
2008-01-16 02:45---------d-----wC:\Program Files\iTunes
2008-01-16 02:45---------d-----wC:\Program Files\iPod
2008-01-16 02:41---------d-----wC:\Program Files\QuickTime
2008-01-14 18:51---------d-----wC:\Program Files\Common Files\Adobe
2008-01-13 22:00---------d--h--wC:\Program Files\InstallShield Installation Information
2007-12-07 02:21824,832----a-wC:\WINDOWS\system32\wininet.dll
2007-12-04 18:38550,912----a-wC:\WINDOWS\system32\oleaut32.dll
2006-02-09 12:405,928----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin
.
 
------- Sigcheck -------
 
8f078ae4ed187aaabc0a305146de6716  C:\WINDOWS\system32\svchost.exe
-c----w  12,800 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
-c----w  14,336 2004-08-04 07:56:57  C:\WINDOWS\ServicePackFiles\i386\svchost.exe
----a-w  14,336 2004-08-04 07:56:57  C:\WINDOWS\system32\svchost.exe
 
b409909f6e2e8a7067076ed748abf1e7  C:\WINDOWS\system32\user32.dll
-c--a-w      577,024 2005-03-02 18:19:56  C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
----a-w      578,048 2007-03-08 15:48:36  C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
-c----w      560,128 2003-09-25 16:49:02  C:\WINDOWS\$NtServicePackUninstall$\user32.dll
-c----w      577,024 2004-08-04 07:56:46  C:\WINDOWS\$NtUninstallKB890859$\user32.dll
-c----w      577,024 2005-03-02 18:09:30  C:\WINDOWS\$NtUninstallKB925902$\user32.dll
-c----w      577,024 2004-08-04 07:56:46  C:\WINDOWS\ServicePackFiles\i386\user32.dll
----a-w      577,536 2007-03-08 15:36:28  C:\WINDOWS\system32\user32.dll
-c----w      577,536 2007-03-08 15:36:28  C:\WINDOWS\system32\dllcache\user32.dll
 
2ed0b7f12a60f90092081c50fa0ec2b2  C:\WINDOWS\system32\ws2_32.dll
-c----w  75,264 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
-c----w  82,944 2004-08-04 07:56:46  C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
----a-w  82,944 2004-08-04 07:56:46  C:\WINDOWS\system32\ws2_32.dll
 
806d274c9a6c3aaea5eae8e4af841e04  C:\WINDOWS\system32\wininet.dll
-c--a-w      656,896 2004-09-29 18:27:41  C:\WINDOWS\$hf_mig$\KB834707\SP2QFE\wininet.dll
-c--a-w      657,920 2005-01-27 17:08:42  C:\WINDOWS\$hf_mig$\KB867282\SP2QFE\wininet.dll
-c--a-w      658,944 2005-05-02 20:57:24  C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll
-c--a-w      657,920 2005-03-10 07:43:23  C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll
-c--a-w      660,480 2005-09-02 23:53:41  C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
-c--a-w      659,456 2005-07-03 02:09:33  C:\WINDOWS\$hf_mig$\KB896727\SP2QFE\wininet.dll
-c--a-w      661,504 2005-10-21 03:38:08  C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\wininet.dll
-c--a-w      663,552 2006-03-04 03:58:52  C:\WINDOWS\$hf_mig$\KB912812\SP2QFE\wininet.dll
----a-w      663,552 2006-05-10 05:25:22  C:\WINDOWS\$hf_mig$\KB916281\SP2QFE\wininet.dll
----a-w      664,576 2006-06-23 11:25:31  C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
----a-w      664,576 2006-09-14 08:31:30  C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
----a-w      664,576 2006-10-23 15:34:22  C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
----a-w      823,296 2007-03-07 17:40:29  C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
----a-w      823,808 2007-04-25 09:08:34  C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
----a-w      824,320 2007-06-27 14:40:03  C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
----a-w      825,344 2007-08-20 10:02:11  C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
----a-w      825,344 2007-10-10 23:47:29  C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
----a-w      825,344 2007-12-07 02:01:13  C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
-c----w      588,288 2004-02-07 01:05:06  C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
-c----w      656,384 2004-08-04 07:56:46  C:\WINDOWS\$NtUninstallKB834707$\wininet.dll
-c----w      656,896 2004-09-29 18:47:04  C:\WINDOWS\$NtUninstallKB867282$\wininet.dll
-c----w      656,896 2005-03-10 08:02:35  C:\WINDOWS\$NtUninstallKB883939$\wininet.dll
-c----w      656,896 2005-01-27 17:13:18  C:\WINDOWS\$NtUninstallKB890923$\wininet.dll
-c----w      658,432 2005-07-03 02:11:30  C:\WINDOWS\$NtUninstallKB896688$\wininet.dll
-c----w      657,920 2005-05-02 20:52:36  C:\WINDOWS\$NtUninstallKB896727$\wininet.dll
-c----w      658,432 2005-09-02 23:52:06  C:\WINDOWS\$NtUninstallKB905915$\wininet.dll
-c----w      658,432 2005-10-21 03:39:30  C:\WINDOWS\$NtUninstallKB912812$\wininet.dll
-c----w      658,432 2006-03-04 03:33:45  C:\WINDOWS\$NtUninstallKB916281$\wininet.dll
-c----w      658,432 2006-05-10 05:23:03  C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
-c----w      658,944 2006-06-23 11:02:52  C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
-c----w      658,944 2006-10-23 15:17:53  C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
-c----w      658,944 2006-09-14 08:39:55  C:\WINDOWS\$NtUninstallKB925454_0$\wininet.dll
-c--a-w      664,576 2006-10-23 15:34:22  C:\WINDOWS\ie7\wininet.dll
-c----w      818,688 2006-11-08 05:03:36  C:\WINDOWS\ie7updates\KB928090-IE7\wininet.dll
-c----w      822,784 2007-01-12 17:27:42  C:\WINDOWS\ie7updates\KB931768-IE7\wininet.dll
-c----w      822,784 2007-03-07 17:45:18  C:\WINDOWS\ie7updates\KB933566-IE7\wininet.dll
-c----w      822,784 2007-04-25 08:41:17  C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll
-c----w      823,808 2007-06-27 14:34:59  C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
-c----w      824,832 2007-08-20 10:04:43  C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
-c----w      824,832 2007-10-10 23:56:00  C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
-c----w      656,384 2004-08-04 07:56:46  C:\WINDOWS\ServicePackFiles\i386\wininet.dll
----a-w      824,832 2007-12-07 02:21:48  C:\WINDOWS\system32\wininet.dll
-c--a-w      824,832 2007-12-07 02:21:48  C:\WINDOWS\system32\dllcache\wininet.dll
 
90caff4b094573449a0872a0f919b178  C:\WINDOWS\system32\drivers\tcpip.sys
-c--a-w      359,936 2005-05-25 19:07:12  C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
-c--a-w      360,448 2006-01-13 17:07:08  C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
----a-w      360,576 2006-04-20 12:18:35  C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
----a-w      360,832 2007-10-30 16:53:32  C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
-c----w      332,928 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
-c----w      359,040 2004-08-04 06:14:40  C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
-c----w      359,808 2005-05-25 19:04:02  C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
-c----w      359,808 2006-01-13 02:28:14  C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
-c----w      359,808 2006-04-20 11:51:50  C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
-c----w      359,040 2004-08-04 06:14:40  C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
-c----w      360,064 2007-10-30 17:20:55  C:\WINDOWS\system32\dllcache\tcpip.sys
----a-w      360,064 2007-10-30 17:20:55  C:\WINDOWS\system32\drivers\tcpip.sys
 
01c3346c241652f43aed8e2149881bfe  C:\WINDOWS\system32\winlogon.exe
-c----w      516,608 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
-c----w      502,272 2004-08-04 07:56:57  C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
----a-w      502,272 2004-08-04 07:56:57  C:\WINDOWS\system32\winlogon.exe
 
558635d3af1c7546d26067d5d9b6959e  C:\WINDOWS\system32\drivers\ndis.sys
-c----w      167,552 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
-c----w      182,912 2004-08-04 06:14:28  C:\WINDOWS\ServicePackFiles\i386\ndis.sys
----a-w      182,912 2004-08-04 06:14:28  C:\WINDOWS\system32\drivers\ndis.sys
 
4448006b6bc60e6c027932cfc38d6855  C:\WINDOWS\system32\drivers\ip6fw.sys
-c----w  29,056 2004-08-04 06:00:06  C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
------w  29,056 2004-08-04 06:00:06  C:\WINDOWS\system32\drivers\ip6fw.sys
 
515d30e2c90a3665a2739309334c9283  C:\WINDOWS\system32\ntkrnlpa.exe
-c--a-w    2,056,832 2005-03-02 00:36:40  C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
----a-w    2,059,392 2006-12-19 16:12:16  C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
----a-w    2,059,392 2007-02-28 09:15:56  C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
-c----w    1,949,440 2003-04-24 15:57:54  C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
-c----w    2,056,832 2004-08-04 05:58:58  C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
-c----w    2,056,832 2005-03-02 00:34:40  C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
-c----w    2,057,600 2006-12-19 12:55:39  C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
------w    2,057,600 2007-02-28 08:38:55  C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
-c----w    2,056,832 2004-08-04 05:58:58  C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
----a-w    2,057,600 2007-02-28 08:38:55  C:\WINDOWS\system32\ntkrnlpa.exe
-c----w    2,057,600 2007-02-28 08:38:55  C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
 
582a8dbaa58c3b1f176eb2817daee77c  C:\WINDOWS\system32\ntoskrnl.exe
-c--a-w    2,179,456 2005-03-02 01:04:22  C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
----a-w    2,182,016 2006-12-19 16:51:12  C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
----a-w    2,182,144 2007-02-28 09:55:14  C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
-c----w    1,925,760 2003-04-24 15:57:50  C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
-c----w    2,180,992 2004-08-04 06:19:59  C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
-c----w    2,179,328 2005-03-02 00:59:53  C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
-c----w    2,180,352 2006-12-19 14:17:19  C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
------w    2,180,352 2007-02-28 09:10:57  C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
-c----w    2,180,992 2004-08-04 06:19:59  C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
----a-w    2,180,352 2007-02-28 09:10:57  C:\WINDOWS\system32\ntoskrnl.exe
-c----w    2,180,352 2007-02-28 09:10:57  C:\WINDOWS\system32\dllcache\ntoskrnl.exe
 
97bd6515465659ff8f3b7be375b2ea87  C:\WINDOWS\explorer.exe
----a-w    1,033,216 2007-06-13 10:23:07  C:\WINDOWS\explorer.exe
----a-w    1,033,216 2007-06-13 11:26:03  C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
-c----w    1,004,032 2003-03-31 12:00:00  C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
-c----w    1,032,192 2004-08-04 07:56:49  C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
------w    1,032,192 2004-08-04 07:56:49  C:\WINDOWS\ServicePackFiles\i386\explorer.exe
-c----w    1,033,216 2007-06-13 10:23:07  C:\WINDOWS\system32\dllcache\explorer.exe
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown  
REGEDIT4
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1}]
C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sect hope"="C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="" []
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"svvkshhzyek"="C:\WINDOWS\System32\bjhbsw.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"satmat"="C:\WINDOWS\satmat.exe" [ ]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42 32768]
"THIS MIX PLAN BAT"="C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe" [ ]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2005-12-15 09:05 230512]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2005-12-15 09:05 185456]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2005-04-22 19:49 397312]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 16:26 406016]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056]
"VGAUtil"="C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe" [2007-09-17 14:26 544768]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 16:05 81920]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-26 23:39 579072]
"THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-02-08 11:22 1047712]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-26 23:39 219136]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Planner Reminders Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Planner Reminders Tray Icon.lnk
backup=C:\WINDOWS\pss\Event Planner Reminders Tray Icon.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
 
IP Logged
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #4 on: Mar 4th, 2008, 1:59pm »
Quote Quote  Modify Modify

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Documents and Settings\Travis\Desktop\Progzors\Bittorrent\bittorrent.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EbatesMoeMoneyMaker0]
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
 
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2005-10-08 16:38 190024 C:\Program Files\MessengerPlus! 3\MsgPlus1.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 08:24 1694208 C:\Program Files\Messenger\msmsgs.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\qttask.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-07-06 09:37 1258744 C:\Program Files\Steam\Steam.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
C:\Program Files\Yahoo!\browser\ybrwicon.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YPC]
--a------ 2005-02-11 18:14 352256 C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\aim\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\GigaByte\\VGA Utility Manager\\G-vga.exe"=
"C:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"C:\\Program Files\\Steam\\steamapps\\tenaci0usxt@sbcglobal.net\\counter-strike\\hl.e xe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"C:\\Documents and Settings\\Casey\\Desktop\\Travis\\Desktop\\Progzors\\Bittorrent\\bittorr ent.exe"=
"C:\\Program Files\\GigaByte\\VGA Utility Manager\\gvupdate.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
 
.
Contents of the 'Scheduled Tasks' folder
"2008-02-26 07:00:00 C:\WINDOWS\Tasks\A2C0C52C910B7820.job"
- c:\docume~1\chip\applic~1\2typem~2\Love About Move.exe
"2008-02-26 07:00:00 C:\WINDOWS\Tasks\A8610321902EB43D.job"
- c:\docume~1\chip\applic~1\2typem~1\Love About Move.exe
"2008-02-17 00:29:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-26 07:00:00 C:\WINDOWS\Tasks\B9129C36907105EE.job"
- c:\docume~1\casey\applic~1\2typem~1\Love About Move.exe
.
************************************************************************ **
 
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 11:42:25
Windows 5.1.2600 Service Pack 2 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ...
 
scanning hidden files ...  
 
scan completed successfully  
hidden files: 0  
 
************************************************************************ **
.
Completion time: 2008-03-04 11:45:16
ComboFix-quarantined-files.txt  2008-03-04 19:45:03
.
2008-02-13 06:34:08--- E O F ---  
IP Logged
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #5 on: Mar 4th, 2008, 2:01pm »
Quote Quote  Modify Modify

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:21 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.1660Cool
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http:/ /www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http:/ /www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: (no name) - {B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1} - C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [svvkshhzyek] C:\WINDOWS\System32\bjhbsw.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [THIS MIX PLAN BAT] C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [Steam]  (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - S-1-5-21-4132917964-2341797327-442734669-1006 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User '?')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS11017X42US
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.1.87.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
 
--
End of file - 11017 bytes
IP Logged
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #6 on: Mar 4th, 2008, 2:03pm »
Quote Quote  Modify Modify

I'd like to do a BitDefender and SuperAntiSpyware scan, but I'm having some issues with both IE and Windows Installer. I'm figuring that I'm going to have to do a wide-scale repair for the OS as soon as I can locate my XP boot disk.
 
Thanks again for helping me out this far. Smiley
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5270
Re: Unable To Move or Copy Files
« Reply #7 on: Mar 4th, 2008, 11:41pm »
Quote Quote  Modify Modify

Would you please do the following next:
 
1.  Run another HJT scan.
 
2.  When the scan is completed, place a check mark next to the following items.  BE SURE that these are the only items checked.
 

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
 
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
 
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
 
O2 - BHO: (no name) - {B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1} - C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe (file missing)
 
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
 
O4 - HKLM\..\Run: [svvkshhzyek] C:\WINDOWS\System32\bjhbsw.exe
 
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
 
O4 - HKLM\..\Run: [THIS MIX PLAN BAT] C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe
 
O4 - HKCU\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe
 
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe (User '?')
 
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [Steam] (User '?')
 
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS11017X42US
 
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
 

 
3.  Close your browser
 
4.  Click on Fix Checked at the lower left of the HJT window.  Confirm that you want HJT to fix these items and let it fix them.
 
5.  Close HJT and reboot.
 
Then please do this:
 
1.  Download the latest rulesets for TrojanHunter.  If you are using the Trial Version of TH, please download the manual update file as per the instructions on the link below.
 
http://www.misec.net/trojanhunter/updating/
 
2.  Reboot your computer into SAFE MODE and run a full scan with TrojanHunter.  Let it quarantine what it finds.
 
3.  Reboot back into Normal Mode.  
 
4.  If TH found/quarantined anything, please post back here its Scan Report log and a new HJT log.  
« Last Edit: Mar 4th, 2008, 11:54pm by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #8 on: Mar 15th, 2008, 12:23pm »
Quote Quote  Modify Modify

Sorry for getting back to you so late, this last week has been busy all around. Getting ill didn't help things either. Tongue
 
Anyhow, here's the result -  
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:21 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.1660Cool
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http:/ /www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http:/ /www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: (no name) - {B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1} - C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [svvkshhzyek] C:\WINDOWS\System32\bjhbsw.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [THIS MIX PLAN BAT] C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [sect hope] C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe (User '?')
O4 - HKUS\S-1-5-21-4132917964-2341797327-442734669-1006\..\Run: [Steam]  (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - S-1-5-21-4132917964-2341797327-442734669-1006 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User '?')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS11017X42US
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.1.87.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
 
--
End of file - 11017 bytes
IP Logged
case
Newbie
*





   


Posts: 8
Re: Unable To Move or Copy Files
« Reply #9 on: Mar 15th, 2008, 12:23pm »
Quote Quote  Modify Modify

TrojanHunter Scan Report - Saved 2008-03-08 12:47
 
Error: Directory not found: C:\Documents and Settings\Casey\My Documents\My Music\iTunes\iTunes Music\Huh·Huh·Huh?
Error: Directory not found: C:\Documents and Settings\Casey\My Documents\My Music\iTunes\iTunes Music\Huh·Huh·Huh?
Found possible trojan file: C:\Program Files\Adobe\Adobe Illustrator CS2 Tryout\Support Files\Contents\Windows\Cracked_Illustrator.exe (Generic.FSG)
Error: Directory not found: F:\
Error: Directory not found: F:\
Error: Directory not found: G:\
Error: Directory not found: G:\
Error: Directory not found: H:\
Error: Directory not found: H:\
Error: Directory not found: I:\
Error: Directory not found: I:\
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5270
Re: Unable To Move or Copy Files
« Reply #10 on: Mar 15th, 2008, 12:35pm »
Quote Quote  Modify Modify

Quote:
Logfile of Trend Micro HijackThis v2.0.2  
Scan saved at 12:00:21 PM, on 3/4/2008  

 
The Hijackthis log is dated 04-March-2008.  Please post a current scan log from Hijackthis so that I can see what remains to be fixed.  
 
Quote:
TrojanHunter Scan Report - Saved 2008-03-08 12:47  

 
And the TH scan report is a week old.  
 
Quote:
Found possible trojan file: C:\Program Files\Adobe\Adobe Illustrator CS2 Tryout\Support Files\Contents\Windows\Cracked_Illustrator.exe (Generic.FSG)

 
This Illustrator.exe is most likely an illegal version.  Most of the cracked sources contain trojans, compliments of the crackers.
« Last Edit: Mar 15th, 2008, 12:43pm by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register