Hi there jholland
I am sorry, My comp slowes to a crawl and freezes often and I don't think I can fully run the progs
AdAware keeps finding files from a trojan downloader but doesn't get rid of the problem.
If you have noticed particular unneeded auto starts,or suspicious auto starting services, and very dangerous "Trusted Sites", I would be more than obliged if you could point them out and I can fix them on the Hijackthis
I will try and add here the log files from OTL and Combifix which I managed to run yesterday/today I had to attach the txt files as copy paste made the reply too long
silclay 0 Newbie Poster
Hi there jholland
I am sorry, My comp slowes to a crawl and freezes often and I don't think I can fully run the progs
AdAware keeps finding files from a trojan downloader but doesn't get rid of the problem.
If you have noticed particular unneeded auto starts,or suspicious auto starting services, and very dangerous "Trusted Sites", I would be more than obliged if you could point them out and I can fix them on the Hijackthis
I will try and add here the log files from OTL and Combifix which I managed to run yesterday/todaybut so far the logs I post seem to be too long for the "reply" to work so I am attaching the txt files
ComboFix 10-10-21.02 - dsilver 10/22/2010 7:51:53.1.2 - x86
Running from: C:\mydoc\HijackThis\MalwareBytes forum\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated) {4CA5B9AB-4295-4D4C-9664-0EBE85AE0525}
AV: Trend Micro OfficeScan Antivirus *On-access scanning enabled* (Updated) {061AE366-576E-4716-93BD-961A93D59089}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\dsilver\Favorites\Delphion Intellectual Property Network to search, view and analyze patent collections worldwide..ur
C:\Documents and Settings\dsilver\GoToAssistDownloadHelper.exe
C:\mydoc\MP4 player\16GB\New Folder\AVI-TOOL\Desktop_.ini
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\_000014_.tmp.dll
C:\WINDOWS\system32\_000015_.tmp.dll
C:\WINDOWS\system32\_000016_.tmp.dll
C:\WINDOWS\system32\Icons
C:\WINDOWS\system32\Icons\Acrobat8.ico
C:\WINDOWS\system32\Icons\BGinfo.ico
C:\WINDOWS\system32\Icons\BlackBarry.ico
C:\WINDOWS\system32\Icons\Bosanova.ico
C:\WINDOWS\system32\Icons\CallCent.ico
C:\WINDOWS\system32\Icons\CitrixP.ico
C:\WINDOWS\system32\Icons\CitrixT.ico
C:\WINDOWS\system32\Icons\Code.ico
C:\WINDOWS\system32\Icons\ConnectW.ico
C:\WINDOWS\system32\Icons\CuteFTP7.ico
C:\WINDOWS\system32\Icons\Designer.ico
C:\WINDOWS\system32\Icons\DiskOn.ico
C:\WINDOWS\system32\Icons\eCenter.ico
C:\WINDOWS\system32\Icons\ERP Portal.ico
C:\WINDOWS\system32\Icons\ExcelXP.ico
C:\WINDOWS\system32\Icons\Facsys.ico
C:\WINDOWS\system32\Icons\FixPrt.ico
C:\WINDOWS\system32\Icons\G-Top Icon_v2.ico
C:\WINDOWS\system32\Icons\GeL.ico
C:\WINDOWS\system32\Icons\HRWeb.ico
C:\WINDOWS\system32\Icons\IDMUSER.ico
C:\WINDOWS\system32\Icons\ImgPro.ico
C:\WINDOWS\system32\Icons\Infosite.ico
C:\WINDOWS\system32\Icons\KillNote.ico
C:\WINDOWS\system32\Icons\Msds.ico
C:\WINDOWS\system32\Icons\PerformanceEva.ico
C:\WINDOWS\system32\Icons\PowerPXP.ico
C:\WINDOWS\system32\Icons\printers.ico
C:\WINDOWS\system32\Icons\PTV_MESHEK.ico
C:\WINDOWS\system32\Icons\RMilim.ico
C:\WINDOWS\system32\Icons\RunLoginScript.ico
C:\WINDOWS\system32\Icons\SachrWeb.ico
C:\WINDOWS\system32\Icons\SKBW.ico
C:\WINDOWS\system32\Icons\SmarTeam.ico
C:\WINDOWS\system32\Icons\SmarTeamDocCenter.ico
C:\WINDOWS\system32\Icons\survey.ico
C:\WINDOWS\system32\Icons\TapiRNDPortal.ico
C:\WINDOWS\system32\Icons\winscp376.ico
C:\WINDOWS\system32\Icons\Winzip11.ico
C:\WINDOWS\system32\Icons\Wisdom Portal.ico
C:\WINDOWS\system32\Icons\WordXP.ico
C:\WINDOWS\system32\logs
C:\WINDOWS\system32\zlibwapi.dll
----- BITS: Possible infected sites -----
hxxp://ILPTVSMS31.il.teva.corp:80
.
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.
2010-10-22 08:51:18 . 2010-10-22 08:51:18 -------- d-----w- C:\WINDOWS\system32\Logs
2010-10-19 15:15:59 . 2010-08-26 08:31:38 69976 ----a-w- C:\WINDOWS\system32\drivers\sbapifs.sys
2010-10-19 15:15:58 . 2010-08-26 08:31:38 21464 ----a-w- C:\WINDOWS\system32\drivers\sbaphd.sys
2010-10-19 14:23:52 . 2010-08-26 08:31:35 15880 ----a-w- C:\WINDOWS\system32\lsdelete.exe
2010-10-19 06:29:00 . 2010-08-26 08:31:36 64288 ----a-w- C:\WINDOWS\system32\drivers\Lbd.sys
2010-10-19 05:43:12 . 2010-10-19 05:43:19 -------- dc-h--w- C:\Documents and Settings\All Users\Application Data\{A4716110-A599-4517-A21D-0B81799F4676}
2010-10-19 05:42:19 . 2010-10-19 05:42:19 -------- d-----w- C:\Program Files\Lavasoft
2010-10-15 22:53:08 . 2010-10-15 22:53:08 -------- d-----w- C:\Documents and Settings\LocalService\Application Data\McAfee
2010-10-15 06:20:15 . 2010-10-15 06:20:15 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee
2010-10-14 12:30:13 . 2010-10-14 12:31:56 -------- d-----w- C:\Documents and Settings\dsilver\Local Settings\Application Data\Temp
2010-10-14 12:27:19 . 2010-10-14 13:35:19 -------- d-----w- C:\Documents and Settings\dsilver\Local Settings\Application Data\Google
2010-10-14 12:20:31 . 2010-10-14 12:21:23 -------- d-----w- C:\Documents and Settings\dsilver\Local Settings\Application Data\Deployment
2010-10-13 17:19:11 . 2010-10-13 17:19:11 -------- d-----w- C:\Documents and Settings\dsilver\Application Data\Malwarebytes
2010-10-13 17:18:37 . 2010-10-13 17:18:37 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-10-13 05:23:20 . 2010-10-13 05:23:20 -------- d-----w- C:\Documents and Settings\dsilver\Local Settings\Application Data\VS Revo Group
2010-10-13 05:22:17 . 2009-12-30 10:20:54 27064 ----a-w- C:\WINDOWS\system32\drivers\revoflt.sys
2010-10-13 05:22:11 . 2010-10-13 05:22:11 -------- d-----w- C:\Program Files\VS Revo Group
2010-10-12 05:58:34 . 2010-10-12 06:00:05 -------- d-----w- C:\Documents and Settings\dsilver\Application Data\AVG
2010-10-12 05:54:42 . 2010-10-13 07:36:45 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2010-10-11 18:34:46 . 2010-10-11 18:34:46 -------- d-----w- C:\$AVG
2010-10-11 11:23:49 . 2010-10-11 11:23:49 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Common Files
2010-10-11 11:21:37 . 2010-10-16 14:45:06 -------- d-----w- C:\WINDOWS\system32\drivers\AVG
2010-10-11 11:21:37 . 2010-10-13 06:27:11 -------- d-----w- C:\Documents and Settings\All Users\Application Data\AVG10
2010-10-11 11:18:08 . 2010-10-13 07:37:01 -------- d-----w- C:\Program Files\AVG
2010-10-11 11:16:23 . 2010-10-11 11:19:32 -------- d-----w- C:\Documents and Settings\All Users\Application Data\MFAData
2010-10-06 14:13:33 . 2010-10-06 14:13:37 -------- d-----w- C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fae3e6b1-1936-40d6-9acc-59ebcf661ccb}]
2010-09-06 17:49:04 2735200 ----a-w- C:\Program Files\ImTranslator_Pro\tbImT0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fae3e6b1-1936-40d6-9acc-59ebcf661ccb}"= "C:\Program Files\ImTranslator_Pro\tbImT0.dll" [2010-09-06 17:49:04 2735200]
The attachment preview is chopped off after the first 10 KB. Please download the entire file.
O T L E x t r a s l o g f i l e c r e a t e d o n : 1 0 / 2 1 / 2 0 1 0 7 : 1 7 : 3 2 P M - R u n 1
O T L b y O l d T i m e r - V e r s i o n 3 . 2 . 1 6 . 0 F o l d e r = C : \ D o c u m e n t s a n d S e t t i n g s \ d s i l v e r \ D e s k t o p
W i n d o w s X P P r o f e s s i o n a l E d i t i o n S e r v i c e P a c k 3 ( V e r s i o n = 5 . 1 . 2 6 0 0 ) - T y p e = N T W o r k s t a t i o n
I n t e r n e t E x p l o r e r ( V e r s i o n = 8 . 0 . 6 0 0 1 . 1 8 7 0 2 )
L o c a l e : 0 0 0 0 0 4 0 9 | C o u n t r y : U n i t e d S t a t e s | L a n g u a g e : E N U | D a t e F o r m a t : M / d / y y y y
2 . 0 0 G b T o t a l P h y s i c a l M e m o r y | 1 . 0 0 G b A v a i l a b l e P h y s i c a l M e m o r y | 4 2 . 0 0 % M e m o r y f r e e
5 . 0 0 G b P a g i n g F i l e | 4 . 0 0 G b A v a i l a b l e i n P a g i n g F i l e | 7 8 . 0 0 % P a g i n g F i l e f r e e
P a g i n g f i l e l o c a t i o n ( s ) : C : \ p a g e f i l e . s y s 3 0 5 7 5 0 9 2 [ b i n a r y d a t a ]
% S y s t e m D r i v e % = C : | % S y s t e m R o o t % = C : \ W I N D O W S | % P r o g r a m F i l e s % = C : \ P r o g r a m F i l e s
D r i v e C : | 2 3 2 . 8 8 G b T o t a l S p a c e | 1 3 5 . 5 1 G b F r e e S p a c e | 5 8 . 1 9 % S p a c e F r e e | P a r t i t i o n T y p e : N T F S
C o m p u t e r N a m e : P T V N 0 3 5 8 9 7 | U s e r N a m e : d s i l v e r | N O T l o g g e d i n a s A d m i n i s t r a t o r .
B o o t M o d e : N o r m a l | S c a n M o d e : A l l u s e r s | Q u i c k S c a n
C o m p a n y N a m e W h i t e l i s t : O n | S k i p M i c r o s o f t F i l e s : O n | N o C o m p a n y N a m e W h i t e l i s t : O n | F i l e A g e = 9 0 D a y s
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = E x t r a R e g i s t r y ( S a f e L i s t ) = = = = = = = = = = [ / c o l o r ]
[ c o l o r = # E 5 6 7 1 7 ] = = = = = = = = = = F i l e A s s o c i a t i o n s = = = = = = = = = = [ / c o l o r ]
[ H K E Y _ L O C A L _ M A C H I N E \ S O F T W A R E \ C l a s s e s \ <