WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionI have BankerFox & Nuqel on my PC and need your help - Page 1 EmptyRe: I have BankerFox & Nuqel on my PC and need your help

more_horiz
Here's the Combofix log. Thanks

ComboFix 09-12-02.05 - Mark Jeffords 12/02/2009 22:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.148 [GMT -5:00]
Running from: c:\documents and settings\Mark Jeffords\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj
c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj\amwxsysguard.exe
c:\program files\Internet Explorer\msimg32.dll
c:\program files\PlaySushi\PSTExt.dll
c:\windows\desktop
c:\windows\desktop\Diva Starz(TM) CD-ROM.lnk
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\lsp.dll
c:\windows\system32\mydll.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.

2009-12-01 00:41 . 2009-12-01 00:41 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\Malwarebytes
2009-11-30 21:13 . 2009-11-30 21:13 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Leadertech
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Malwarebytes
2009-11-30 20:28 . 2009-11-30 20:28 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\Malwarebytes
2009-11-30 11:56 . 2009-11-30 11:56 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 18:40 . 2004-09-08 03:13 24520 ----a-w- c:\documents and settings\Administrator.JEFFORDS1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-29 17:18 . 2009-11-29 17:18 -------- d-----w- c:\program files\Trend Micro
2009-11-13 01:25 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-13 01:24 . 2009-11-13 01:24 -------- d-----w- c:\program files\iPod
2009-11-13 01:23 . 2009-11-13 01:25 -------- d-----w- c:\program files\iTunes
2009-11-13 01:13 . 2009-11-13 01:13 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 04:22 . 2009-10-29 01:42 -------- d-----w- c:\program files\PlaySushi
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-11-29 18:26 . 2004-09-08 03:06 10344 ----a-w- c:\windows\system32\drivers\symlcbrd.sys
2009-11-29 00:51 . 2009-10-29 01:44 -------- d-----w- c:\program files\qhaqan
2009-11-13 01:23 . 2008-12-25 16:57 -------- d-----w- c:\program files\Common Files\Apple
2009-11-04 21:45 . 2005-02-22 20:54 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\AdobeUM
2009-11-03 12:25 . 2008-05-01 01:47 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\U3
2009-11-01 02:02 . 2009-10-29 22:43 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\U3
2009-10-30 00:04 . 2004-09-08 03:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-29 23:31 . 2009-10-29 23:31 46640 ----a-w- c:\windows\system32\msln.exe
2009-10-29 19:49 . 2009-10-29 19:49 -------- d-----w- c:\program files\MSN Toolbar Installer
2009-10-28 00:16 . 2008-01-19 14:32 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\FrostWire
2009-10-27 23:45 . 2009-10-27 23:45 43824 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-27 21:54 . 2009-10-27 21:54 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\AdobeUM
2009-10-27 15:42 . 2009-10-27 15:42 188928 ----a-w- c:\documents and settings\Alisa Jeffords\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
2009-10-27 02:50 . 2004-10-24 19:39 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\AdobeUM
2009-10-24 13:36 . 2009-06-02 14:35 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Apple Computer
2009-10-19 21:39 . 2005-03-05 22:36 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\AdobeUM
2009-10-15 18:40 . 2008-12-25 17:01 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Apple Computer
2009-10-15 18:32 . 2009-10-15 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-15 18:29 . 2009-10-15 18:29 -------- d-----w- c:\program files\QuickTime
2009-10-14 20:49 . 2005-01-20 00:07 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\AdobeUM
2009-09-25 05:49 . 2006-06-23 16:33 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:48 . 2004-08-04 07:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2002-08-29 10:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2004-03-30 01:48 58880 ----a-w- c:\windows\system32\msasn1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-03 4800512]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 131072]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 172032]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\System32\hphmon06.exe" [2004-06-07 659456]
"HostManager"="c:\program files\Common Files\AOL\1107989059\ee\AOLSoftware.exe" [2006-09-26 50736]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 99480]
"PaperPort PTD"="c:\program files\Scansoft\PaperPort\pptd40nt.exe" [2002-09-23 45108]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 36864]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2003-08-18 98304]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\SYSTEM32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\SYSTEM32\CTASIO.DLL [2003-02-20 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1107989059\\EE\\aolsoftware.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/22/2007 5:11 PM 24652]
S3 lsscdbhk;lsscdbhk;\??\c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys --> c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys [?]
S3 MMCD;MMCD;\??\c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS --> c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS [?]
S3 NwudfRd;NwudfRd;\??\c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys --> c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-12-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-12-02 c:\windows\Tasks\HP Usg Daily FY04.job
- c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe [2004-06-07 04:53]

2009-09-18 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-20 03:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = "c:\program files\MSN Gaming Zone\Windows\CHKRZM.EXE"
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} - hxxps://www.creditcommander.com/cabs/htmlprint.cab
FF - ProfilePath - c:\documents and settings\Mark Jeffords\Application Data\Mozilla\Firefox\Profiles\q3idopo5.default\
FF - component: c:\program files\BearShare Applications\Personalization\FF_v1047\components\BearSharePersonalizationFF_v1047.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -

AddRemove-BearShare - c:\program files\BearShare Applications\BearShare\UninstallSurvey.exe c:\progra~1\BEARSH~1\BEARSH~1\UNWISE.EXE
AddRemove-Playsushi - c:\program files\PlaySushi\psuninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RegPowerClean2007_is1 - c:\program files\Winferno\RegistryPowerCleaner\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 23:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\.mfp]
@DACL=(02 0000)
@="MacromediaFlashPaper.MacromediaFlashPaper"
"Content Type"="application/x-shockwave-flash"

[HKEY_LOCAL_MACHINE\software\Classes\.sol]
@DACL=(02 0000)
"Content Type"="text/plain"

[HKEY_LOCAL_MACHINE\software\Classes\.sor]
@DACL=(02 0000)
"Content Type"="text/plain"
.
Completion time: 2009-12-02 23:43
ComboFix-quarantined-files.txt 2009-12-03 04:42

Pre-Run: 106,350,702,592 bytes free
Post-Run: 108,277,817,344 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - A1C1E8F05A049126A4E5096921A0AC67

descriptionI have BankerFox & Nuqel on my PC and need your help - Page 1 EmptyRe: I have BankerFox & Nuqel on my PC and need your help

more_horiz
Hello.

I see that you are running Frostwire.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Ask Toolbar
    FrostWire 4.17.0
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_03
    Java 2 Runtime Environment, SE v1.4.2_13
    Java(TM) 6 Update 13
    Java(TM) 6 Update 3MediaBar 2.0 (BearShare)
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Viewpoint Toolbar

Please download the OTMoveIt by OldTimer.

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :services
    lsscdbhk
    MMCD
    NwudfRd

    :files
    c:\documents and settings\Lauren Jeffords\Application Data\FrostWire
    c:\documents and settings\Lauren Jeffords\Application Data\Viewpoint
    c:\program files\Viewpoint
    c:\program files\FrostWire


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
I have BankerFox & Nuqel on my PC and need your help - Page 1 DXwU4
I have BankerFox & Nuqel on my PC and need your help - Page 1 VvYDg
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum