JohnGoodheart
asked on
Cannot remove virus Backdoor.Win32.Rbot.bll from my computer!!!
I am using Zone Alarm Serurity Suite. It has identified virus Backdoor.Win32.Rbot.bll but i cannot remove it, everytime i do the scan it is still there. Any suggestions?
I suspect the Virus self restores from a carrier file, have a look for the following suspects via Search:
%SYSTEM%\ iwghnotnzk.exe
%system%\ wuauclt28.exe
btorrent.exe
id161.exe
mybot.exe
r1ne.exe
rr1.exe
rr3.exe
steam.exe
wave1.exe
xwinupdaterarx.exe
zzz.exe
WinMIS.exe
Delete any of these, if btorrent or steam are 2 programs you use then download these again after you rid the virus.
Now boot into safemode with networking and go to http://www.pandasoftware.com/products/activescan
run the scan and hopefuly it should remove the trojan.
Hth
%SYSTEM%\ iwghnotnzk.exe
%system%\ wuauclt28.exe
btorrent.exe
id161.exe
mybot.exe
r1ne.exe
rr1.exe
rr3.exe
steam.exe
wave1.exe
xwinupdaterarx.exe
zzz.exe
WinMIS.exe
Delete any of these, if btorrent or steam are 2 programs you use then download these again after you rid the virus.
Now boot into safemode with networking and go to http://www.pandasoftware.com/products/activescan
run the scan and hopefuly it should remove the trojan.
Hth
ASKER
OK will try these when i get off from work
thank you
thank you
Can we look at a hijackthis log? RBot variants are also called SDBot by other scanners.
http://danborg.org/spy/hjt/alternativ.exe
This tool also removes SDBot/RBot/IRCBot variants.
Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
http://danborg.org/spy/hjt/alternativ.exe
This tool also removes SDBot/RBot/IRCBot variants.
Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
ASKER
Sorry it's taken so long to get back to this!!!! Prblems on the homestead.
Ok. Ive tried everything from all 3 solutitions and no luck. the virus is still there. I run all the antivirus progams in safe mode, disable system restore and run this program from rpggamergirl and this is the results
SDFix: Version 1.94
Run by k on Tue 07/31/2007 at 06:01 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\k\Desktop\SDFi x\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\svdhos t.exe - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchos t.exe
No streams found.
C:\WINDOWS\system32\ntoskr nl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system \currentco ntrolset\s ervices\sh aredaccess \parameter s\firewall policy\sta ndardprofi le\authori zedapplica tions\list ]
"%windir%\\system32\\sessm gr.exe"="% windir%\\s ystem32\\s essmgr.exe :*:enabled :@xpsp2res .dll,-2201 9"
"C:\\WINDOWS\\system32\\Zo neLabs\\vs mon.exe"=" C:\\WINDOW S\\system3 2\\ZoneLab s\\vsmon.e xe:*:Enabl ed:TrueVec tor Service"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C :\\Program Files\\MSN Messenger\\msnmsgr.exe:*:E nabled:Win dows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"=" C:\\Progra m Files\\MSN Messenger\\livecall.exe:*: Enabled:Wi ndows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe" ="C:\\Prog ram Files\\iTunes\\iTunes.exe: *:Enabled: iTunes"
"C:\\Program Files\\Yahoo!\\Messenger\\ YahooMesse nger.exe"= "C:\\Progr am Files\\Yahoo!\\Messenger\\ YahooMesse nger.exe:* :Enabled:Y ahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\ YServer.ex e"="C:\\Pr ogram Files\\Yahoo!\\Messenger\\ YServer.ex e:*:Enable d:Yahoo! FT Server"
"C:\\Program Files\\LimeWire\\LimeWire. exe"="C:\\ Program Files\\LimeWire\\LimeWire. exe:*:Enab led:LimeWi re"
"C:\\Program Files\\BitTorrent_DNA\\dna .exe"="C:\ \Program Files\\BitTorrent_DNA\\dna .exe:*:Ena bled:DNA"
"C:\\Program Files\\BitTorrent\\bittorr ent.exe"=" C:\\Progra m Files\\BitTorrent\\bittorr ent.exe:*: Enabled:Bi tTorrent"
[HKEY_LOCAL_MACHINE\system \currentco ntrolset\s ervices\sh aredaccess \parameter s\firewall policy\dom ainprofile \authorize dapplicati ons\list]
"%windir%\\system32\\sessm gr.exe"="% windir%\\s ystem32\\s essmgr.exe :*:enabled :@xpsp2res .dll,-2201 9"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C :\\Program Files\\MSN Messenger\\msnmsgr.exe:*:E nabled:Win dows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"=" C:\\Progra m Files\\MSN Messenger\\livecall.exe:*: Enabled:Wi ndows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\k\Desktop\SDFi x\SDFix\ba ckups\back ups.zip
Files with Hidden Attributes:
C:\WINDOWS\system32\svehos t.exe.vzr
C:\NTBOOTDD.SYS
C:\WINDOWS\system32\config \default.t mp.LOG
C:\WINDOWS\system32\config \software. tmp.LOG
C:\WINDOWS\system32\config \system.tm p.LOG
Finished
Ok. Ive tried everything from all 3 solutitions and no luck. the virus is still there. I run all the antivirus progams in safe mode, disable system restore and run this program from rpggamergirl and this is the results
SDFix: Version 1.94
Run by k on Tue 07/31/2007 at 06:01 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\k\Desktop\SDFi
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\svdhos
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchos
No streams found.
C:\WINDOWS\system32\ntoskr
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system
"%windir%\\system32\\sessm
"C:\\WINDOWS\\system32\\Zo
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C
"C:\\Program Files\\MSN Messenger\\livecall.exe"="
"C:\\Program Files\\iTunes\\iTunes.exe"
"C:\\Program Files\\Yahoo!\\Messenger\\
"C:\\Program Files\\Yahoo!\\Messenger\\
"C:\\Program Files\\LimeWire\\LimeWire.
"C:\\Program Files\\BitTorrent_DNA\\dna
"C:\\Program Files\\BitTorrent\\bittorr
[HKEY_LOCAL_MACHINE\system
"%windir%\\system32\\sessm
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C
"C:\\Program Files\\MSN Messenger\\livecall.exe"="
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\k\Desktop\SDFi
Files with Hidden Attributes:
C:\WINDOWS\system32\svehos
C:\NTBOOTDD.SYS
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
Finished
Hi
I am convinced that this may have to do with the bittorrent exe, can you rename the following 2 files
bittorent.exe and dna.exe into .old files, run the remover again and reboot.
Trojan gone?
hth
I am convinced that this may have to do with the bittorrent exe, can you rename the following 2 files
bittorent.exe and dna.exe into .old files, run the remover again and reboot.
Trojan gone?
hth
ASKER
I could not find those files even in c:/programs/bittorent. Since that last list of files i have run spysweeper, spybot, adware,and couple of other programs. maybe they remove that file?(bittorent.exe and dna.exe)
i will run the program again and post another list after i get back from seeing the simpsons movie.
the virus is still present according to zone alarm security suite
i will run the program again and post another list after i get back from seeing the simpsons movie.
the virus is still present according to zone alarm security suite
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
indows XP Professional 5.1.2600.2.1252.1.1033.18. True
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
C:\WINDOWS\system32\driver s\npf.sys
C:\WINDOWS\system32\packet .dll
C:\WINDOWS\system32\wpcap. dll
(((((((((((((((((((((((((( (((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 )))))))))))))))))))))))))) )))))
2007-08-02 19:36 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-01 13:54 22,080 --a------ C:\WINDOWS\system32\driver s\sshrmd.s ys
2007-08-01 13:54 21,056 --a------ C:\WINDOWS\system32\driver s\sskbfd.s ys
2007-08-01 13:54 20,544 --a------ C:\WINDOWS\system32\driver s\SSFS0509 .sys
2007-08-01 13:54 144,960 --a------ C:\WINDOWS\system32\driver s\ssidrv.s ys
2007-08-01 13:54 <DIR> d-------- C:\Program Files\Webroot
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLI C~1\Webroo t
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\k\APPLIC~1\Web root
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI C~1\Webroo t
2007-07-31 23:34 <DIR> d--hs---- C:\WINDOWS\CSC
2007-07-31 18:00 <DIR> d-------- C:\WINDOWS\ERUNT
2007-07-20 22:30 983,083 --a------ C:\WINDOWS\system32\LXBAGF .DLL
2007-07-20 22:30 90,112 --a------ C:\WINDOWS\system32\LXBACU R.DLL
2007-07-20 22:30 86,016 --a------ C:\WINDOWS\system32\LXBAIH .EXE
2007-07-20 22:30 77,824 --a------ C:\WINDOWS\system32\LXBALC NP.DLL
2007-07-20 22:30 73,728 --a------ C:\WINDOWS\system32\lxbapw r.dll
2007-07-20 22:30 69,632 --a------ C:\WINDOWS\system32\LXBACU .DLL
2007-07-20 22:30 57,344 --a------ C:\WINDOWS\system32\lxbaci nf.dll
2007-07-20 22:30 544,768 --a------ C:\WINDOWS\system32\LXBALS NT.EXE
2007-07-20 22:30 49,152 --a------ C:\WINDOWS\system32\lxbaco in.dll
2007-07-20 22:30 466,944 --a------ C:\WINDOWS\system32\LXBAJS WR.DLL
2007-07-20 22:30 40,960 --a------ C:\WINDOWS\system32\INSTMO N.EXE
2007-07-20 22:30 303,104 --a------ C:\WINDOWS\system32\LEXBCE S.EXE
2007-07-20 22:30 294,912 --a------ C:\WINDOWS\system32\LXBAUT IL.DLL
2007-07-20 22:30 286,720 --a------ C:\WINDOWS\system32\LXBAPM NT.DLL
2007-07-20 22:30 286,720 --a------ C:\WINDOWS\system32\lxbaco mm.dll
2007-07-20 22:30 217,088 --a------ C:\WINDOWS\system32\LXBALC NT.DLL
2007-07-20 22:30 201,216 --a------ C:\WINDOWS\system32\LEXP2P 32.DLL
2007-07-20 22:30 196,096 --a------ C:\WINDOWS\system32\LEX2KU SB.DLL
2007-07-20 22:30 192,512 --a------ C:\WINDOWS\system32\lexlmp m.dll
2007-07-20 22:30 174,592 --a------ C:\WINDOWS\system32\LEXPPS .EXE
2007-07-20 22:30 155,648 --a------ C:\WINDOWS\system32\LEXPIN G.EXE
2007-07-20 22:30 147,456 --a------ C:\WINDOWS\system32\LEXBCE .DLL
2007-07-20 22:30 126,976 --a------ C:\WINDOWS\system32\LXBACF G.EXE
2007-07-18 12:10 <DIR> d-------- C:\Program Files\PTDD Group
2007-07-17 19:48 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSE R.DAT
2007-07-17 18:47 <DIR> d-------- C:\Program Files\PowerQuest
2007-07-17 15:52 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLI C~1\Google
2007-07-17 15:47 <DIR> d-------- C:\WINDOWS\Prefetch
2007-07-17 15:41 9,728 --a--c--- C:\WINDOWS\system32\dllcac he\rwnh.dl l
2007-07-17 15:41 9,728 --a--c--- C:\WINDOWS\system32\dllcac he\query.e xe
2007-07-17 15:41 9,216 --a--c--- C:\WINDOWS\system32\dllcac he\wamps51 .dll
2007-07-17 15:41 86,073 --a--c--- C:\WINDOWS\system32\dllcac he\voicesu b.dll
2007-07-17 15:41 8,704 --a--c--- C:\WINDOWS\system32\dllcac he\snmptra p.exe
2007-07-17 15:41 79,872 --a--c--- C:\WINDOWS\system32\dllcac he\rwia330 .dll
2007-07-17 15:41 79,872 --a--c--- C:\WINDOWS\system32\dllcac he\rwia001 .dll
2007-07-17 15:41 76,800 --a--c--- C:\WINDOWS\system32\dllcac he\wam51.d ll
2007-07-17 15:41 76,288 --a--c--- C:\WINDOWS\system32\dllcac he\uniime. dll
2007-07-17 15:41 73,728 --a--c--- C:\WINDOWS\system32\dllcac he\w3ext.d ll
2007-07-17 15:41 70,144 --a--c--- C:\WINDOWS\system32\dllcac he\pintlph r.exe
2007-07-17 15:41 7,680 --a--c--- C:\WINDOWS\system32\dllcac he\pwsdata .dll
2007-07-17 15:41 7,168 --a--c--- C:\WINDOWS\system32\dllcac he\EXCH_sn prfdll.dll
2007-07-17 15:41 67,584 --a--c--- C:\WINDOWS\system32\dllcac he\pmigrat e.dll
2007-07-17 15:41 6,144 --a--c--- C:\WINDOWS\system32\dllcac he\snmpmib .dll
2007-07-17 15:41 6,144 --a--c--- C:\WINDOWS\system32\dllcac he\pmxgl.d ll
2007-07-17 15:41 57,856 --a--c--- C:\WINDOWS\system32\dllcac he\EXCH_sc ripto.dll
2007-07-17 15:41 53,760 --a--c--- C:\WINDOWS\system32\dllcac he\pintlcs d.dll
2007-07-17 15:41 53,248 --a--c--- C:\WINDOWS\system32\dllcac he\wamreg5 1.dll
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac he\w3svapi .dll
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac he\smimsgi f.dll
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac he\smierrs y.dll
2007-07-17 15:41 48,256 --a--c--- C:\WINDOWS\system32\dllcac he\w32.dll
2007-07-17 15:41 46,592 --a--c--- C:\WINDOWS\system32\dllcac he\svcext5 1.dll
2007-07-17 15:41 46,592 --a--c--- C:\WINDOWS\system32\dllcac he\sspifil t.dll
2007-07-17 15:41 456,704 --a--c--- C:\WINDOWS\system32\dllcac he\smtpsvc .dll
2007-07-17 15:41 455,168 --a--c--- C:\WINDOWS\system32\dllcac he\tintset p.exe
2007-07-17 15:41 45,056 --a--c--- C:\WINDOWS\system32\dllcac he\ssinc51 .dll
2007-07-17 15:41 44,032 --a--c--- C:\WINDOWS\system32\dllcac he\tintlph r.exe
2007-07-17 15:41 426,041 --a--c--- C:\WINDOWS\system32\dllcac he\voicepa d.dll
2007-07-17 15:41 41,600 --a--c--- C:\WINDOWS\system32\dllcac he\weitekp 9.dll
2007-07-17 15:41 40,448 --a--c--- C:\WINDOWS\system32\dllcac he\snmpthr d.dll
2007-07-17 15:41 4,608 --a--c--- C:\WINDOWS\system32\dllcac he\w3ctrs5 1.dll
2007-07-17 15:41 4,096 --a--c--- C:\WINDOWS\system32\dllcac he\rpcref. dll
2007-07-17 15:41 38,912 --a--c--- C:\WINDOWS\system32\dllcac he\sm9aw.d ll
2007-07-17 15:41 363,520 --a--c--- C:\WINDOWS\system32\dllcac he\w3svc.d ll
2007-07-17 15:41 36,927 --a--c--- C:\WINDOWS\system32\dllcac he\padrs41 1.dll
2007-07-17 15:41 358,400 --a--c--- C:\WINDOWS\system32\dllcac he\snmpinc l.dll
2007-07-17 15:41 32,768 --a--c--- C:\WINDOWS\system32\dllcac he\snmp.ex e
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac he\smb6w.d ll
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac he\sma3w.d ll
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac he\pagecnt .dll
2007-07-17 15:41 31,232 --a--c--- C:\WINDOWS\system32\dllcac he\weitekp 9.sys
2007-07-17 15:41 31,232 --a--c--- C:\WINDOWS\system32\dllcac he\tools.d ll
2007-07-17 15:41 30,208 --a--c--- C:\WINDOWS\system32\dllcac he\sm87w.d ll
2007-07-17 15:41 30,208 --a--c--- C:\WINDOWS\system32\dllcac he\sm81w.d ll
2007-07-17 15:41 29,184 --a--c--- C:\WINDOWS\system32\dllcac he\sm8cw.d ll
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac he\sm93w.d ll
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac he\sm92w.d ll
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac he\rw330ex t.dll
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac he\sm90w.d ll
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac he\sm8dw.d ll
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac he\sm8aw.d ll
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac he\sm89w.d ll
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac he\EXCH_se os.dll
2007-07-17 15:41 259,072 --a--c--- C:\WINDOWS\system32\dllcac he\snmpcl. dll
2007-07-17 15:41 25,088 --a--c--- C:\WINDOWS\system32\dllcac he\sm59w.d ll
2007-07-17 15:41 24,576 --a--c--- C:\WINDOWS\system32\dllcac he\rw001ex t.dll
2007-07-17 15:41 236,544 --a--c--- C:\WINDOWS\system32\dllcac he\smi2smi r.exe
2007-07-17 15:41 23,040 --a--c--- C:\WINDOWS\system32\dllcac he\EXCH_re gtrace.exe
2007-07-17 15:41 221,696 --a--c--- C:\WINDOWS\system32\dllcac he\seo.dll
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
2007-08-02 20:43 870688 --ahs---- C:\WINDOWS\system32\driver s\fidbox2. dat
2007-08-02 20:43 82760 --ahs---- C:\WINDOWS\system32\driver s\fidbox2. idx
2007-08-02 20:43 78088224 --ahs---- C:\WINDOWS\system32\driver s\fidbox.d at
2007-08-02 20:43 384 --a------ C:\WINDOWS\system32\DVCSta teBkp-{000 00002-0000 0000-00000 004-000011 02-0000000 4-20021102 }.dat
2007-08-02 20:43 384 --a------ C:\WINDOWS\system32\DVCSta te-{000000 02-0000000 0-00000004 -00001102- 00000004-2 0021102}.d at
2007-08-02 20:43 1051136 --ahs---- C:\WINDOWS\system32\driver s\fidbox.i dx
2007-08-02 01:20 512 --a------ C:\ScanSectorLog.dat
2007-07-30 16:16 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Mai lFrontier
2007-07-20 22:30 --------- d-------- C:\Program Files\Lexmark X5100 Series
2007-07-19 17:46 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-19 00:31 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Azu reus
2007-07-19 00:29 --------- d-------- C:\Program Files\Google
2007-07-19 00:29 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-17 15:53 --------- d-------- C:\Program Files\InterActual
2007-07-17 15:36 23312 --a------ C:\WINDOWS\system32\emptyr egdb.dat
2007-07-17 15:36 --------- d-------- C:\Program Files\Messenger
2007-07-16 13:58 --------- d-------- C:\Program Files\ProxyWay
2007-07-09 11:46 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cam frog
2007-07-08 18:35 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Lim eWire
2007-07-05 22:51 --------- d-------- C:\Program Files\Azureus
2007-07-05 17:12 685816 --a------ C:\WINDOWS\system32\driver s\sptd.sys
2007-07-03 14:01 --------- d-------- C:\Program Files\exPressit S.E. 2.1
2007-07-02 10:05 --------- d-------- C:\DOCUME~1\k\APPLIC~1\App le Computer
2007-06-25 18:06 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cre ative
2007-06-25 17:55 --------- d-------- C:\Program Files\Creative
2007-06-25 17:52 184 --a------ C:\WINDOWS\system32\e00000 2.dat
2007-06-25 17:51 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cre ative ASR2
2007-06-16 20:04 --------- d-------- C:\Program Files\Avi2Dvd
2007-06-16 19:57 --------- d-------- C:\Program Files\AviSynth 2.5
2007-06-15 21:18 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Goo gle
2007-05-29 19:58 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-05-29 19:58 286720 --a------ C:\WINDOWS\SETUP1.EXE
2007-05-25 13:27 25088 --a------ C:\WINDOWS\system32\msxml3 a.dll
2007-05-13 19:28 528 --a------ C:\WINDOWS\eReg.dat
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex e" [2007-03-09 04:02]
"AsioReg"="REGSVR32.exe" [2004-08-03 18:56 C:\WINDOWS\system32\regsvr 32.exe]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS \Surround Mixer\CTSysVol.exe" [2003-07-02 10:03]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS \DVDAudio\ CTDVDDET.E XE" [2003-06-18 01:00]
"CTHelper"="CTHELPER.EXE" [2003-06-19 23:55 C:\WINDOWS\system32\CTHELP ER.EXE]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe " [2007-02-16 13:54]
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49]
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 15:54]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo! \MESSEN~1\ YAHOOM~1.e xe" [2007-03-27 15:22]
"Hide IP Platinum"="C:\Program Files\Hide IP Platinum\hideippla.exe" []
"BitTorrent"="C:\Program Files\BitTorrent\bittorren t.exe" []
"RemoteCenter"="C:\Program Files\Creative\MediaSource \RemoteCon trol\RCMan .EXE" [2003-06-12 09:47]
"ProxyWay"="C:\Program Files\ProxyWay\proxyway.ex e" []
"AlcoholAutomount"="C:\Pro gram Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 06:27]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe " [2004-08-04 04:06]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupfold er\C:^Docu ments and Settings^All Users^Start Menu^Programs^Startup^Adob e Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adob e Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adob e Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupfold er\C:^Docu ments and Settings^All Users^Start Menu^Programs^Startup^Adob e Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adob e Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adob e Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupfold er\C:^Docu ments and Settings^All Users^Start Menu^Programs^Startup^Goog le Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Goog le Updater.lnk
backup=C:\WINDOWS\pss\Goog le Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupfold er\C:^Docu ments and Settings^All Users^Start Menu^Programs^Startup^Nort on GoBack.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nort on GoBack.lnk
backup=C:\WINDOWS\pss\Nort on GoBack.lnkCommon Startup
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ BgMonitor_ {79662E04- 7C6C-4d9f- 84C7-88D8A 56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonito r.exe"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS \DVDAudio\ CTDVDDET.E XE
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ CTHelper]
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS \Surround Mixer\CTSysVol.exe /r
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ DMXLaunche r]
"C:\Program Files\Roxio\Media Experience\DMXLauncher.exe "
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ iTunesHelp er]
"C:\Program Files\iTunes\iTunesHelper. exe"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Lexmark X5100 Series]
"C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ LVCOMSX]
C:\WINDOWS\system32\LVCOMS X.EXE
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ NeroFilter Check]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck. exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe " -atboottime
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ RoxioDragT oDisc]
"C:\Program Files\Roxio\Drag-to-Disc\D rgToDsc.ex e"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ RoxWatchTr ay]
"C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWa tchTray9.e xe"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SunJavaUpd ateSched]
"C:\Program Files\Java\jre1.6.0_01\bin \jusched.e xe"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ UpdReg]
C:\WINDOWS\UpdReg.EXE
R1 DLARTL_M;DLARTL_M;C:\WINDO WS\system3 2\Drivers\ DLARTL_M.S YS
R1 PQNTDrv;PQNTDrv;C:\WINDOWS \system32\ drivers\PQ NTDrv.sys
S3 pepifilter;Volume Adapter;C:\WINDOWS\system3 2\DRIVERS\ lv302af.sy s
S3 PID_08A0;QuickCam IM(PID_08A0);C:\WINDOWS\sy stem32\DRI VERS\LV302 AV.SYS
S3 TSP;TSP;\??\C:\WINDOWS\sys tem32\Zone Labs\avsys \KLIF.SYS
S4 RxFilter;RxFilter;C:\WINDO WS\system3 2\DRIVERS\ RxFilter.s ys
[HKEY_CURRENT_USER\softwar e\microsof t\windows\ currentver sion\explo rer\mountp oints2\E]
AutoRun\command- E:\launch.exe /a
[HKEY_CURRENT_USER\softwar e\microsof t\windows\ currentver sion\explo rer\mountp oints2\{37 a0186f-011 f-11dc-bc6 1-0019d10c 5e7f}]
AutoRun\command- L:\RunGame.exe
************************** ********** ********** ********** ********** ********
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 20:46:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Expl orer\Autop layHandler s\CancelAu toplay\CLS ID]
"\30 A?E?2?A?E?D?8?F?-?5?6?9?5? -?4?a?6?d? -?9?7?0?9? -?1?4?E?5? 1?C?D?1?7? B?1?C?'?"= ""
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
Completion time: 2007-08-02 20:49:04 - machine was rebooted
C:\ComboFix-quarantined-fi les.txt ... 2007-08-02 20:48
backdoor.win32.rbot.bll
this is the info. Any questions?
((((((((((((((((((((((((((
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\packet
C:\WINDOWS\system32\wpcap.
((((((((((((((((((((((((((
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 ))))))))))))))))))))))))))
2007-08-02 19:36 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-01 13:54 22,080 --a------ C:\WINDOWS\system32\driver
2007-08-01 13:54 21,056 --a------ C:\WINDOWS\system32\driver
2007-08-01 13:54 20,544 --a------ C:\WINDOWS\system32\driver
2007-08-01 13:54 144,960 --a------ C:\WINDOWS\system32\driver
2007-08-01 13:54 <DIR> d-------- C:\Program Files\Webroot
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLI
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\k\APPLIC~1\Web
2007-08-01 13:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI
2007-07-31 23:34 <DIR> d--hs---- C:\WINDOWS\CSC
2007-07-31 18:00 <DIR> d-------- C:\WINDOWS\ERUNT
2007-07-20 22:30 983,083 --a------ C:\WINDOWS\system32\LXBAGF
2007-07-20 22:30 90,112 --a------ C:\WINDOWS\system32\LXBACU
2007-07-20 22:30 86,016 --a------ C:\WINDOWS\system32\LXBAIH
2007-07-20 22:30 77,824 --a------ C:\WINDOWS\system32\LXBALC
2007-07-20 22:30 73,728 --a------ C:\WINDOWS\system32\lxbapw
2007-07-20 22:30 69,632 --a------ C:\WINDOWS\system32\LXBACU
2007-07-20 22:30 57,344 --a------ C:\WINDOWS\system32\lxbaci
2007-07-20 22:30 544,768 --a------ C:\WINDOWS\system32\LXBALS
2007-07-20 22:30 49,152 --a------ C:\WINDOWS\system32\lxbaco
2007-07-20 22:30 466,944 --a------ C:\WINDOWS\system32\LXBAJS
2007-07-20 22:30 40,960 --a------ C:\WINDOWS\system32\INSTMO
2007-07-20 22:30 303,104 --a------ C:\WINDOWS\system32\LEXBCE
2007-07-20 22:30 294,912 --a------ C:\WINDOWS\system32\LXBAUT
2007-07-20 22:30 286,720 --a------ C:\WINDOWS\system32\LXBAPM
2007-07-20 22:30 286,720 --a------ C:\WINDOWS\system32\lxbaco
2007-07-20 22:30 217,088 --a------ C:\WINDOWS\system32\LXBALC
2007-07-20 22:30 201,216 --a------ C:\WINDOWS\system32\LEXP2P
2007-07-20 22:30 196,096 --a------ C:\WINDOWS\system32\LEX2KU
2007-07-20 22:30 192,512 --a------ C:\WINDOWS\system32\lexlmp
2007-07-20 22:30 174,592 --a------ C:\WINDOWS\system32\LEXPPS
2007-07-20 22:30 155,648 --a------ C:\WINDOWS\system32\LEXPIN
2007-07-20 22:30 147,456 --a------ C:\WINDOWS\system32\LEXBCE
2007-07-20 22:30 126,976 --a------ C:\WINDOWS\system32\LXBACF
2007-07-18 12:10 <DIR> d-------- C:\Program Files\PTDD Group
2007-07-17 19:48 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSE
2007-07-17 18:47 <DIR> d-------- C:\Program Files\PowerQuest
2007-07-17 15:52 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLI
2007-07-17 15:47 <DIR> d-------- C:\WINDOWS\Prefetch
2007-07-17 15:41 9,728 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 9,728 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 9,216 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 86,073 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 8,704 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 79,872 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 79,872 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 76,800 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 76,288 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 73,728 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 70,144 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 7,680 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 7,168 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 67,584 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 6,144 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 6,144 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 57,856 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 53,760 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 53,248 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 5,632 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 48,256 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 46,592 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 46,592 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 456,704 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 455,168 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 45,056 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 44,032 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 426,041 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 41,600 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 40,448 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 4,608 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 4,096 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 38,912 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 363,520 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 36,927 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 358,400 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 32,768 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 31,744 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 31,232 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 31,232 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 30,208 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 30,208 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 29,184 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,624 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 26,112 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 259,072 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 25,088 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 24,576 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 236,544 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 23,040 --a--c--- C:\WINDOWS\system32\dllcac
2007-07-17 15:41 221,696 --a--c--- C:\WINDOWS\system32\dllcac
((((((((((((((((((((((((((
2007-08-02 20:43 870688 --ahs---- C:\WINDOWS\system32\driver
2007-08-02 20:43 82760 --ahs---- C:\WINDOWS\system32\driver
2007-08-02 20:43 78088224 --ahs---- C:\WINDOWS\system32\driver
2007-08-02 20:43 384 --a------ C:\WINDOWS\system32\DVCSta
2007-08-02 20:43 384 --a------ C:\WINDOWS\system32\DVCSta
2007-08-02 20:43 1051136 --ahs---- C:\WINDOWS\system32\driver
2007-08-02 01:20 512 --a------ C:\ScanSectorLog.dat
2007-07-30 16:16 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Mai
2007-07-20 22:30 --------- d-------- C:\Program Files\Lexmark X5100 Series
2007-07-19 17:46 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-19 00:31 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Azu
2007-07-19 00:29 --------- d-------- C:\Program Files\Google
2007-07-19 00:29 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-17 15:53 --------- d-------- C:\Program Files\InterActual
2007-07-17 15:36 23312 --a------ C:\WINDOWS\system32\emptyr
2007-07-17 15:36 --------- d-------- C:\Program Files\Messenger
2007-07-16 13:58 --------- d-------- C:\Program Files\ProxyWay
2007-07-09 11:46 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cam
2007-07-08 18:35 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Lim
2007-07-05 22:51 --------- d-------- C:\Program Files\Azureus
2007-07-05 17:12 685816 --a------ C:\WINDOWS\system32\driver
2007-07-03 14:01 --------- d-------- C:\Program Files\exPressit S.E. 2.1
2007-07-02 10:05 --------- d-------- C:\DOCUME~1\k\APPLIC~1\App
2007-06-25 18:06 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cre
2007-06-25 17:55 --------- d-------- C:\Program Files\Creative
2007-06-25 17:52 184 --a------ C:\WINDOWS\system32\e00000
2007-06-25 17:51 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Cre
2007-06-16 20:04 --------- d-------- C:\Program Files\Avi2Dvd
2007-06-16 19:57 --------- d-------- C:\Program Files\AviSynth 2.5
2007-06-15 21:18 --------- d-------- C:\DOCUME~1\k\APPLIC~1\Goo
2007-05-29 19:58 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-05-29 19:58 286720 --a------ C:\WINDOWS\SETUP1.EXE
2007-05-25 13:27 25088 --a------ C:\WINDOWS\system32\msxml3
2007-05-13 19:28 528 --a------ C:\WINDOWS\eReg.dat
((((((((((((((((((((((((((
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
"AsioReg"="REGSVR32.exe" [2004-08-03 18:56 C:\WINDOWS\system32\regsvr
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS
"CTHelper"="CTHELPER.EXE" [2003-06-19 23:55 C:\WINDOWS\system32\CTHELP
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49]
[HKEY_CURRENT_USER\SOFTWAR
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 15:54]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!
"Hide IP Platinum"="C:\Program Files\Hide IP Platinum\hideippla.exe" []
"BitTorrent"="C:\Program Files\BitTorrent\bittorren
"RemoteCenter"="C:\Program
"ProxyWay"="C:\Program Files\ProxyWay\proxyway.ex
"AlcoholAutomount"="C:\Pro
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\softwa
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adob
backup=C:\WINDOWS\pss\Adob
[HKEY_LOCAL_MACHINE\softwa
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adob
backup=C:\WINDOWS\pss\Adob
[HKEY_LOCAL_MACHINE\softwa
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Goog
backup=C:\WINDOWS\pss\Goog
[HKEY_LOCAL_MACHINE\softwa
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nort
backup=C:\WINDOWS\pss\Nort
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonito
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Creative\SBAudigy2ZS
[HKEY_LOCAL_MACHINE\softwa
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Creative\SBAudigy2ZS
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\iTunes\iTunesHelper.
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
[HKEY_LOCAL_MACHINE\softwa
C:\WINDOWS\system32\LVCOMS
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Roxio\Drag-to-Disc\D
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWa
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Java\jre1.6.0_01\bin
[HKEY_LOCAL_MACHINE\softwa
C:\WINDOWS\UpdReg.EXE
R1 DLARTL_M;DLARTL_M;C:\WINDO
R1 PQNTDrv;PQNTDrv;C:\WINDOWS
S3 pepifilter;Volume Adapter;C:\WINDOWS\system3
S3 PID_08A0;QuickCam IM(PID_08A0);C:\WINDOWS\sy
S3 TSP;TSP;\??\C:\WINDOWS\sys
S4 RxFilter;RxFilter;C:\WINDO
[HKEY_CURRENT_USER\softwar
AutoRun\command- E:\launch.exe /a
[HKEY_CURRENT_USER\softwar
AutoRun\command- L:\RunGame.exe
**************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 20:46:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWA
"\30 A?E?2?A?E?D?8?F?-?5?6?9?5?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
Completion time: 2007-08-02 20:49:04 - machine was rebooted
C:\ComboFix-quarantined-fi
backdoor.win32.rbot.bll
this is the info. Any questions?
ASKER
The virus is still there. Any suggestions anyone?
If you can, run Zone Alarm Security in Safe Mode to delete the virus.
Check if the virus is in System Restore file. Disable System Restore and test if virus still shows.
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
If no joy, use BitDefender or Kaspersky, but of which has ability to remove.
BitDefender
http://www.bitdefender.com/
Kaspersky
http://www.kaspersky.com/
Best wishes, war1