nicky
10-22-2008, 11:43 PM
You need to get a firewall on this thing and then you can look at the processes one at a time....
Hi Victor Frankl
I have the above malware problem with the videoonlinefor free popping up when in file manager and explorer. i followed uyour advice and here is the ,long i got. Please can you help?
ComboFix 08-10-22.02 - Nicola 2008-10-22 19:36:00.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1464 [GMT -6:00]
Running from: C:\Documents and Settings\Nicola\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\k.txt
.
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-22 18:56 . 2008-10-22 18:56 7,478,208 --a------ C:\windows-kb890830-v2.3.exe
2008-10-21 22:09 . 2008-10-21 22:09 <DIR> d-------- C:\Autoruns
2008-10-21 21:57 . 2008-10-15 09:25 644,976 --a------ C:\autoruns.exe
2008-10-21 21:57 . 2008-10-15 09:25 538,480 --a------ C:\autorunsc.exe
2008-10-21 21:57 . 2008-08-20 14:18 48,986 --a------ C:\autoruns.chm
2008-10-21 21:56 . 2008-10-21 21:58 575,124 --a------ C:\Autoruns.zip
2008-10-19 20:18 . 2008-10-19 20:18 <DIR> d--h----- C:\WINDOWS\PIF
2008-10-19 14:26 . 2008-10-19 14:26 57,344 --a------ C:\WINDOWS\system32\gopfa.dll
2008-10-18 18:36 . 2008-10-18 18:36 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-17 21:17 . 2008-10-17 21:17 <DIR> d-------- C:\WINDOWS\Sun
2008-10-17 21:17 . 2007-05-22 17:39 61,555 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-10-17 21:16 . 2008-10-17 21:17 <DIR> d-------- C:\Program Files\Java
2008-10-17 21:16 . 2008-10-17 21:16 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-17 21:06 . 2008-10-17 21:06 <DIR> d-------- C:\Documents and Settings\Satish\Application Data\Nero
2008-10-17 20:26 . 2008-10-21 21:36 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-17 19:49 . 2008-10-17 19:49 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-10-17 19:48 . 2008-10-17 19:48 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Nero
2008-10-17 19:46 . 2008-10-17 19:46 <DIR> d-------- C:\Program Files\Nero
2008-10-17 19:46 . 2008-10-17 19:47 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-10-17 19:46 . 2008-10-17 19:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-10-16 08:49 . 2008-09-15 06:12 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 08:49 . 2008-09-08 04:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 08:48 . 2008-08-14 04:11 2,189,184 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 08:48 . 2008-08-14 04:09 2,145,280 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 08:48 . 2008-08-14 03:33 2,066,048 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 08:48 . 2008-08-14 03:33 2,023,936 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 16:27 . 2008-10-15 16:59 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\U3
2008-10-08 21:10 . 2008-10-08 21:10 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\AVS4YOU
2008-10-08 20:13 . 2008-10-08 20:13 <DIR> d-------- C:\Program Files\LG Software Innovations
2008-10-08 20:13 . 2008-10-08 20:13 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Vso
2008-10-08 20:13 . 2008-10-08 21:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-10-08 20:13 . 2008-10-08 20:13 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-10-08 20:13 . 2008-10-08 20:13 47,360 --a------ C:\Documents and Settings\Nicola\Application Data\pcouffin.sys
2008-10-08 19:41 . 2008-10-08 19:41 <DIR> d-------- C:\Program Files\THQ
2008-10-08 14:58 . 2008-10-08 14:58 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-10-08 14:58 . 2008-10-22 19:37 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Skype
2008-10-07 21:43 . 2008-10-07 21:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ten Thumbs Typing Tutor
2008-10-07 21:42 . 2008-10-07 21:43 <DIR> d-------- C:\Program Files\Ten Thumbs Typing Tutor 4.7
2008-10-06 22:29 . 2008-10-08 20:02 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\dvdcss
2008-10-06 18:54 . 2008-10-06 18:54 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Creative
2008-10-06 18:45 . 2008-10-06 18:47 <DIR> d-------- C:\Documents and Settings\Satish\Downloads
2008-10-06 00:33 . 2008-10-06 00:33 <DIR> d-------- C:\Documents and Settings\Sophie
2008-10-05 22:57 . 2008-10-21 21:36 <DIR> d-------- C:\Downloads
2008-10-05 22:45 . 2008-10-21 22:04 <DIR> d-------- C:\Program Files\FlashGet
2008-10-05 17:40 . 2008-10-05 17:40 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\vlc
2008-10-05 15:07 . 2008-10-05 16:07 <DIR> d-------- C:\Documents and Settings\Satish\Application Data\Skype
2008-10-05 14:47 . 2008-10-08 14:58 <DIR> d-------- C:\Program Files\Skype
2008-10-05 14:45 . 2003-06-13 00:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd
2008-10-05 14:43 . 2008-04-13 18:12 91,136 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-10-05 14:43 . 2008-04-13 18:12 91,136 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-10-05 14:43 . 2008-04-13 18:12 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-10-05 14:43 . 2008-04-13 18:12 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-10-05 14:43 . 2008-04-13 18:12 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-05 14:43 . 2008-04-13 18:12 53,760 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-10-05 14:43 . 2008-04-13 18:12 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-10-05 14:43 . 2008-04-13 18:12 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-10-05 14:41 . 2008-10-05 14:43 <DIR> d-------- C:\Program Files\SightSpeed
2008-10-05 14:41 . 2003-03-18 23:19 1,060,864 --------- C:\WINDOWS\system32\MFC71.DLL
2008-10-05 14:41 . 2003-03-18 06:14 499,712 --------- C:\WINDOWS\system32\msvcp71.dll
2008-10-05 14:41 . 1998-10-29 17:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-10-05 14:40 . 2008-10-06 18:54 <DIR> d-------- C:\Program Files\Creative
2008-10-04 20:22 . 2008-10-04 20:22 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-10-04 19:12 . 2008-10-04 19:12 <DIR> d-------- C:\Documents and Settings\Olivia\Application Data\Apple Computer
2008-10-04 18:56 . 2008-10-04 18:56 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Leadertech
2008-10-04 11:53 . 2008-10-04 11:53 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-10-03 22:08 . 2008-10-03 22:08 <DIR> d--hs---- C:\Documents and Settings\Olivia\PrivacIE
2008-10-02 21:28 . 2008-10-02 21:28 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-10-02 21:27 . 2008-10-04 19:10 <DIR> d-------- C:\Documents and Settings\Olivia\Application Data\U3
2008-10-02 20:39 . 2008-10-22 19:20 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\skypePM
2008-10-02 20:39 . 2008-10-02 20:39 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-02 11:37 . 2008-10-08 14:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-10-02 10:57 . 2008-10-02 10:57 <DIR> d--------
Hi Victor Frankl
I have the above malware problem with the videoonlinefor free popping up when in file manager and explorer. i followed uyour advice and here is the ,long i got. Please can you help?
ComboFix 08-10-22.02 - Nicola 2008-10-22 19:36:00.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1464 [GMT -6:00]
Running from: C:\Documents and Settings\Nicola\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\k.txt
.
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-22 18:56 . 2008-10-22 18:56 7,478,208 --a------ C:\windows-kb890830-v2.3.exe
2008-10-21 22:09 . 2008-10-21 22:09 <DIR> d-------- C:\Autoruns
2008-10-21 21:57 . 2008-10-15 09:25 644,976 --a------ C:\autoruns.exe
2008-10-21 21:57 . 2008-10-15 09:25 538,480 --a------ C:\autorunsc.exe
2008-10-21 21:57 . 2008-08-20 14:18 48,986 --a------ C:\autoruns.chm
2008-10-21 21:56 . 2008-10-21 21:58 575,124 --a------ C:\Autoruns.zip
2008-10-19 20:18 . 2008-10-19 20:18 <DIR> d--h----- C:\WINDOWS\PIF
2008-10-19 14:26 . 2008-10-19 14:26 57,344 --a------ C:\WINDOWS\system32\gopfa.dll
2008-10-18 18:36 . 2008-10-18 18:36 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-17 21:17 . 2008-10-17 21:17 <DIR> d-------- C:\WINDOWS\Sun
2008-10-17 21:17 . 2007-05-22 17:39 61,555 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-10-17 21:16 . 2008-10-17 21:17 <DIR> d-------- C:\Program Files\Java
2008-10-17 21:16 . 2008-10-17 21:16 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-17 21:06 . 2008-10-17 21:06 <DIR> d-------- C:\Documents and Settings\Satish\Application Data\Nero
2008-10-17 20:26 . 2008-10-21 21:36 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-17 19:49 . 2008-10-17 19:49 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-10-17 19:48 . 2008-10-17 19:48 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Nero
2008-10-17 19:46 . 2008-10-17 19:46 <DIR> d-------- C:\Program Files\Nero
2008-10-17 19:46 . 2008-10-17 19:47 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-10-17 19:46 . 2008-10-17 19:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-10-16 08:49 . 2008-09-15 06:12 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 08:49 . 2008-09-08 04:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 08:48 . 2008-08-14 04:11 2,189,184 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 08:48 . 2008-08-14 04:09 2,145,280 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 08:48 . 2008-08-14 03:33 2,066,048 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 08:48 . 2008-08-14 03:33 2,023,936 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 16:27 . 2008-10-15 16:59 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\U3
2008-10-08 21:10 . 2008-10-08 21:10 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\AVS4YOU
2008-10-08 20:13 . 2008-10-08 20:13 <DIR> d-------- C:\Program Files\LG Software Innovations
2008-10-08 20:13 . 2008-10-08 20:13 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Vso
2008-10-08 20:13 . 2008-10-08 21:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-10-08 20:13 . 2008-10-08 20:13 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-10-08 20:13 . 2008-10-08 20:13 47,360 --a------ C:\Documents and Settings\Nicola\Application Data\pcouffin.sys
2008-10-08 19:41 . 2008-10-08 19:41 <DIR> d-------- C:\Program Files\THQ
2008-10-08 14:58 . 2008-10-08 14:58 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-10-08 14:58 . 2008-10-22 19:37 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Skype
2008-10-07 21:43 . 2008-10-07 21:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ten Thumbs Typing Tutor
2008-10-07 21:42 . 2008-10-07 21:43 <DIR> d-------- C:\Program Files\Ten Thumbs Typing Tutor 4.7
2008-10-06 22:29 . 2008-10-08 20:02 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\dvdcss
2008-10-06 18:54 . 2008-10-06 18:54 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Creative
2008-10-06 18:45 . 2008-10-06 18:47 <DIR> d-------- C:\Documents and Settings\Satish\Downloads
2008-10-06 00:33 . 2008-10-06 00:33 <DIR> d-------- C:\Documents and Settings\Sophie
2008-10-05 22:57 . 2008-10-21 21:36 <DIR> d-------- C:\Downloads
2008-10-05 22:45 . 2008-10-21 22:04 <DIR> d-------- C:\Program Files\FlashGet
2008-10-05 17:40 . 2008-10-05 17:40 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\vlc
2008-10-05 15:07 . 2008-10-05 16:07 <DIR> d-------- C:\Documents and Settings\Satish\Application Data\Skype
2008-10-05 14:47 . 2008-10-08 14:58 <DIR> d-------- C:\Program Files\Skype
2008-10-05 14:45 . 2003-06-13 00:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd
2008-10-05 14:43 . 2008-04-13 18:12 91,136 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-10-05 14:43 . 2008-04-13 18:12 91,136 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-10-05 14:43 . 2008-04-13 18:12 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-10-05 14:43 . 2008-04-13 18:12 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-10-05 14:43 . 2008-04-13 18:12 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-05 14:43 . 2008-04-13 18:12 53,760 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-10-05 14:43 . 2008-04-13 18:12 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-10-05 14:43 . 2008-04-13 18:12 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-10-05 14:41 . 2008-10-05 14:43 <DIR> d-------- C:\Program Files\SightSpeed
2008-10-05 14:41 . 2003-03-18 23:19 1,060,864 --------- C:\WINDOWS\system32\MFC71.DLL
2008-10-05 14:41 . 2003-03-18 06:14 499,712 --------- C:\WINDOWS\system32\msvcp71.dll
2008-10-05 14:41 . 1998-10-29 17:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-10-05 14:40 . 2008-10-06 18:54 <DIR> d-------- C:\Program Files\Creative
2008-10-04 20:22 . 2008-10-04 20:22 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-10-04 19:12 . 2008-10-04 19:12 <DIR> d-------- C:\Documents and Settings\Olivia\Application Data\Apple Computer
2008-10-04 18:56 . 2008-10-04 18:56 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\Leadertech
2008-10-04 11:53 . 2008-10-04 11:53 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-10-03 22:08 . 2008-10-03 22:08 <DIR> d--hs---- C:\Documents and Settings\Olivia\PrivacIE
2008-10-02 21:28 . 2008-10-02 21:28 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-10-02 21:27 . 2008-10-04 19:10 <DIR> d-------- C:\Documents and Settings\Olivia\Application Data\U3
2008-10-02 20:39 . 2008-10-22 19:20 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\skypePM
2008-10-02 20:39 . 2008-10-02 20:39 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-02 11:37 . 2008-10-08 14:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-10-02 10:57 . 2008-10-02 10:57 <DIR> d--------