Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: application can not be executed - xy is infected - trojan horse  (Read 18058 times)

0 Members and 1 Guest are viewing this topic.

ekluever

    Topic Starter


    Rookie

    Hello there
    I had a serious problem with seemingly a trojan horse,which didn't let me open anything as everything was supposedly infected, also all kinds of antivirus programs.
    Finally I succeeded in doing a scan with Superantispyware by first using rkill.com and then exeHelper.com
    Then I did a quick scan with Malwarebytes.
    Ultimately I did a scan with Trend Micro Hijack.
    I am now able to open Outlook again, etc. and the messages telling me to purchase protection seized.
    I'll attach the logs, to make sure that everything is okay with your help and advice!
    I also freshly downloaded Avira Antivir Personal - but it won't update. At the same time Windows Defender is now active, as the Security Center still says virus protection (by Antivir) is out of date.
    I furthermore downloaded PC Tools Firewall, but also the Windows Firewall is active - I am not sure whether to switch anything off.
    Many thanks for any help you can provide on the finishing off of the trojan horse and current/double firewalls and virus protection!
    Elisa


    [recovering disk space - old attachment deleted by admin]

    ekluever

      Topic Starter


      Rookie

      Re: application can not be executed - xy is infected - trojan horse
      « Reply #1 on: July 07, 2010, 01:19:26 PM »
      I'm sorry, I just read the post saying we should not attach logs:

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 07/07/2010 at 05:30 PM

      Application Version : 4.40.1002

      Core Rules Database Version : 5134
      Trace Rules Database Version: 2946

      Scan type       : Complete Scan
      Total Scan Time : 02:31:59

      Memory items scanned      : 550
      Memory threats detected   : 0
      Registry items scanned    : 7728
      Registry threats detected : 3
      File items scanned        : 185244
      File threats detected     : 37

      Adware.Flash Tracking Cookie
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\SERVING-SYS.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\BC.YOUPORN.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\STATIC.YOUPORN.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\IA.MEDIA-IMDB.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\MEDIA.ENTERTONEMENT.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\EC.ATDMT.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\SPE.ATDMT.COM
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\M1.2MDN.NET
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\M1.EMEA.2MDN.NET
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\S0.2MDN.NET
         C:\Users\Elisa\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\NDUZ5RBG\SECURE-US.IMRWORLDWIDE.COM

      Rogue.AntivirusSoft
         HKU\S-1-5-21-2443503019-3500141324-4188383778-1000\Software\avsoft

      Malware.Trace
         C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
         C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
         HKU\S-1-5-21-2443503019-3500141324-4188383778-1000\SOFTWARE\XML
         HKU\S-1-5-21-2443503019-3500141324-4188383778-1000\SOFTWARE\AVSUITE

      Trojan.Agent/Gen-FraudLoad
         C:\USERS\ELISA\APPDATA\LOCAL\TEMP\ERMS.EXE
         C:\Windows\Prefetch\ERMS.EXE-DF23FA25.pf

      Trojan.Agent/Gen-Small[Parvat]
         C:\USERS\ELISA\APPDATA\LOCAL\TEMP\MSRXACONEW.EXE
         C:\Windows\Prefetch\MSRXACONEW.EXE-D5D62C85.pf

      Trojan.Agent/Gen-NET
         C:\USERS\ELISA\APPDATA\LOCAL\VIRTUALSTORE\WINDOWS\SYSTEM32\NET.NET

      Adware.Tracking Cookie
         bc.youporn.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         cdn2.themis-media.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         cdn5.specificclick.net [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         cloud.video.unrulymedia.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         ec.atdmt.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         gw.callingbanners.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         ia.media-imdb.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         m1.2mdn.net [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         m1.emea.2mdn.net [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         media.entertonement.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         media.restaurant-bookings.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         media.scanscout.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         media01.kyte.tv [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         s0.2mdn.net [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         secure-us.imrworldwide.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         serving-sys.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         spe.atdmt.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         static.youporn.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RBG ]
         www.emitourtracker.com [ C:\Users\Elisa\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\NDUZ5RB


      _______________________________________ ___________________________________

      Malwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Database version: 4289

      Windows 6.0.6002 Service Pack 2
      Internet Explorer 7.0.6002.18005

      7/7/2010 6:03:05 PM
      mbam-log-2010-07-07 (18-03-05).txt

      Scan type: Quick scan
      Objects scanned: 142531
      Time elapsed: 10 minute(s), 37 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 5
      Registry Values Infected: 2
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 12

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CURRENT_USER\SOFTWARE\UBC5AB1IDP (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\EWABQAF7KL (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\oskpmnnf (Trojan.Downloader) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ewabqaf7kl (Trojan.FakeAlert) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\Users\Elisa\AppData\Local\yipovrvjr\eqltluotssd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Roaming\2b01e43f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Windows\system32\Drivers\igcmc.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\omsxenwcar.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\rgdrebd.exe (Trojan.Insain) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\drebjsrc.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\emwfggn.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\vlln.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\Kzv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Users\Elisa\downloads\setup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
      C:\Users\Elisa\AppData\Local\Temp\Kzx.exe (Trojan.FakeAlert) -> Delete on reboot.
      C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


      _______________________________________ _______________________________________ _

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 6:11:00 PM, on 7/7/2010
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v7.00 (7.00.6002.18005)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Windows\OEM02Mon.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Winamp\winampa.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5577
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
      O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

      --
      End of file - 5240 bytes


      Sorry about that error with attaching first...

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: application can not be executed - xy is infected - trojan horse
      « Reply #2 on: July 07, 2010, 05:58:11 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      Quote
      I furthermore downloaded PC Tools Firewall, but also the Windows Firewall is active - I am not sure whether to switch anything off.
      Please turn one of them off. You should only run one firewall.

      I strongly recommend that you remove Ask from your computer because it;

      •Promotes its toolbars on sites targeted to kids.

      •Promotes its toolbars through ads that appear to be part of other companies' sites.

      •Promotes its toolbars through other companies' spyware.

      •Installs without any disclosure whatsoever and without any consent whatsoever.

      •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

      •Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.

      See Here for more info.

      If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

      AskBarDis or anything related to Ask

      Then please find and delete this folder in bold (if present):
      C:\Program Files\AskBarDis. or anything related to Ask.

      ==============================================

      Open HijackThis and select Do a system scan only

      Place a check mark next to the following entries: (if there)

      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5577
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.

      =======================================

      Download ComboFix by sUBs from one of the below links. 

      Important! You MUST save ComboFix to your desktop

      link # 1
      Link # 2

      Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click on ComboFix.exe & follow the prompts.

      Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

      Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

      When the scan completes it will open a text window.
       
      Post the contents of that log in your next reply.

      Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.
      Windows 8 and Windows 10 dual boot with two SSD's

      ekluever

        Topic Starter


        Rookie

        Re: application can not be executed - xy is infected - trojan horse
        « Reply #3 on: July 08, 2010, 05:34:58 AM »
        Dear Dave
        Thank you soooo much!
        Yes, I had tried to remove Ask before - but hadn't succeeded... This time I hope I have, even though I just did the steps through the Control Panel, as in the Program List nothing was to be found.
        At first I couldn't do the HijackThis Fix because it repeatedly said the program was running already and wouldn't let me open it. After restarting the computer, however, it worked.
        I'll copy and paste the ComboFix log:

        ComboFix 10-07-07.02 - Elisa 07/08/2010  11:55:58.1.2 - x86
        Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.2037.1169 [GMT 1:00]
        Running from: c:\users\Elisa\Desktop\ComboFix.exe
        SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
        SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
        .

        (((((((((((((((((((((((((   Files Created from 2010-06-08 to 2010-07-08  )))))))))))))))))))))))))))))))
        .

        2010-07-07 20:21 . 2010-07-07 20:22   --------   d-----w-   c:\users\Elisa\AppData\Roaming\PCToolsFirewallPlus
        2010-07-07 19:03 . 2010-01-12 08:34   70664   ----a-w-   c:\windows\system32\drivers\pctNdis-PacketFilter.sys
        2010-07-07 19:03 . 2010-01-07 10:35   58816   ----a-w-   c:\windows\system32\drivers\pctNdis.sys
        2010-07-07 19:03 . 2010-01-07 10:35   32680   ----a-w-   c:\windows\system32\drivers\pctNdis-DNS.sys
        2010-07-07 19:03 . 2010-01-13 07:59   115216   ----a-w-   c:\windows\system32\drivers\pctplfw.sys
        2010-07-07 19:02 . 2010-07-07 20:22   --------   d-----w-   c:\program files\PC Tools Firewall Plus
        2010-07-07 17:30 . 2010-07-07 17:30   --------   d-----w-   c:\users\Elisa\AppData\Roaming\Avira
        2010-07-07 17:24 . 2010-07-07 17:24   --------   d-----w-   c:\programdata\Avira
        2010-07-07 17:24 . 2010-07-07 17:24   --------   d-----w-   c:\program files\Avira
        2010-07-07 17:24 . 2010-03-01 09:05   124784   ----a-w-   c:\windows\system32\drivers\avipbb.sys
        2010-07-07 17:24 . 2010-02-16 13:24   60936   ----a-w-   c:\windows\system32\drivers\avgntflt.sys
        2010-07-07 17:24 . 2009-05-11 11:49   51992   ----a-w-   c:\windows\system32\drivers\avgntdd.sys
        2010-07-07 17:24 . 2009-05-11 11:49   17016   ----a-w-   c:\windows\system32\drivers\avgntmgr.sys
        2010-07-07 17:07 . 2010-07-07 17:07   --------   d-----w-   c:\program files\Trend Micro
        2010-07-07 12:29 . 2010-07-07 12:29   63488   ----a-w-   c:\users\Elisa\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
        2010-07-07 12:29 . 2010-07-07 12:29   52224   ----a-w-   c:\users\Elisa\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
        2010-07-07 12:29 . 2010-07-07 12:29   117760   ----a-w-   c:\users\Elisa\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
        2010-07-07 12:29 . 2010-07-07 12:29   --------   d-----w-   c:\users\Elisa\AppData\Roaming\SUPERAntiSpyware.com
        2010-07-07 12:29 . 2010-07-07 12:29   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
        2010-07-07 10:35 . 2010-03-17 10:35   309248   ----a-w-   c:\users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\zsj0t91x.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
        2010-07-07 10:11 . 2010-07-07 10:11   --------   d-----w-   c:\users\Elisa\AppData\Roaming\Malwarebytes
        2010-07-07 10:11 . 2010-04-29 14:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
        2010-07-07 10:11 . 2010-07-07 16:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
        2010-07-07 10:11 . 2010-07-07 10:11   --------   d-----w-   c:\programdata\Malwarebytes
        2010-07-07 10:11 . 2010-04-29 14:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
        2010-07-07 00:19 . 2010-02-05 08:18   100136   ----a-w-   c:\windows\system32\drivers\pctwfpfilter.sys
        2010-07-07 00:19 . 2010-02-05 08:17   233136   ----a-w-   c:\windows\system32\drivers\pctgntdi.sys
        2010-07-07 00:19 . 2010-03-29 09:06   218592   ----a-w-   c:\windows\system32\drivers\PCTCore.sys
        2010-07-07 00:19 . 2009-11-23 12:54   88040   ----a-w-   c:\windows\system32\drivers\PCTAppEvent.sys
        2010-07-07 00:19 . 2010-04-08 13:29   63360   ----a-w-   c:\windows\system32\drivers\pctplsg.sys
        2010-07-07 00:19 . 2010-07-07 19:03   --------   d-----w-   c:\program files\Common Files\PC Tools
        2010-07-07 00:19 . 2010-07-07 00:19   --------   d-----w-   c:\program files\Spyware Doctor
        2010-07-07 00:19 . 2010-07-07 00:19   --------   d-----w-   c:\users\Elisa\AppData\Roaming\PC Tools
        2010-07-07 00:19 . 2010-07-07 00:19   --------   d-----w-   c:\programdata\PC Tools
        2010-07-06 20:52 . 2010-07-07 17:03   --------   d-----w-   c:\users\Elisa\AppData\Local\yipovrvjr
        2010-07-06 20:52 . 2010-07-07 18:51   --------   d-----w-   c:\users\Elisa\AppData\Roaming\4BE28AF70D98635D906A7947BA597FBF
        2010-06-30 15:54 . 2010-06-30 15:59   --------   d-----w-   c:\users\Elisa\AppData\Local\Microsoft Games
        2010-06-23 08:24 . 2009-11-08 09:55   99176   ----a-w-   c:\windows\system32\PresentationHostProxy.dll
        2010-06-23 08:24 . 2009-11-08 09:55   49472   ----a-w-   c:\windows\system32\netfxperf.dll
        2010-06-23 08:24 . 2009-11-08 09:55   297808   ----a-w-   c:\windows\system32\mscoree.dll
        2010-06-23 08:24 . 2009-11-08 09:55   295264   ----a-w-   c:\windows\system32\PresentationHost.exe
        2010-06-23 08:24 . 2009-11-08 09:55   1130824   ----a-w-   c:\windows\system32\dfshim.dll
        2010-06-23 08:05 . 2010-04-16 16:43   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
        2010-06-23 08:05 . 2010-04-16 14:39   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
        2010-06-21 20:09 . 2010-06-21 20:09   --------   d-----w-   c:\program files\7-Zip
        2010-06-15 12:37 . 2010-06-15 12:37   --------   d-----w-   c:\users\Default\AppData\Roaming\Trusteer
        2010-06-08 18:40 . 2009-09-04 16:29   1892184   ----a-w-   c:\windows\system32\D3DX9_42.dll
        2010-06-08 18:40 . 2006-09-28 15:05   2414360   ----a-w-   c:\windows\system32\d3dx9_31.dll
        2010-06-08 18:39 . 2010-06-08 18:39   --------   d-----w-   c:\program files\Winamp Detect
        2010-06-08 18:39 . 2010-06-22 23:05   --------   d-----w-   c:\users\Elisa\AppData\Roaming\Winamp
        2010-06-08 18:39 . 2010-06-08 19:43   --------   d-----w-   c:\program files\Winamp

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2010-07-08 10:22 . 2009-09-29 23:13   --------   d-----w-   c:\users\Elisa\AppData\Roaming\Skype
        2010-07-08 09:39 . 2009-09-29 23:14   --------   d-----w-   c:\users\Elisa\AppData\Roaming\skypePM
        2010-07-07 10:58 . 2009-09-29 13:17   680   ----a-w-   c:\users\Elisa\AppData\Local\d3d9caps.dat
        2010-06-20 12:30 . 2009-09-29 13:37   --------   d-----w-   c:\users\Elisa\AppData\Roaming\vlc
        2010-06-11 10:02 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
        2010-06-09 18:49 . 2010-06-09 18:49   --------   d-----w-   c:\programdata\WindowsSearch
        2010-06-08 18:39 . 2009-10-18 10:41   --------   d-----w-   c:\program files\Common Files\PX Storage Engine
        2010-06-07 17:07 . 2010-06-07 17:07   434176   ----a-w-   c:\programdata\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
        2010-06-03 02:41 . 2010-06-03 02:41   3600384   ----a-w-   c:\windows\system32\GPhotos.scr
        2010-05-26 17:06 . 2010-06-09 18:49   34304   ----a-w-   c:\windows\system32\atmlib.dll
        2010-05-26 14:47 . 2010-06-09 18:49   289792   ----a-w-   c:\windows\system32\atmfd.dll
        2010-05-21 13:14 . 2009-10-03 08:05   221568   ------w-   c:\windows\system32\MpSigStub.exe
        2010-05-04 19:15 . 2010-06-09 18:49   834048   ----a-w-   c:\windows\system32\wininet.dll
        2010-05-04 18:37 . 2010-06-09 18:49   78336   ----a-w-   c:\windows\system32\ieencode.dll
        2010-05-01 14:13 . 2010-06-09 18:49   2037248   ----a-w-   c:\windows\system32\win32k.sys
        2010-04-23 23:16 . 2010-04-23 23:16   0   ----a-w-   c:\users\Elisa\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
        2010-04-23 23:12 . 2010-04-23 23:12   411368   ----a-w-   c:\windows\system32\deploytk.dll
        2010-04-23 14:13 . 2010-05-25 18:59   2048   ----a-w-   c:\windows\system32\tzres.dll
        2010-04-16 16:43 . 2010-06-23 08:05   173056   ----a-w-   c:\windows\AppPatch\AcXtrnal.dll
        2010-04-16 16:43 . 2010-06-23 08:05   458752   ----a-w-   c:\windows\AppPatch\AcSpecfc.dll
        2010-04-16 16:43 . 2010-06-23 08:05   542720   ----a-w-   c:\windows\AppPatch\AcLayers.dll
        2010-04-16 16:43 . 2010-06-23 08:05   2159616   ----a-w-   c:\windows\AppPatch\AcGenral.dll
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
        "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
        "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
        "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
        "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
        "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
        "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-04-23 149280]
        "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-05-25 37888]
        "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-05-11 1287120]
        "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
        "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "EnableUIADesktopToggle"= 0 (0x0)

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
        @="Service"

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
        "VistaSp2"=hex(b):8c,17,d4,44,62,51,ca,01

        R3 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [2010-06-07 59240]
        R3 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-06-07 166632]
        R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-09-29 721904]
        S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-03-29 218592]
        S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2010-02-05 233136]
        S1 SASDIFSV;SASDIFSV;c:\users\Elisa\Desktop\SASDIFSV.SYS [2010-02-17 12872]
        S1 SASKUTIL;SASKUTIL;c:\users\Elisa\Desktop\SASKUTIL.SYS [2010-05-10 67656]
        S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
        S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-11-23 88040]
        S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-06-07 840936]
        S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
        S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2010-01-12 70664]
        S3 pctNDIS;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis.sys [2010-01-07 58816]
        S3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw.sys [2010-01-13 115216]


        --- Other Services/Drivers In Memory ---

        *Deregistered* - igcmc

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
        .
        Contents of the 'Scheduled Tasks' folder

        2010-07-08 c:\windows\Tasks\User_Feed_Synchronization-{982BEE4D-B0F2-4903-9506-A2914121ECE0}.job
        - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
        .
        .
        ------- Supplementary Scan -------
        .
        uDefault_Search_URL = hxxp://www.google.com/ie
        uInternet Settings,ProxyOverride = <local>
        uSearchAssistant = hxxp://www.google.com/ie
        uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
        IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
        FF - ProfilePath - c:\users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\zsj0t91x.default\
        FF - prefs.js: browser.search.selectedEngine - Google
        FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
        FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
        FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
        FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
        FF - plugin: c:\users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\zsj0t91x.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
        FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

        ---- FIREFOX POLICIES ----
        c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
        c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
        c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
        c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
        c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
        c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
        .
        - - - - ORPHANS REMOVED - - - -

        WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
        AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



        **************************************************************************
        scanning hidden processes ... 

        scanning hidden autostart entries ...

        scanning hidden files ... 

        scan completed successfully
        hidden files:

        **************************************************************************

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\igcmc]

        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        @Denied: (A) (Users)
        @Denied: (A) (Everyone)
        @Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        .
        Completion time: 2010-07-08  12:04:58
        ComboFix-quarantined-files.txt  2010-07-08 11:04

        Pre-Run: 51,518,025,728 bytes free
        Post-Run: 58,767,671,296 bytes free

        - - End Of File - - 3AA2539EAD85F3013441B540F3D8ADE5


        Afterwards, when turning the firewall back on, interestingly the update of AntiVir finally worked. so now windows leaves me alone with security-warnings...
        Many, many thanks,
        Elisa

        ekluever

          Topic Starter


          Rookie

          Re: application can not be executed - xy is infected - trojan horse
          « Reply #4 on: July 08, 2010, 07:40:47 AM »
          oh, somehow skype was just now constantly turning itself off - no idea whether that is related, as it didn't work at all, before i followed the guidelines and did all the scans with the different programs mentioned here...

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: application can not be executed - xy is infected - trojan horse
          « Reply #5 on: July 08, 2010, 11:51:16 AM »
          I'd like us to scan your machine with ESET OnlineScan

          •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
          ESET OnlineScan
          •Click the button.
          •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          • Click on to download the ESET Smart Installer. Save it to your desktop.
          • Double click on the icon on your desktop.
          •Check
          •Click the button.
          •Accept any security warnings from your browser.
          •Check
          •Push the Start button.
          •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
          •When the scan completes, push
          •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
          •Push the button.
          •Push
          A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

          Windows 8 and Windows 10 dual boot with two SSD's

          ekluever

            Topic Starter


            Rookie

            Re: application can not be executed - xy is infected - trojan horse
            « Reply #6 on: July 09, 2010, 03:55:49 AM »
            hello dave
            i ran the eset scan, but during the scan my computer went out of battery and thus turned itself off. when i plugged it in again, it seemingly resumed the scan where it had been interrupted. i couldn't click 'list of found threats' however, as the result is, that no threats have been found...
            what do you say?
            shall i repeat the scan with the computer plugged in all the time?
            thanks a lot,
            elisa

            ps: what also happened a couple of times now, is that when starting the computer it says it has some problem, whether i want to start it in safemode or regular, or two other versions, and if i don't choose anything, it'll resume as regular. the first times i used to chose the 'normal' button (i can't remember what exactly it said) and it returned after a while to the same view - mentioning it had a problem, and whether i wanted to start the system in one of the four options. when i just didn't klick anything, but let it resume in the regular way after waiting for a couple of seconds, then it would finally start normally.

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: application can not be executed - xy is infected - trojan horse
            « Reply #7 on: July 09, 2010, 05:43:55 AM »
            Let's try another scanner.

            Download Dr.Web CureIt to the desktop:
            Dr WebCureIt
            • Double-click the launch.exe or cureit.exe file and Allow to run the express scan
            • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
            • Once the short scan has finished, just let it cure whatever it finds...

              o Now, go to Settings >> Change Settings
              o Go to Actions tab >> under Objects section, change the settings to below
              Infected objects - Cure
              Incurable objects - Report
              Suspicious objects - Report
              o Don't change any other settings
            • Start the scan again. This time, choose Complete Scan
            • Click the green arrow button at the right, and the scan will start.
            • After the scan finished, click Select all
            • Click on Cure and choose Report incurable (means take no actions.. Don't "move", or "rename" or "delete")
            • When the scan has finished, in the menu, click File and choose Save report list
            • Save the report to your Desktop. The report will be called DrWeb.csv
            • Post DrWeb.csv in your next reply (Open it as Notepad).. Do NOT reboot the computer yet..
            Windows 8 and Windows 10 dual boot with two SSD's

            ekluever

              Topic Starter


              Rookie

              Re: application can not be executed - xy is infected - trojan horse
              « Reply #8 on: July 09, 2010, 01:36:42 PM »
              Hello Dave
              It didn't work-when i click on the link the server can't be found.
              In the mean time, I had turned my laptop off again, and this time had the troubles with starting it many times.
              It repeatedly says Windows failed start and recent hardware or software change might be the cause, and whether I'd like to start it in 3 different versions of safemode, in the last configuration or start normally...
              and when I enter the 'start normally' or when it does so after a few seconds passing by, by itself, it just loads a bit and ends up saying the exact same thing - until after 4 or 5 attempts it finally does load...
              Also I now noticed, that in the small search field to the upper right, where i set google as my default search machine, ask.com still is an option, and removed it from there. I don't know if that means, however, that it could still be elsewhere or whether it's been the last souvenir.
              sorry, i feel really bad at explaining this.
              thanks a lot for all the help!

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: application can not be executed - xy is infected - trojan horse
              « Reply #9 on: July 09, 2010, 03:00:08 PM »
              Could you please try running the ESET scan again?
              Windows 8 and Windows 10 dual boot with two SSD's

              ekluever

                Topic Starter


                Rookie

                Re: application can not be executed - xy is infected - trojan horse
                « Reply #10 on: July 09, 2010, 10:37:44 PM »
                i just started the eset scanner again - but in the meantime windows defender alerted me it had found PWS:Win32/Daurso.A
                as it asked me to either remove or ignore it, i klicked the remove button...
                i'll keep you posted and thanks again!

                ekluever

                  Topic Starter


                  Rookie

                  Re: application can not be executed - xy is infected - trojan horse
                  « Reply #11 on: July 09, 2010, 10:48:04 PM »
                  oh, and thereby i noticed that not only antivir but also windows defender is running - shall i turn windows defender off, or even uninstall it maybe?
                  (I like having not too many programs, and antivir was recommended by this site, whereas the defender wasn't- or is the 'two is too many' thing only true for firewalls?)

                  SuperDave

                  • Malware Removal Specialist


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: application can not be executed - xy is infected - trojan horse
                  « Reply #12 on: July 10, 2010, 05:33:32 PM »
                  One Anti-Virus, one firewall and you can run a few anti-malware programs (more about this later ) if you wish. Windows Defender is ok to run alongside your AV.
                  Windows 8 and Windows 10 dual boot with two SSD's

                  ekluever

                    Topic Starter


                    Rookie

                    Re: application can not be executed - xy is infected - trojan horse
                    « Reply #13 on: July 11, 2010, 12:47:07 PM »
                    hello dave
                    finally i managed to run the complete scan (i had the time and the computer didn't shut itself off):

                    this is the list of threats:
                    C:\Windows\temp\37716533.tmp   a variant of Win32/Kryptik.FKM trojan
                    C:\Windows\temp\a879b485.tmp   a variant of Win32/Kryptik.FKM trojan

                    and this is the (hopefully right - since i had run the scan before and the results were different then) log:
                    ESETSmartInstaller@High as downloader log:
                    all ok
                    # version=7
                    # OnlineScannerApp.exe=1.0.0.1
                    # OnlineScanner.ocx=1.0.0.6211
                    # api_version=3.0.2
                    # EOSSerial=d1385694d1dc1f45a007e809a130e85c
                    # end=finished
                    # remove_checked=true
                    # archives_checked=true
                    # unwanted_checked=true
                    # unsafe_checked=false
                    # antistealth_checked=true
                    # utc_time=2010-07-09 01:48:51
                    # local_time=2010-07-09 02:48:51 (+0000, GMT Daylight Time)
                    # country="United States"
                    # lang=1033
                    # osver=6.0.6002 NT Service Pack 2
                    # compatibility_mode=512 16777215 100 0 149069 149069 0 0
                    # compatibility_mode=1797 16775165 100 94 2018 37761018 80461 0
                    # compatibility_mode=2560 16777215 100 0 0 0 0 0
                    # compatibility_mode=5892 16776573 100 100 69082 116204253 0 0
                    # compatibility_mode=8192 67108863 100 0 143 143 0 0
                    # scanned=172418
                    # found=0
                    # cleaned=0
                    # scan_time=11806
                    ESETSmartInstaller@High as downloader log:
                    all ok
                    ESETSmartInstaller@High as downloader log:
                    all ok
                    # version=7
                    # OnlineScannerApp.exe=1.0.0.1
                    # OnlineScanner.ocx=1.0.0.6211
                    # api_version=3.0.2
                    # EOSSerial=d1385694d1dc1f45a007e809a130e85c
                    # end=finished
                    # remove_checked=false
                    # archives_checked=true
                    # unwanted_checked=true
                    # unsafe_checked=false
                    # antistealth_checked=true
                    # utc_time=2010-07-11 06:31:24
                    # local_time=2010-07-11 07:31:24 (+0000, GMT Daylight Time)
                    # country="United States"
                    # lang=1033
                    # osver=6.0.6002 NT Service Pack 2
                    # compatibility_mode=512 16777215 100 0 345811 345811 0 0
                    # compatibility_mode=1797 16775165 100 94 198760 37957760 0 0
                    # compatibility_mode=2560 16777215 100 0 0 0 0 0
                    # compatibility_mode=5892 16776573 100 100 265824 116400995 0 0
                    # compatibility_mode=8192 67108863 100 0 196885 196885 0 0
                    # scanned=172573
                    # found=2
                    # cleaned=0
                    # scan_time=4816
                    C:\Windows\temp\37716533.tmp   a variant of Win32/Kryptik.FKM trojan   00000000000000000000000000000000   I
                    C:\Windows\temp\a879b485.tmp   a variant of Win32/Kryptik.FKM trojan   00000000000000000000000000000000   I

                    many thanks,
                    elisa

                    SuperDave

                    • Malware Removal Specialist


                    • Genius
                    • Thanked: 1020
                    • Certifications: List
                    • Experience: Expert
                    • OS: Windows 10
                    Re: application can not be executed - xy is infected - trojan horse
                    « Reply #14 on: July 11, 2010, 06:14:32 PM »
                    Just another scan to make sure, if you don't mind.

                    Download Dr.Web CureIt to the desktop:
                    Dr WebCureIt
                    • Double-click the launch.exe or cureit.exe file and Allow to run the express scan
                    • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
                    • Once the short scan has finished, just let it cure whatever it finds...

                      o Now, go to Settings >> Change Settings
                      o Go to Actions tab >> under Objects section, change the settings to below
                      Infected objects - Cure
                      Incurable objects - Report
                      Suspicious objects - Report
                      o Don't change any other settings
                    • Start the scan again. This time, choose Complete Scan
                    • Click the green arrow button at the right, and the scan will start.
                    • After the scan finished, click Select all
                    • Click on Cure and choose Report incurable (means take no actions.. Don't "move", or "rename" or "delete")
                    • When the scan has finished, in the menu, click File and choose Save report list
                    • Save the report to your Desktop. The report will be called DrWeb.csv
                    • Post DrWeb.csv in your next reply (Open it as Notepad).. Do NOT reboot the computer yet..
                    Windows 8 and Windows 10 dual boot with two SSD's