Something ain't right

Discussion in 'Malware Help (A Specialist Will Reply)' started by nonsenc, Nov 30, 2006.

  1. nonsenc

    nonsenc Private E-2

    I ran through the list of things that are asked of posters to do first and the results are attached to this post. My problem is that, Even after all that my computer seems to be dragging a bit. I t all atarted when i tried to download a chinese version of Internet Explorer for my girlfriend to use and then Avast! picked up a trojan horse in the file, started to take action and then the computer froze and rebooted. It said that the file had been deleted but now I have to IE icon downloaded and stuck on my desktop. It won't delete...so on and so forth. That's the story, here's the logs. thanks for the help.

    Also, apologies but counterspy and AVG anti-spyware won't download and/or instal. So, I don't have any logs for those, sorry.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please explain exactly the problem. You were able to download other tools. Why not these? Where exactly is the problem? Is it downloading the files or is it installing the program or is it running the scans? If you get any error messages along the way, please give the exact error message.

    You need to attach the logs from the below:
    - Bitdefender
    - PandaActiveScan
    - ShowNew
     
  3. nonsenc

    nonsenc Private E-2

    sorry, finally got all the logs. Had a problem downloading the file for counterspy due to retched chinese internet. Attached are the rest of the logs. Thank you in advance for the help.

    cheers.
     

    Attached Files:

  4. nonsenc

    nonsenc Private E-2

    also, I put the shownow and getrunkey together in one attachment
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not! Take a look for yourself at what you put into that file. In addition, you attached the log from GetRunKey (called runkeys.txt) in message one. You just never attached the log from ShowNew (called newfiles.txt).

    And notice the first things CounterSpy detected and quarantined:
    3721 Chinese Keywords (CNSMin) Browser Plug-in more information...


    What is the below folder for:
    C:\KV-Back.vir

    Is this PC used to access Chinese websites and does it run Chinese applications? (I know you mentioned Chinese IE in your first message)
     
    Last edited: Dec 1, 2006
  6. nonsenc

    nonsenc Private E-2

    Yeah......you're right. wrong file. Sorry about that. This computer accesses Chinese websites and only runs legitimate Canon printing software in chinese. I have downloaded and installed the east asian language packs, but that's it. As for that C:/KV.vir file......I have no idea. I tried searching the net for any hints about that file but to no avail. Sorry again about all the hassle and your help is greatly appreciated.

    And now I cannot attach files.......the icon to attach files does not work for me.
    I am just going to cut and paste the Show now file. sorry.


    ******************************************************************************
    * ShowNew.Bat - (c) 07/01/2006 By Chaslang *
    * *
    * 11/26/2006 Version 0.22 beta - Added displaying of free disk space on the *
    * drive where show new is installed. *
    ******************************************************************************
    * Most of the information reported below is not necessarily bad. You must *
    * not take any steps on any of these lines without consulting an expert. *
    ******************************************************************************

    Windows OS is

    Microsoft Windows XP [Version 5.1.2600]
    It's Mon December 4, 2006 09:59:11 PM

    ******************************************************************************
    ShowNew installation folder and files

    "D:\Fix Programs\ShowNew\"
    grep.exe Apr 14 2003 80412 "grep.exe"
    locate.com Jan 13 2005 11254 "locate.com"
    ltime.exe Oct 28 1986 13184 "ltime.exe"
    shownew.bat Nov 26 2006 34060 "ShowNew.bat"

    4 items found: 4 files, 0 directories.
    Total of file sizes: 138,910 bytes 135.65 K
    2 Dir(s) 65,736,900,608 bytes free

    ******************************************************************************

    System Environment Variables
    ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS
    APPDATA=C:\Documents and Settings\Asus.ASUS-2852DBE852\Application Data
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=ASUS-2852DBE852
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Asus.ASUS-2852DBE852
    LOGONSERVER=\\ASUS-2852DBE852
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=0c00
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\ASUS~1.ASU\LOCALS~1\Temp
    TMP=C:\DOCUME~1\ASUS~1.ASU\LOCALS~1\Temp
    USERDOMAIN=ASUS-2852DBE852
    USERNAME=Asus
    USERPROFILE=C:\Documents and Settings\Asus.ASUS-2852DBE852
    windir=C:\WINDOWS
    __COMPAT_LAYER=DisableNXShowUI

    ******************************************************************************

    Showing any Pocket Killbox backup files

    "C:\!KillBox\"
    ie7-wi~1.exe Nov 13 2006 0 "IE7-WI~1.EXE"

    1 item found: 1 file, 0 directories.
    Total of file sizes: 0 bytes 0.00 K

    ******************************************************************************

    Not All Files Found are bad files: DO NOT TOUCH THEM WITHOUT EXPERT HELP!!!!
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\Asus.ASUS-2852DBE852\Desktop within the last 90 days.

    "C:\Documents and Settings\Asus.ASUS-2852DBE852\Desktop\"
    FIXFOL~1 Nov 29 2006 "Fix folder"
    ie7-wi~1.exe Nov 13 2006 0 "IE7-WindowsServer2003-x86-hh.exe"
    killbox.exe Sep 5 2006 73728 "KillBox.exe"
    shortc~1.lnk Nov 14 2006 511 "Shortcut to Downloads.lnk"
    torren~1.txt Nov 27 2006 47 "Torrent downloaded from Demonoid.com.txt"
    torren~1.lnk Sep 27 2006 524 "μTorrent.lnk"
    媛媛的~1 Nov 28 2006 "媛媛的商店"

    7 items found: 5 files, 2 directories.
    Total of file sizes: 74,810 bytes 73.05 K
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\Asus.ASUS-2852DBE852\Start Menu\Programs\Startup within the last 90 days.

    No matches found.
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\All Users.WINDOWS\Start Menu within the last 90 days.

    No matches found.
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ within the last 90 days.

    "C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\"
    adober~1.lnk Dec 4 2006 2325 "Adobe Reader Speed Launch.lnk"

    1 item found: 1 file, 0 directories.
    Total of file sizes: 2,325 bytes 2.27 K
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\All Users.WINDOWS\Desktop\ within the last 90 days.

    "C:\Documents and Settings\All Users.WINDOWS\Desktop\"
    adobep~1.lnk Nov 28 2006 670 "Adobe Photoshop Elements 5.0.lnk"
    cataly~1.lnk Sep 20 2006 1875 "Catalyst Control Center.lnk"
    counte~1.lnk Dec 1 2006 1544 "CounterSpy.lnk"
    daemon~1.lnk Nov 27 2006 588 "DAEMON Tools.lnk"
    easy-p~1.lnk Nov 16 2006 808 "Easy-PhotoPrint.lnk"
    mp530~1.lnk Nov 16 2006 1910 "MP530 电子手册.lnk"
    mpnavi~1.lnk Nov 16 2006 1693 "MP Navigator 2.2.lnk"
    msnmes~1.lnk Nov 29 2006 1862 "MSN Messenger 7.5.lnk"
    presto~1.lnk Nov 16 2006 868 "Presto! PageManager 7.15.lnk"
    qqd190~1.lnk Nov 4 2006 640 "QQó??·.lnk"
    vlcmed~1.lnk Sep 23 2006 635 "VLC media player.lnk"

    11 items found: 11 files, 0 directories.
    Total of file sizes: 13,093 bytes 12.79 K
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\Asus.ASUS-2852DBE852\Application Data\ within the last 90 days.

    "C:\Documents and Settings\Asus.ASUS-2852DBE852\Application Data\"
    BITDEF~1 Dec 1 2006 "BitDefender"
    CANON Nov 16 2006 "Canon"
    DATALA~1 Sep 30 2006 "Datalayer"
    DVDCSS Nov 27 2006 "dvdcss"
    NEWSOFT Nov 16 2006 "NewSoft"
    NOKIA Sep 30 2006 "Nokia"
    NOKIAM~1 Oct 3 2006 "Nokia Multimedia Player"
    PCSUIT~1 Sep 30 2006 "PC Suite"
    UTORRENT Sep 27 2006 "uTorrent"

    9 items found: 0 files, 9 directories.
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\Asus.ASUS-2852DBE852\Local Settings\Application Data\ within the last 90 days.

    "C:\Documents and Settings\Asus.ASUS-2852DBE852\Local Settings\Application Data\"
    dcbc2a~1.ini Dec 4 2006 170496 "DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini"
    gdipfo~1.dat Nov 28 2006 26072 "GDIPFONTCACHEV1.DAT"
    NEWSOFT Nov 16 2006 "NewSoft"
    SUNBEL~1 Dec 1 2006 "Sunbelt Software"

    4 items found: 2 files, 2 directories.
    Total of file sizes: 196,568 bytes 191.96 K
    ******************************************************************************

    Locating all files created in C:\Documents and Settings\All Users.WINDOWS\Application Data\ within the last 90 days.

    "C:\Documents and Settings\All Users.WINDOWS\Application Data\"
    CANONBJ Nov 16 2006 "CanonBJ"
    ESPION~1 Nov 28 2006 "espionServerData"
    OFFICE~1 Nov 13 2006 "Office Genuine Advantage"
    SPYBOT~1 Nov 29 2006 "Spybot - Search & Destroy"
    TENCENT Oct 7 2006 "Tencent"

    5 items found: 0 files, 5 directories (1 H/S).
    ******************************************************************************

    Locating all files created in C:\Program Files\ within the last 90 days.

    "C:\Program Files\"
    CANON Nov 16 2006 "Canon"
    MSXML4~1.0 Nov 20 2006 "MSXML 4.0"
    REAL Oct 14 2006 "Real"
    REALTE~2 Nov 17 2006 "Realtek AC97"
    SAMSUNG Nov 3 2006 "Samsung"
    SOFTWIN Dec 1 2006 "Softwin"
    TENCENT Oct 7 2006 "Tencent"
    WINAMP Oct 16 2006 "Winamp"

    8 items found: 0 files, 8 directories.
    ******************************************************************************

    DeluxeCommunications Search (new form of SurfSideKick)
    Locating all files created in C:\Program Files\DeluxeCommunications\ within the last 90 days.

    No matches found.
    ******************************************************************************

    WebHancer - dohancer form Search
    Locating all files created in C:\Program Files\em\ within the last 90 days.

    No matches found.
    ******************************************************************************

    WebHancer - hancmmnew form Search
    Locating all files created in C:\Program Files\mm\ within the last 90 days.

    No matches found.
    ******************************************************************************

    Locating all files created in C:\Program Files\Common Files\ within the last 90 days.

    "C:\Program Files\Common Files\"
    NOKIA Sep 30 2006 "Nokia"
    PCSUITE Sep 30 2006 "PCSuite"
    PDFVIEW Nov 16 2006 "PDFView"
    SOFTWIN Dec 1 2006 "Softwin"
    WISEIN~1 Nov 27 2006 "Wise Installation Wizard"
    XINGSH~1 Oct 14 2006 "xing shared"

    6 items found: 0 files, 6 directories.
    ******************************************************************************

    Locating all files created in C:\Program Files\Common Files\Microsoft Shared\Web Folders within the last 120 days.

    No matches found.
    ******************************************************************************

    Locating all files created in C:\ within the last 90 days.

    "C:\"
    !KILLBOX Sep 5 2006 "!KillBox"
    adobed~1.txt Nov 28 2006 0 "AdobeDebug.txt"
    amt1 Oct 16 2006 241484 "amt1"
    boot.ini Nov 29 2006 310 "boot.ini"
    CANONMP Nov 16 2006 "CanonMP"
    CONFIG.MSI Dec 1 2006 "Config.Msi"
    newfiles.txt Dec 4 2006 11346 "newfiles.txt"
    pagefile.sys Dec 4 2006 1610612736 "pagefile.sys"
    runkeys.txt Nov 29 2006 12159 "runkeys.txt"

    9 items found: 6 files (2 H/S), 3 directories (2 H/S).
    Total of file sizes: 1,610,878,035 bytes 1.50 G
    ******************************************************************************

    Locating all files created in C:\WINDOWS\Downloaded Program Files\ within the last 90 days.

    No matches found.
    ******************************************************************************

    Locating .EXE files created in C:\WINDOWS within the last 360 days.

    "C:\WINDOWS\"
    alcfdrtm.exe Apr 3 2006 60416 "ALCFDRTM.EXE"
    bdosca~1.exe May 25 2006 53248 "bdoscandel.exe"
    soundman.exe Jan 11 2006 577536 "soundman.exe"
    uninst~1.exe Apr 3 2006 107134 "UninstallFirefox.exe"

    4 items found: 4 files, 0 directories.
    Total of file sizes: 798,334 bytes 779.62 K
    ******************************************************************************

    Locating .EXE files created in C:\WINDOWS\system32 within the last 90 days.

    "C:\WINDOWS\system32\"
    aswboot.exe Sep 25 2006 666240 "aswBoot.exe"
    java.exe Oct 12 2006 49248 "java.exe"
    javaw.exe Oct 12 2006 53346 "javaw.exe"
    javaws.exe Oct 12 2006 127078 "javaws.exe"
    mrt.exe Nov 16 2006 10474920 "MRT.exe"
    pxcpyi64.exe Nov 28 2006 108544 "pxcpyi64.exe"
    unins000.exe Sep 27 2006 657667 "unins000.exe"
    wgatray.exe Sep 20 2006 280368 "WgaTray.exe"

    8 items found: 8 files, 0 directories.
    Total of file sizes: 12,417,411 bytes 11.84 M
    ******************************************************************************

    Locating .DLL files created in C:\WINDOWS within the last 360 days.

    No matches found.
    ******************************************************************************

    Locating .DLL files created in C:\WINDOWS\System32 within the last 90 days.

    "C:\WINDOWS\system32\"
    browseui.dll Sep 14 2006 1022976 "browseui.dll"
    cdfview.dll Sep 14 2006 151040 "cdfview.dll"
    cmdlin~1.dll Oct 29 2006 43520 "CmdLineExt03.dll"
    danim.dll Sep 14 2006 1054208 "danim.dll"
    dxtmsft.dll Sep 14 2006 357888 "dxtmsft.dll"
    dxtrans.dll Sep 14 2006 205312 "dxtrans.dll"
    extmgr.dll Sep 14 2006 55808 "extmgr.dll"
    iepeers.dll Sep 14 2006 251392 "iepeers.dll"
    inseng.dll Sep 14 2006 96256 "inseng.dll"
    jsproxy.dll Sep 14 2006 16384 "jsproxy.dll"
    legitc~1.dll Sep 20 2006 571696 "LegitCheckControl.dll"
    mshtml.dll Sep 14 2006 3054592 "mshtml.dll"
    mshtmled.dll Sep 14 2006 448512 "mshtmled.dll"
    msrating.dll Sep 14 2006 146432 "msrating.dll"
    mstime.dll Sep 14 2006 532480 "mstime.dll"
    msxml3.dll Sep 13 2006 1084416 "msxml3.dll"
    msxml4.dll Nov 4 2006 1245696 "msxml4.dll"
    nwapi32.dll Oct 13 2006 64000 "nwapi32.dll"
    nwprovau.dll Oct 13 2006 142336 "nwprovau.dll"
    nwwks.dll Oct 13 2006 65536 "nwwks.dll"
    pncrt.dll Oct 14 2006 278528 "pncrt.dll"
    pndx5016.dll Oct 14 2006 6656 "pndx5016.dll"
    pndx5032.dll Oct 14 2006 5632 "pndx5032.dll"
    pngfilt.dll Sep 14 2006 39424 "pngfilt.dll"
    rmoc3260.dll Oct 14 2006 176167 "rmoc3260.dll"
    shlwapi.dll Sep 14 2006 474112 "shlwapi.dll"
    sintf16.dll Oct 3 2006 12067 "SIntf16.dll"
    sintf32.dll Oct 3 2006 17212 "SIntf32.dll"
    sintfnt.dll Oct 3 2006 21840 "SIntfNT.dll"
    urlmon.dll Sep 14 2006 613888 "urlmon.dll"
    wgalogon.dll Sep 20 2006 441136 "WgaLogon.dll"
    wininet.dll Sep 14 2006 658944 "wininet.dll"
    xpsp3res.dll Oct 16 2006 115200 "xpsp3res.dll"

    33 items found: 33 files, 0 directories.
    Total of file sizes: 13,471,286 bytes 12.84 M
    ******************************************************************************

    Locating .TMP files created in C:\WINDOWS\System32 within the last 90 days.

    No matches found.
    ******************************************************************************

    Locating .INI files created in C:\WINDOWS\System32 within the last 90 days.

    "C:\WINDOWS\system32\"
    perfst~1.ini Nov 17 2006 461310 "PerfStringBackup.INI"

    1 item found: 1 file, 0 directories.
    Total of file sizes: 461,310 bytes 450.50 K
    ******************************************************************************

    Locating .DAT files created in C:\WINDOWS\System32 within the last 90 days.

    "C:\WINDOWS\system32\"
    cid_st~1.dat Nov 29 2006 236 "cid_store.dat"
    fntcache.dat Nov 28 2006 119744 "FNTCACHE.DAT"
    getfile.dat Dec 1 2006 15 "getfile.dat"
    perfc009.dat Nov 17 2006 59440 "perfc009.dat"
    perfh009.dat Nov 17 2006 395200 "perfh009.dat"
    unins000.dat Sep 27 2006 838 "unins000.dat"

    6 items found: 6 files, 0 directories.
    Total of file sizes: 575,473 bytes 561.98 K
    ******************************************************************************

    Locating all files created in C:\WINDOWS\System32\components within the last 90 days.
    This folder is now being used by Trojan.FakeAlert.CX aka SmitFraud

    No matches found.
    ******************************************************************************

    Locating C:\WINDOWS\TEMP files created with in the last 90 days.

    "C:\WINDOWS\Temp\"
    perfli~1.dat Dec 4 2006 16384 "Perflib_Perfdata_484.dat"
    _AVAST4_ Nov 29 2006 "_avast4_"

    2 items found: 1 file, 1 directory.
    Total of file sizes: 16,384 bytes 16.00 K
    ******************************************************************************

    Locating C:\Documents and Settings\Asus.ASUS-2852DBE852\Local Settings\TEMP files created within the last 90 days.

    "C:\Documents and Settings\Asus.ASUS-2852DBE852\Local Settings\Temp\"
    perfli~1.dat Dec 4 2006 16384 "Perflib_Perfdata_aac.dat"
    perfli~2.dat Dec 4 2006 16384 "Perflib_Perfdata_ec.dat"
    perfli~3.dat Dec 4 2006 16384 "Perflib_Perfdata_fa8.dat"
    perfli~4.dat Dec 4 2006 16384 "Perflib_Perfdata_208.dat"
    ~dfb644.tmp Dec 4 2006 49152 "~DFB644.tmp"
    ~dfdeed.tmp Dec 4 2006 32768 "~DFDEED.tmp"
    ~dff308.tmp Dec 4 2006 16384 "~DFF308.tmp"

    7 items found: 7 files, 0 directories.
    Total of file sizes: 163,840 bytes 160.00 K
    ******************************************************************************

    Locating .COM files in the C:\WINDOWS\System32 folder

    "C:\WINDOWS\system32\"
    chcp.com Aug 4 2004 7680 "chcp.com"
    command.com Aug 4 2004 50620 "command.com"
    diskcomp.com Aug 4 2004 9216 "diskcomp.com"
    diskcopy.com Aug 4 2004 7168 "diskcopy.com"
    edit.com Aug 4 2004 69886 "edit.com"
    format.com Aug 4 2004 25600 "format.com"
    graftabl.com Aug 4 2004 26112 "graftabl.com"
    graphics.com Aug 4 2004 19694 "graphics.com"
    kb16.com Aug 4 2004 14710 "kb16.com"
    loadfix.com Aug 4 2004 1131 "loadfix.com"
    locate.com Jan 13 2005 11254 "locate.com"
    mode.com Aug 4 2004 19456 "mode.com"
    more.com Aug 4 2004 15872 "more.com"
    tree.com Aug 4 2004 11264 "tree.com"
    win.com Aug 4 2004 18432 "win.com"

    15 items found: 15 files, 0 directories.
    Total of file sizes: 308,095 bytes 300.87 K
    ******************************************************************************

    Checking for .COM files to Delete. They will only print if deleted!

    ******************************************************************************

    Dumping HKLM Uninstall Programs list

    "DisplayName"="3ivx D4 4.5.1 (remove only)"
    "DisplayName"="à?èí???ú′?2???ò?ì??ˉ V4.52 μ¥?ú/í???°?"
    "DisplayName"="Ace DivX Player"
    "DisplayName"="Adobe Help Center 2.1"
    "DisplayName"="Adobe Photoshop Elements 5.0"
    "DisplayName"="Adobe Photoshop Elements 5.0"
    "DisplayName"="Adobe Reader 7.0"
    "DisplayName"="Ahead Nero Burning ROM"
    "DisplayName"="ASUSDVD XP"
    "DisplayName"="ATI - Software Uninstall Utility"
    "DisplayName"="ATI Catalyst Control Center"
    "DisplayName"="ATI Catalyst Control Center"
    "DisplayName"="ATI Display Driver"
    "DisplayName"="avast! Antivirus"
    "DisplayName"="BitComet 0.70"
    "DisplayName"="Canon MP Navigator 2.2"
    "DisplayName"="Canon MP500"
    "DisplayName"="Canon MP530"
    "DisplayName"="Canon Utilities Easy-PhotoPrint"
    "DisplayName"="Caplio Software"
    "DisplayName"="CCleaner (remove only)"
    "DisplayName"="CD-LabelPrint"
    "DisplayName"="CD/DVD-ROM Generator 2.00"
    "DisplayName"="CDRWIN 6.1"
    "DisplayName"="CleanUp!"
    "DisplayName"="CmbEdit"
    "DisplayName"="DVD Decrypter (Remove Only)"
    "DisplayName"="DVD Shrink 3.2"
    "DisplayName"="Easy-WebPrint"
    "DisplayName"="ffdshow"
    "DisplayName"="GSpot Codec Information Appliance"
    "DisplayName"="HijackThis 1.99.1"
    "DisplayName"="Huffyuv AVI lossless video codec (Remove Only)"
    "DisplayName"="ImageMixer"
    "DisplayName"="iPod for Windows 2005-06-26"
    "DisplayName"="iPod for Windows 2005-06-26"
    "DisplayName"="iTunes"
    "DisplayName"="iTunes"
    "DisplayName"="J2SE Runtime Environment 5.0 Update 6"
    "DisplayName"="J2SE Runtime Environment 5.0 Update 9"
    "DisplayName"="K-Lite Codec Pack 2.51 Full"
    "DisplayName"="LimeWire PRO 4.10.5"
    "DisplayName"="Macromedia Flash Player 8"
    "DisplayName"="Microsoft .NET Framework 2.0"
    "DisplayName"="Microsoft .NET Framework 2.0"
    "DisplayName"="Microsoft Office Standard Edition 2003"
    "DisplayName"="Mozilla Firefox (1.5.0.8)"
    "DisplayName"="MP3 To Ringtone Gold 3.26"
    "DisplayName"="MSN Messenger 7.5"
    "DisplayName"="MSN Shell 4"
    "DisplayName"="MSXML 4.0 SP2 (KB927978)"
    "DisplayName"="nAVI Vx3 MPEG-4 Codec"
    "DisplayName"="Noiseware Community Edition"
    "DisplayName"="Nokia Connectivity Cable Driver"
    "DisplayName"="Nokia PC Suite"
    "DisplayName"="NVIDIA Drivers"
    "DisplayName"="NvMixer"
    "DisplayName"="Panda ActiveScan"
    "DisplayName"="PartitionMagic"
    "DisplayName"="PIMS & File Manager"
    "DisplayName"="Portable USB Storage Device"
    "DisplayName"="PowerQuest PartitionMagic 8.0"
    "DisplayName"="Presto! PageManager 7.15.12"
    "DisplayName"="QQ?é??ó??·"
    "DisplayName"="QQáú?é??é?°?"
    "DisplayName"="QQíú?ó"
    "DisplayName"="QQó??·"
    "DisplayName"="QQó??·′óìü"
    "DisplayName"="QQ对对碰游戏"
    "DisplayName"="QQ龙珠游戏"
    "DisplayName"="QQ麻将游戏"
    "DisplayName"="QuickTime"
    "DisplayName"="RealPlayer"
    "DisplayName"="Realtek AC'97 Audio"
    "DisplayName"="Registry Mechanic 5.0"
    "DisplayName"="Rome - Total War(TM)"
    "DisplayName"="Rome - Total War(TM)"
    "DisplayName"="SafeInput 1.0"
    "DisplayName"="Security Update for Microsoft .NET Framework 2.0 (KB922770)"
    "DisplayName"="Security Update for Windows Media Player (KB911564)"
    "DisplayName"="Security Update for Windows Media Player 10 (KB911565)"
    "DisplayName"="Security Update for Windows Media Player 10 (KB917734)"
    "DisplayName"="Security Update for Windows XP (KB890046)"
    "DisplayName"="Security Update for Windows XP (KB893756)"
    "DisplayName"="Security Update for Windows XP (KB896358)"
    "DisplayName"="Security Update for Windows XP (KB896422)"
    "DisplayName"="Security Update for Windows XP (KB896423)"
    "DisplayName"="Security Update for Windows XP (KB896424)"
    "DisplayName"="Security Update for Windows XP (KB896428)"
    "DisplayName"="Security Update for Windows XP (KB899587)"
    "DisplayName"="Security Update for Windows XP (KB899589)"
    "DisplayName"="Security Update for Windows XP (KB899591)"
    "DisplayName"="Security Update for Windows XP (KB900725)"
    "DisplayName"="Security Update for Windows XP (KB901017)"
    "DisplayName"="Security Update for Windows XP (KB901190)"
    "DisplayName"="Security Update for Windows XP (KB901214)"
    "DisplayName"="Security Update for Windows XP (KB902400)"
    "DisplayName"="Security Update for Windows XP (KB904706)"
    "DisplayName"="Security Update for Windows XP (KB905414)"
    "DisplayName"="Security Update for Windows XP (KB905749)"
    "DisplayName"="Security Update for Windows XP (KB905915)"
    "DisplayName"="Security Update for Windows XP (KB908519)"
    "DisplayName"="Security Update for Windows XP (KB908531)"
    "DisplayName"="Security Update for Windows XP (KB911280)"
    "DisplayName"="Security Update for Windows XP (KB911562)"
    "DisplayName"="Security Update for Windows XP (KB911567)"
    "DisplayName"="Security Update for Windows XP (KB911927)"
    "DisplayName"="Security Update for Windows XP (KB912812)"
    "DisplayName"="Security Update for Windows XP (KB912919)"
    "DisplayName"="Security Update for Windows XP (KB913446)"
    "DisplayName"="Security Update for Windows XP (KB913580)"
    "DisplayName"="Security Update for Windows XP (KB914388)"
    "DisplayName"="Security Update for Windows XP (KB914389)"
    "DisplayName"="Security Update for Windows XP (KB916281)"
    "DisplayName"="Security Update for Windows XP (KB917159)"
    "DisplayName"="Security Update for Windows XP (KB917344)"
    "DisplayName"="Security Update for Windows XP (KB917422)"
    "DisplayName"="Security Update for Windows XP (KB917953)"
    "DisplayName"="Security Update for Windows XP (KB918439)"
    "DisplayName"="Security Update for Windows XP (KB918899)"
    "DisplayName"="Security Update for Windows XP (KB920213)"
    "DisplayName"="Security Update for Windows XP (KB920214)"
    "DisplayName"="Security Update for Windows XP (KB920670)"
    "DisplayName"="Security Update for Windows XP (KB920683)"
    "DisplayName"="Security Update for Windows XP (KB921398)"
    "DisplayName"="Security Update for Windows XP (KB921883)"
    "DisplayName"="Security Update for Windows XP (KB922616)"
    "DisplayName"="Security Update for Windows XP (KB922760)"
    "DisplayName"="Security Update for Windows XP (KB922819)"
    "DisplayName"="Security Update for Windows XP (KB923191)"
    "DisplayName"="Security Update for Windows XP (KB923414)"
    "DisplayName"="Security Update for Windows XP (KB923980)"
    "DisplayName"="Security Update for Windows XP (KB924191)"
    "DisplayName"="Security Update for Windows XP (KB924270)"
    "DisplayName"="Security Update for Windows XP (KB924496)"
    "DisplayName"="Security Update for Windows XP (KB925486)"
    "DisplayName"="setup (Remove only)"
    "DisplayName"="Shutterfly Plugin"
    "DisplayName"="Skype 2.5"
    "DisplayName"="Spybot - Search & Destroy 1.4"
    "DisplayName"="Sunbelt CounterSpy"
    "DisplayName"="Sygate Personal Firewall Pro"
    "DisplayName"="Tencent Media Player by Viewpoint"
    "DisplayName"="Update for Windows XP (KB894391)"
    "DisplayName"="Update for Windows XP (KB898461)"
    "DisplayName"="Update for Windows XP (KB900485)"
    "DisplayName"="Update for Windows XP (KB910437)"
    "DisplayName"="Update for Windows XP (KB916595)"
    "DisplayName"="VideoLAN VLC media player 0.8.5"
    "DisplayName"="VobSub v2.05 (Remove Only)"
    "DisplayName"="WebFldrs XP"
    "DisplayName"="Winamp (remove only)"
    "DisplayName"="Windows Defender Signatures"
    "DisplayName"="Windows Genuine Advantage Notifications (KB905474)"
    "DisplayName"="Windows Genuine Advantage Validation Tool"
    "DisplayName"="Windows Installer 3.1 (KB893803)"
    "DisplayName"="Windows XP Hotfix - KB873339"
    "DisplayName"="Windows XP Hotfix - KB885250"
    "DisplayName"="Windows XP Hotfix - KB885835"
    "DisplayName"="Windows XP Hotfix - KB885836"
    "DisplayName"="Windows XP Hotfix - KB886185"
    "DisplayName"="Windows XP Hotfix - KB887472"
    "DisplayName"="Windows XP Hotfix - KB887742"
    "DisplayName"="Windows XP Hotfix - KB888113"
    "DisplayName"="Windows XP Hotfix - KB888302"
    "DisplayName"="Windows XP Hotfix - KB890859"
    "DisplayName"="Windows XP Hotfix - KB891781"
    "DisplayName"="WinRAR archiver"
    "DisplayName"="μTorrent"
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There should be no reason why you cannot attach the log. Just dump your IE cache and click refresh next time.

    The below list of programs are things from your ShowNew log. They are things that are installed on your PC. Ignore the "DisplayName"=" at the beginning of each line it is just the formatting from dumping the list out of the registry. I'm adding comments and questions in RED on each line or above a certain group of items.


    "DisplayName"="à?èí???ú′?2???ò?ì??ˉ V4.52 μ¥?ú/í???°?" ---> What is this?

    What are all of the below? Is this a Chinese Instant Messenger? I thought you said only a Chinese IE was added. COunterSpy did not like these! They should all be uninstalled. Some of these lines may be duplicate entries.
    "DisplayName"="QQ?é??ó??·"
    "DisplayName"="QQáú?é??é?°?"
    "DisplayName"="QQíú?ó"
    "DisplayName"="QQó??·"
    "DisplayName"="QQó??·′óìü"
    "DisplayName"="QQ对对碰游戏"
    "DisplayName"="QQ龙珠游戏"
    "DisplayName"="QQ麻将游戏"

    Uninstall All of the below.
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Tencent Media Player by Viewpoint
     
  8. nonsenc

    nonsenc Private E-2

    Replies to your questions in Orange

    "DisplayName"="à?èí???ú′?2???ò?ì??ˉ V4.52 μ¥?ú/í???°?" ---> What is this?
    This is a viewer for Chinese Docs. Sorry, This was installed by my girlfriend a couple days ago. She swears it's kosher.

    "DisplayName"="QQ?é??ó??·"
    "DisplayName"="QQáú?é??é?°?"
    "DisplayName"="QQíú?ó"
    "DisplayName"="QQó??·"
    "DisplayName"="QQó??·′óìü"
    "DisplayName"="QQ对对碰游戏"
    "DisplayName"="QQ龙珠游戏"
    "DisplayName"="QQ麻将游戏"
    All this is a Chinese instant messenger and on-line community gaming software. It's now gone.




    Uninstall All of the below.
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Tencent Media Player by Viewpoint

    These are now uninstalled.


    What's the next step?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What's your current status?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds