Bad Virus.. Please check logs and advise... [Solved], I tried to fix do know if I did more harm then good |
![]() ![]() |
Bad Virus.. Please check logs and advise... [Solved], I tried to fix do know if I did more harm then good |
Feb 21 2009, 08:39 PM
Post
#1
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Running Windows xp sp 3
Well I have a terrible virus. The virus disabled these items: Task Manager Regedit Chk disk Defrag Folder options Spybot - wont run anymore Google redict thing.... Terrible pop-ups I read allot of different forums but the advice I found on this one actually worked the best! I followed the direction on this post: http://www.geekstogo.com/forum/Google-Redi...us-t229785.html And everything seems to be ok now. I was hoping someone would take a look at my logs to see if Im good or do I need to do more. Thank you in advance for all your help!! This post has been edited by BBJrDA: Feb 21 2009, 09:23 PM
Attached File(s)
Extras.Txt ( 64.38K )
Number of downloads: 56
OTListIt.Txt ( 70.83K )
Number of downloads: 40
combofix.txt ( 14.7K )
Number of downloads: 42
mbam_log_2009_02_21__19_08_30_.txt ( 7.42K )
Number of downloads: 52
hijackthis.txt ( 8.06K )
Number of downloads: 57 |
|
|
Feb 21 2009, 08:51 PM
Post
#2
|
|
![]() Trusted Helper Posts: 4,592 From: London, UK OS: XP |
Hello BBJrDA
welcome to geekstogo could you re-run combofix by double clicking its icon on your desktop could you then post the log as a reply to this thread by copying and pasting the log into the reply - dont attach the log unless i ask you to. and could you re-run the hijackthis and copy and paste in the log please. andrewuk |
|
|
Feb 21 2009, 09:03 PM
Post
#3
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Sorry about attaching the text files.. Thought it would be way to much to read.. any ways thanks for taking a look here is the combo fix log..
ComboFix 09-02-19.01 - Hollie 2009-02-21 19:57:53.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1598 [GMT -7:00] Running from: c:\documents and settings\Hollie\Desktop\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 ))))))))))))))))))))))))))))))) . 2009-02-21 18:32 . 2009-02-21 18:32 <DIR> d-------- c:\documents and settings\Hollie\Application Data\Malwarebytes 2009-02-21 18:31 . 2009-02-21 18:32 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-21 18:31 . 2009-02-21 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-21 18:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-21 18:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-21 18:29 . 2009-02-21 18:29 <DIR> d-------- c:\program files\Trend Micro 2009-02-21 17:57 . 2009-02-21 18:11 <DIR> d-------- c:\program files\Spybot - Search & Destroy 2009-02-20 19:50 . 2009-02-20 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-02-20 19:49 . 2009-02-20 19:49 <DIR> d-------- c:\documents and settings\Hollie\Application Data\SUPERAntiSpyware.com 2009-02-20 17:23 . 2009-02-20 17:23 <DIR> d-------- c:\documents and settings\Hollie\Application Data\GlarySoft 2009-02-20 16:51 . 2009-02-21 19:21 13,588 --a------ c:\windows\system32\wpa.dbl 2009-02-20 12:57 . 2009-02-20 12:57 <DIR> d-------- c:\program files\CCleaner 2009-02-19 22:40 . 2009-02-19 22:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI 2009-02-19 13:45 . 2009-02-19 13:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\DivX 2009-02-17 18:53 . 2009-02-17 18:53 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Talkback 2009-02-17 18:50 . 2009-02-20 16:40 <DIR> d-------- c:\documents and settings\Administrator 2009-02-17 13:36 . 2009-02-18 18:26 32,768 --a------ c:\windows\system32\drivers\ati4gmxx.sys 2009-02-10 23:13 . 2009-02-10 23:13 361,600 --a------ c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2009-01-28 19:57 . 2009-01-28 19:57 <DIR> d-------- c:\program files\Hide and Secret 2009-01-24 21:32 . 2009-01-24 21:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\PopCapGamesv1005 2009-01-24 21:31 . 2009-01-24 21:31 <DIR> d-------- c:\program files\PopCap Games 2009-01-24 19:02 . 2009-01-24 19:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Mushroom Age 2009-01-23 01:49 . 2009-01-23 01:49 <DIR> d-------- C:\users 2009-01-23 01:28 . 2009-02-17 19:01 <DIR> d-------- c:\program files\RealArcade . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-22 02:57 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-02-22 00:54 --------- d-----w c:\program files\Macrogaming 2009-02-22 00:02 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-02-21 21:35 --------- d-----w c:\documents and settings\Hollie\Application Data\uTorrent 2009-02-21 16:10 --------- d-----w c:\program files\Qwest 2009-02-20 18:49 --------- d-----w c:\program files\Agatha Christie - Peril at End House 2009-02-20 05:37 --------- d-----w c:\program files\ATI Technologies 2009-02-19 20:43 --------- d-----w c:\program files\DivX 2009-02-18 03:26 14,336 ----a-w c:\windows\system32\svchost.exe 2009-02-18 02:46 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-16 23:56 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-02-13 04:30 --------- d-----w c:\documents and settings\Hollie\Application Data\dvdcss 2009-02-12 17:59 --------- d-----w c:\documents and settings\Hollie\Application Data\Vso 2009-02-11 06:13 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS 2009-01-20 22:16 --------- d-----w c:\documents and settings\Hollie\Application Data\Flood Light Games 2009-01-20 22:16 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games 2009-01-04 03:19 --------- d-----w c:\program files\EA SPORTS 2008-12-28 05:49 --------- d-----w c:\program files\Smilebox 2008-12-25 18:39 --------- d-----w c:\documents and settings\All Users\Application Data\Knowledge Adventure 2008-12-25 18:34 --------- d-----w c:\program files\JumpStart World 2008-12-25 18:33 --------- d--h--w c:\program files\InstallShield Installation Information 2008-12-25 18:33 --------- d-----w c:\program files\Common Files\Knowledge Adventure 2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll 2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll 2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll 2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll 2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll 2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll 2008-12-01 21:35 593,920 ------w c:\windows\system32\ati2sgag.exe 2008-12-01 20:52 425,984 ----a-w c:\windows\system32\ATIDEMGX.dll 2008-12-01 20:51 318,464 ----a-w c:\windows\system32\ati2dvag.dll 2008-12-01 20:46 11,304,960 ----a-w c:\windows\system32\atioglxx.dll 2008-12-01 20:41 188,416 ----a-w c:\windows\system32\atipdlxx.dll 2008-12-01 20:40 43,520 ----a-w c:\windows\system32\ati2edxx.dll 2008-12-01 20:40 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe 2008-12-01 20:40 147,456 ----a-w c:\windows\system32\Oemdspif.dll 2008-12-01 20:40 143,360 ----a-w c:\windows\system32\ati2evxx.dll 2008-12-01 20:38 598,016 ----a-w c:\windows\system32\ati2evxx.exe 2008-12-01 20:37 53,248 ----a-w c:\windows\system32\ATIDDC.DLL 2008-12-01 20:27 4,120,384 ----a-w c:\windows\system32\ati3duag.dll 2008-12-01 20:19 307,200 ----a-w c:\windows\system32\atiiiexx.dll 2008-12-01 20:11 2,495,360 ----a-w c:\windows\system32\ativvaxx.dll 2008-12-01 19:57 48,640 ----a-w c:\windows\system32\amdpcom32.dll 2008-12-01 19:53 45,056 ----a-w c:\windows\system32\amdcalrt.dll 2008-12-01 19:53 45,056 ----a-w c:\windows\system32\amdcalcl.dll 2008-12-01 19:53 401,408 ----a-w c:\windows\system32\atikvmag.dll 2008-12-01 19:52 86,016 ----a-w c:\windows\system32\atiadlxx.dll 2008-12-01 19:52 17,408 ----a-w c:\windows\system32\atitvo32.dll 2008-12-01 19:50 3,252,224 ----a-w c:\windows\system32\Amdcaldd.dll 2008-12-01 19:50 286,720 ----a-w c:\windows\system32\atiok3x2.dll 2008-12-01 19:45 577,536 ----a-w c:\windows\system32\ati2cqag.dll 2008-07-03 18:41 47,360 ----a-w c:\documents and settings\Hollie\Application Data\pcouffin.sys 2008-07-03 18:11 87,608 ----a-w c:\documents and settings\Hollie\Application Data\ezpinst.exe 2007-10-15 09:37 774,144 ----a-w c:\program files\RngInterstitial.dll 2008-08-23 15:40 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082320080824\index.dat . ------- Sigcheck ------- 2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys 2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys 2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys 2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\$NtServicePackUninstall$\tcpip.sys 2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys 2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys 2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys 2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys 2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS 2009-02-10 23:13 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\dllcache\TCPIP.SYS 2009-02-10 23:13 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\drivers\TCPIP.SYS . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048] "dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2005-12-05 691200] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] c:\documents and settings\Hollie\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] c:\documents and settings\All Users\Start Menu\Programs\Startup\ hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 147456] hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 28672] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=oylvih.dll hhtmbr.dll userlg.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4gmxx.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Microsoft Games\\Mechwarrior Mercenaries\\MW4MERCS.ICD"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= S0 ati4gmxx;ati4gmxx;c:\windows\system32\drivers\ati4gmxx.sys [2009-02-17 32768] S1 9740f36f;9740f36f;c:\windows\system32\drivers\9740f36f.sys --> c:\windows\system32\drivers\9740f36f.sys [?] S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?] S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe --> c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [?] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fef53924-38aa-11dd-a3bf-0015059efc23}] \Shell\AutoRun\command - H:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder 2008-05-03 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1200736522.job - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 00:52] . . ------- Supplementary Scan ------- . mStart Page = hxxp://home.sweetim.com uInternet Settings,ProxyOverride = *.local IE: &Search - ?p=ZK IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Download All by FlashGet IE: Download using FlashGet IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Hollie\Application Data\Mozilla\Firefox\Profiles\qwrgqpco.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13761&gct=&gc=1&q= FF - plugin: c:\documents and settings\Hollie\Application Data\Mozilla\Firefox\Profiles\qwrgqpco.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-21 19:58:45 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1757981266-1715567821-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ac,0a,68,5b,dc,ff,0a,96,bb,15,f9,53,7a,86,7e,cc,5d,7b,36,2b,43,a7,a8, 86,29,d0,35,5a,3f,2a,2b,8f,01,81,28,ab,d0,6a,17,dc,9b,40,b2,25,2c,24,0b,f5,\ "??"=hex:f3,f7,9f,fd,8d,d1,5d,22,47,69,7c,4b,79,0d,25,ce [HKEY_USERS\S-1-5-21-1757981266-1715567821-682003330-1003\Software\SecuROM\License information*] "datasecu"=hex:b7,2e,49,a1,d4,ba,61,6e,27,96,bb,58,ae,00,2e,0e,94,a7,d3,29,f7, 55,2b,d1,db,9b,eb,70,ca,d6,7c,17,52,7e,c1,55,ad,77,21,55,c6,3b,b0,51,6f,49,\ "rkeysecu"=hex:ba,ae,56,43,80,b0,98,e8,95,a5,5c,ec,d2,52,69,d2 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(736) c:\windows\system32\Ati2evxx.dll . Completion time: 2009-02-21 20:00:02 ComboFix-quarantined-files.txt 2009-02-22 02:59:54 ComboFix2.txt 2009-02-22 02:23:35 Pre-Run: 9,050,824,704 bytes free Post-Run: 9,034,027,008 bytes free 207 --- E O F --- 2009-01-15 07:11:35 I will now run Hi jack this log ... give you a minute to read and then I will post that log... Thanks again!! |
|
|
Feb 21 2009, 09:06 PM
Post
#4
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Here is the Hijack log....
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:05:48 PM, on 2/21/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: hp psc 1000 series.lnk = ? O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Search - ?p=ZK O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v47/wwspades/wwspades.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O20 - AppInit_DLLs: oylvih.dll hhtmbr.dll userlg.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\ O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- End of file - 7454 bytes |
|
|
Feb 21 2009, 09:28 PM
Post
#5
|
|
![]() Trusted Helper Posts: 4,592 From: London, UK OS: XP |
QUOTE Sorry about attaching the text files.. Thought it would be way to much to read.. easier to read if they are copied and pasted in, to be honest is this meant to be your home page: http://home.sweetim.com ? ====STEP 1==== Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O8 - Extra context menu item: &Search - ?p=ZK Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. ====STEP 2==== 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: CODE File:: c:\windows\system32\drivers\ati4gmxx.sys c:\windows\system32\drivers\9740f36f.sys Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4gmxx.sys] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fef53924-38aa-11dd-a3bf-0015059efc23}] Driver:: ati4gmxx 9740f36f DirLook:: c:\program files\Hide and Secret Save this as CFScript.txt, in the same location as ComboFix.exe Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. and a new hijackthis log please. The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts. andrewuk |
|
|
Feb 22 2009, 12:21 AM
Post
#6
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
To answer your question... No http://home.sweetim.com is not meant to be my home page.. to be honest I have never heard of that site before...
Here is combo fix log: ComboFix 09-02-19.01 - Hollie 2009-02-21 23:12:30.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1465 [GMT -7:00] Running from: c:\documents and settings\Hollie\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Hollie\Desktop\CFScript.txt * Created a new restore point FILE :: c:\windows\system32\drivers\9740f36f.sys c:\windows\system32\drivers\ati4gmxx.sys . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\drivers\ati4gmxx.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ATI4GMXX -------\Service_9740f36f -------\Service_ati4gmxx ((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 ))))))))))))))))))))))))))))))) . 2009-02-21 18:32 . 2009-02-21 18:32 <DIR> d-------- c:\documents and settings\Hollie\Application Data\Malwarebytes 2009-02-21 18:31 . 2009-02-21 18:32 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-21 18:31 . 2009-02-21 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-21 18:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-21 18:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-21 18:29 . 2009-02-21 18:29 <DIR> d-------- c:\program files\Trend Micro 2009-02-21 17:57 . 2009-02-21 18:11 <DIR> d-------- c:\program files\Spybot - Search & Destroy 2009-02-20 19:50 . 2009-02-20 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-02-20 19:49 . 2009-02-20 19:49 <DIR> d-------- c:\documents and settings\Hollie\Application Data\SUPERAntiSpyware.com 2009-02-20 17:23 . 2009-02-20 17:23 <DIR> d-------- c:\documents and settings\Hollie\Application Data\GlarySoft 2009-02-20 16:51 . 2009-02-21 23:14 13,588 --a------ c:\windows\system32\wpa.dbl 2009-02-20 12:57 . 2009-02-20 12:57 <DIR> d-------- c:\program files\CCleaner 2009-02-19 22:40 . 2009-02-19 22:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI 2009-02-19 13:45 . 2009-02-19 13:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\DivX 2009-02-17 18:53 . 2009-02-17 18:53 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Talkback 2009-02-17 18:50 . 2009-02-20 16:40 <DIR> d-------- c:\documents and settings\Administrator 2009-02-10 23:13 . 2009-02-10 23:13 361,600 --a------ c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2009-01-28 19:57 . 2009-01-28 19:57 <DIR> d-------- c:\program files\Hide and Secret 2009-01-24 21:32 . 2009-01-24 21:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\PopCapGamesv1005 2009-01-24 21:31 . 2009-01-24 21:31 <DIR> d-------- c:\program files\PopCap Games 2009-01-24 19:02 . 2009-01-24 19:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Mushroom Age 2009-01-23 01:49 . 2009-01-23 01:49 <DIR> d-------- C:\users 2009-01-23 01:28 . 2009-02-17 19:01 <DIR> d-------- c:\program files\RealArcade . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-22 04:01 --------- d-----w c:\documents and settings\Hollie\Application Data\uTorrent 2009-02-22 02:57 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-02-22 00:54 --------- d-----w c:\program files\Macrogaming 2009-02-22 00:02 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-02-21 16:10 --------- d-----w c:\program files\Qwest 2009-02-20 18:49 --------- d-----w c:\program files\Agatha Christie - Peril at End House 2009-02-20 05:37 --------- d-----w c:\program files\ATI Technologies 2009-02-19 20:43 --------- d-----w c:\program files\DivX 2009-02-18 02:46 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-16 23:56 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-02-13 04:30 --------- d-----w c:\documents and settings\Hollie\Application Data\dvdcss 2009-02-12 17:59 --------- d-----w c:\documents and settings\Hollie\Application Data\Vso 2009-02-11 06:13 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS 2009-01-20 22:16 --------- d-----w c:\documents and settings\Hollie\Application Data\Flood Light Games 2009-01-20 22:16 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games 2009-01-04 03:19 --------- d-----w c:\program files\EA SPORTS 2008-12-28 05:49 --------- d-----w c:\program files\Smilebox 2008-12-25 18:39 --------- d-----w c:\documents and settings\All Users\Application Data\Knowledge Adventure 2008-12-25 18:34 --------- d-----w c:\program files\JumpStart World 2008-12-25 18:33 --------- d--h--w c:\program files\InstallShield Installation Information 2008-12-25 18:33 --------- d-----w c:\program files\Common Files\Knowledge Adventure 2008-07-03 18:41 47,360 ----a-w c:\documents and settings\Hollie\Application Data\pcouffin.sys 2008-07-03 18:11 87,608 ----a-w c:\documents and settings\Hollie\Application Data\ezpinst.exe 2007-10-15 09:37 774,144 ----a-w c:\program files\RngInterstitial.dll 2008-08-23 15:40 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082320080824\index.dat . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of c:\program files\Hide and Secret ---- 2009-02-15 23:54 988 --a------ c:\program files\Hide and Secret\userdata.xml 2009-02-15 23:54 1071 --a------ c:\program files\Hide and Secret\highscores.xml 2009-01-28 19:57 85542 --a------ c:\program files\Hide and Secret\uninstall.exe 2009-01-28 19:57 7575 --a------ c:\program files\Hide and Secret\uninstall.ini 2007-04-20 10:03 108773 --a------ c:\program files\Hide and Secret\logos.swf 2007-04-19 13:25 10461 --a------ c:\program files\Hide and Secret\eula.txt 2007-04-18 01:15 18581464 --a------ c:\program files\Hide and Secret\Hide-and-Secret.exe 2007-02-05 08:46 239170 --a------ c:\program files\Hide and Secret\data\comic23.swf 2007-02-05 08:46 160042 --a------ c:\program files\Hide and Secret\data\comic22.swf 2007-02-05 08:46 134727 --a------ c:\program files\Hide and Secret\data\comic21.swf 2007-02-05 08:45 160640 --a------ c:\program files\Hide and Secret\data\comic17.swf 2007-02-05 08:45 156421 --a------ c:\program files\Hide and Secret\data\comic16.swf 2007-02-05 08:45 139411 --a------ c:\program files\Hide and Secret\data\comic19.swf 2007-02-05 08:45 136207 --a------ c:\program files\Hide and Secret\data\comic20.swf 2007-02-05 08:44 196227 --a------ c:\program files\Hide and Secret\data\comic13.swf 2007-02-05 08:44 187057 --a------ c:\program files\Hide and Secret\data\comic12.swf 2007-02-05 08:44 163023 --a------ c:\program files\Hide and Secret\data\comic15.swf 2007-02-05 08:44 157321 --a------ c:\program files\Hide and Secret\data\comic11.swf 2007-02-05 08:44 136507 --a------ c:\program files\Hide and Secret\data\comic18.swf 2007-02-05 08:43 179964 --a------ c:\program files\Hide and Secret\data\comic14.swf 2007-02-05 08:43 172401 --a------ c:\program files\Hide and Secret\data\comic10.swf 2007-02-05 08:43 153707 --a------ c:\program files\Hide and Secret\data\comic09.swf 2007-02-05 08:42 165847 --a------ c:\program files\Hide and Secret\data\comic07.swf 2007-02-05 08:42 164414 --a------ c:\program files\Hide and Secret\data\comic06.swf 2007-02-05 08:42 163581 --a------ c:\program files\Hide and Secret\data\comic04.swf 2007-02-05 08:42 157816 --a------ c:\program files\Hide and Secret\data\comic05.swf 2007-02-05 08:42 111895 --a------ c:\program files\Hide and Secret\data\comic08.swf 2007-02-05 08:41 177331 --a------ c:\program files\Hide and Secret\data\comic03.swf 2007-02-05 08:41 145492 --a------ c:\program files\Hide and Secret\data\comic02.swf 2007-02-05 08:41 140311 --a------ c:\program files\Hide and Secret\data\comic01c.swf 2007-02-05 08:13 208197 --a------ c:\program files\Hide and Secret\data\comic01b.swf 2007-02-05 08:11 225916 --a------ c:\program files\Hide and Secret\data\comic01a.swf 2007-02-05 01:49 70942 --a------ c:\program files\Hide and Secret\things.xml 2007-02-04 04:43 5538 --a------ c:\program files\Hide and Secret\locations.xml 2007-02-03 18:45 271363 --a------ c:\program files\Hide and Secret\Music\HnS-Story01a-music-c-001.mp3 2007-02-03 09:13 103208 --a------ c:\program files\Hide and Secret\data\comic24.swf 2007-02-02 11:02 191898 --a------ c:\program files\Hide and Secret\Music\HnS-Story09-music-c-001.mp3 2007-02-01 22:15 357880 --a------ c:\program files\Hide and Secret\Music\map-screen.mp3 2007-02-01 22:11 87670 --a------ c:\program files\Hide and Secret\Music\level-complete.mp3 2007-02-01 22:09 356417 --a------ c:\program files\Hide and Secret\Music\track1.mp3 2007-02-01 21:55 1103519 --a------ c:\program files\Hide and Secret\Music\track5.mp3 2007-02-01 21:54 428933 --a------ c:\program files\Hide and Secret\Music\track2.mp3 2007-02-01 21:54 1708933 --a------ c:\program files\Hide and Secret\Music\track3.mp3 2007-02-01 21:54 1441021 --a------ c:\program files\Hide and Secret\Music\track4.mp3 2007-02-01 21:36 52561 --a------ c:\program files\Hide and Secret\Music\HnS-Story24-music-c-001.mp3 2007-02-01 21:36 122935 --a------ c:\program files\Hide and Secret\Music\HnS-Story23-music-c-001.mp3 2007-02-01 21:36 109142 --a------ c:\program files\Hide and Secret\Music\HnS-Story24-music-c-002.mp3 2007-02-01 21:32 85162 --a------ c:\program files\Hide and Secret\Music\HnS-Story22-music-c-001.mp3 2007-02-01 21:32 176538 --a------ c:\program files\Hide and Secret\Music\HnS-Story22-music-c-002.mp3 2007-02-01 21:29 126226 --a------ c:\program files\Hide and Secret\Music\HnS-Story21-music-c-001.mp3 2007-02-01 21:28 178419 --a------ c:\program files\Hide and Secret\Music\HnS-Story20-music-c-001.mp3 2007-02-01 21:27 81870 --a------ c:\program files\Hide and Secret\Music\HnS-Story19-music-c-002.mp3 2007-02-01 21:27 74974 --a------ c:\program files\Hide and Secret\Music\HnS-Story19-music-c-001.mp3 2007-02-01 21:25 182024 --a------ c:\program files\Hide and Secret\Music\HnS-Story18-music-c-001.mp3 2007-02-01 21:24 65570 --a------ c:\program files\Hide and Secret\Music\HnS-Story17-music-c-002.mp3 2007-02-01 21:24 100052 --a------ c:\program files\Hide and Secret\Music\HnS-Story17-music-c-001.mp3 2007-02-01 21:20 36104 --a------ c:\program files\Hide and Secret\Music\HnS-Story16-music-c-001.mp3 2007-02-01 21:20 142056 --a------ c:\program files\Hide and Secret\Music\HnS-Story16-music-c-002.mp3 2007-02-01 21:18 81087 --a------ c:\program files\Hide and Secret\Music\HnS-Story15-music-c-002.mp3 2007-02-01 21:18 46292 --a------ c:\program files\Hide and Secret\Music\HnS-Story15-music-c-003.mp3 2007-02-01 21:18 115568 --a------ c:\program files\Hide and Secret\Music\HnS-Story15-music-c-001.mp3 2007-02-01 21:14 74190 --a------ c:\program files\Hide and Secret\Music\HnS-Story14-music-c-003.mp3 2007-02-01 21:14 50367 --a------ c:\program files\Hide and Secret\Music\HnS-Story14-music-c-001.mp3 2007-02-01 21:14 140959 --a------ c:\program files\Hide and Secret\Music\HnS-Story14-music-c-002.mp3 2007-02-01 21:10 121838 --a------ c:\program files\Hide and Secret\Music\HnS-Story13-music-c-002.mp3 2007-02-01 21:10 115568 --a------ c:\program files\Hide and Secret\Music\HnS-Story13-music-c-001.mp3 2007-02-01 21:10 101776 --a------ c:\program files\Hide and Secret\Music\HnS-Story13-music-c-003.mp3 2007-02-01 21:08 59301 --a------ c:\program files\Hide and Secret\Music\HnS-Story12-music-c-001.mp3 2007-02-01 21:07 320734 --a------ c:\program files\Hide and Secret\Music\HnS-Story12-music-c-002.mp3 2007-02-01 21:04 62279 --a------ c:\program files\Hide and Secret\Music\HnS-Story11-music-c-002.mp3 2007-02-01 21:04 122621 --a------ c:\program files\Hide and Secret\Music\HnS-Story11-music-c-001.mp3 2007-02-01 21:02 126540 --a------ c:\program files\Hide and Secret\Music\HnS-Story10-music-c-001.mp3 2007-02-01 21:02 125129 --a------ c:\program files\Hide and Secret\Music\HnS-Story10-music-c-002.mp3 2007-02-01 20:58 142840 --a------ c:\program files\Hide and Secret\Music\HnS-Story08-music-c-001.mp3 2007-02-01 20:57 83438 --a------ c:\program files\Hide and Secret\Music\HnS-Story07-music-c-003.mp3 2007-02-01 20:57 76385 --a------ c:\program files\Hide and Secret\Music\HnS-Story07-music-c-002.mp3 2007-02-01 20:57 69959 --a------ c:\program files\Hide and Secret\Music\HnS-Story07-music-c-001.mp3 2007-02-01 20:55 88767 --a------ c:\program files\Hide and Secret\Music\HnS-Story06-music-c-001.mp3 2007-02-01 20:55 173403 --a------ c:\program files\Hide and Secret\Music\HnS-Story06-music-c-002.mp3 2007-02-01 20:51 59301 --a------ c:\program files\Hide and Secret\Music\HnS-Story04-music-c-001.mp3 2007-02-01 20:51 148012 --a------ c:\program files\Hide and Secret\Music\HnS-Story05-music-c-001.mp3 2007-02-01 20:51 122621 --a------ c:\program files\Hide and Secret\Music\HnS-Story04-music-c-002.mp3 2007-02-01 20:44 128421 --a------ c:\program files\Hide and Secret\Music\HnS-Story03-music-c-001.mp3 2007-02-01 20:43 182808 --a------ c:\program files\Hide and Secret\Music\HnS-Story02-music-c-001.mp3 2007-02-01 20:41 190017 --a------ c:\program files\Hide and Secret\Music\HnS-Story01c-music-c-001.mp3 2007-02-01 20:38 14097 --a------ c:\program files\Hide and Secret\Music\silence-5-seconds.mp3 2007-02-01 20:35 53188 --a------ c:\program files\Hide and Secret\Music\HnS-Story01b-music-c-001.mp3 2007-02-01 20:35 177008 --a------ c:\program files\Hide and Secret\Music\HnS-Story01b-music-c-002.mp3 2007-01-28 15:24 75566 --a------ c:\program files\Hide and Secret\HnS.ico 2007-01-25 15:40 9163 --a------ c:\program files\Hide and Secret\levels.xml 2007-01-23 05:22 218 --a------ c:\program files\Hide and Secret\digital Brandplay.url 2006-02-16 05:59 18902 --a------ c:\program files\Hide and Secret\anarchy.ico 2004-03-25 10:52 139 --a------ c:\program files\Hide and Secret\Anarchy Enterprises.url ------- Sigcheck ------- 2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys 2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys 2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys 2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\$NtServicePackUninstall$\tcpip.sys 2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys 2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys 2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys 2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys 2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS 2009-02-10 23:13 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\dllcache\TCPIP.SYS 2009-02-10 23:13 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\drivers\TCPIP.SYS . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048] "dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2005-12-05 691200] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] c:\documents and settings\Hollie\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] c:\documents and settings\All Users\Start Menu\Programs\Startup\ hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 147456] hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 28672] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Microsoft Games\\Mechwarrior Mercenaries\\MW4MERCS.ICD"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?] S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe --> c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [?] . Contents of the 'Scheduled Tasks' folder 2008-05-03 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1200736522.job - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 00:52] . . ------- Supplementary Scan ------- . mStart Page = hxxp://home.sweetim.com uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Download All by FlashGet IE: Download using FlashGet IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Hollie\Application Data\Mozilla\Firefox\Profiles\qwrgqpco.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13761&gct=&gc=1&q= FF - plugin: c:\documents and settings\Hollie\Application Data\Mozilla\Firefox\Profiles\qwrgqpco.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-21 23:14:47 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1757981266-1715567821-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ac,0a,68,5b,dc,ff,0a,96,bb,15,f9,53,7a,86,7e,cc,5d,7b,36,2b,43,a7,a8, 86,29,d0,35,5a,3f,2a,2b,8f,01,81,28,ab,d0,6a,17,dc,9b,40,b2,25,2c,24,0b,f5,\ "??"=hex:f3,f7,9f,fd,8d,d1,5d,22,47,69,7c,4b,79,0d,25,ce [HKEY_USERS\S-1-5-21-1757981266-1715567821-682003330-1003\Software\SecuROM\License information*] "datasecu"=hex:b7,2e,49,a1,d4,ba,61,6e,27,96,bb,58,ae,00,2e,0e,94,a7,d3,29,f7, 55,2b,d1,db,9b,eb,70,ca,d6,7c,17,52,7e,c1,55,ad,77,21,55,c6,3b,b0,51,6f,49,\ "rkeysecu"=hex:ba,ae,56,43,80,b0,98,e8,95,a5,5c,ec,d2,52,69,d2 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(736) c:\windows\system32\Ati2evxx.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\system32\drivers\CDAC11BA.EXE c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\wscntfy.exe c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe . ************************************************************************** . Completion time: 2009-02-21 23:17:05 - machine was rebooted ComboFix-quarantined-files.txt 2009-02-22 06:17:03 ComboFix2.txt 2009-02-22 02:23:35 Pre-Run: 9,011,130,368 bytes free Post-Run: 8,992,272,384 bytes free 292 --- E O F --- 2009-01-15 07:11:35 |
|
|
Feb 22 2009, 12:22 AM
Post
#7
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Here is Hijack log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:17:59 PM, on 2/21/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\dvd43\dvd43_tray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: hp psc 1000 series.lnk = ? O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v47/wwspades/wwspades.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\ O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- End of file - 7219 bytes Thanks for your help!!! much appreciated This post has been edited by BBJrDA: Feb 22 2009, 12:25 AM |
|
|
Feb 22 2009, 09:33 AM
Post
#8
|
|
![]() Trusted Helper Posts: 4,592 From: London, UK OS: XP |
looking better
in this post we will do some general scans to clear out the remnants and ensure nothing else sneaked onto your machine. we will also update your java. the scans will likely take 3 hours, quite possibly much longer. so just let them run. feel free to post the logs as they come - i will wait for the final log before proceeding. ====STEP 1==== we will need toi disable your TeaTimer for this part: Disable Teatimer First:
====STEP 2==== Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. ====STEP 3==== Please download ATF Cleaner by Atribune. Caution: This program is for Windows 2000, XP and Vista only
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu. ====STEP 4==== we will update and rerun your malwarebytes we will update and re-run your malwarebytes: double click the malwarebytes icon on your desktop to open the program
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. ====STEP 5==== Download and scan with SUPERAntiSpyware Free for Home Users
====STEP 6==== we will also update your java: Please download JavaRa to your desktop and unzip it to its own folder
====STEP 7==== Please do an online scan with Kaspersky WebScanner (this will identify any issues, we will clear them in the following post) Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.
Upgrading Java:
In your next reply could i see: 1. the malwarebytes log 2. the superantispyware log 3. the kaspersky log 4. some idea of how your machine is running now The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts. andrewuk |
|
|
Feb 23 2009, 03:20 AM
Post
#9
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Sorry it so long had to work today
MBAM Log Malwarebytes' Anti-Malware 1.34 Database version: 1792 Windows 5.1.2600 Service Pack 3 2/22/2009 10:29:20 AM mbam-log-2009-02-22 (10-29-20).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|) Objects scanned: 225116 Time elapsed: 46 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
Feb 23 2009, 03:21 AM
Post
#10
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
SUPERAntiSpyware Scan Log
http://www.superantispyware.com Generated 02/22/2009 at 10:59 AM Application Version : 4.25.1012 Core Rules Database Version : 3769 Trace Rules Database Version: 1729 Scan type : Complete Scan Total Scan Time : 00:25:28 Memory items scanned : 570 Memory threats detected : 0 Registry items scanned : 6627 Registry threats detected : 5 File items scanned : 24676 File threats detected : 4 Rogue.Component/Trace HKLM\Software\Microsoft\50C65FDA HKLM\Software\Microsoft\50C65FDA#50c65fda HKLM\Software\Microsoft\50C65FDA#Version HKLM\Software\Microsoft\50C65FDA#50c6f25a HKLM\Software\Microsoft\50C65FDA#50c69bbf Adware.Vundo/Variant-S129 C:\SYSTEM VOLUME INFORMATION\_RESTORE{263DC4CB-168D-41C9-A433-4A1769538FAB}\RP570\A0112502.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{263DC4CB-168D-41C9-A433-4A1769538FAB}\RP570\A0112505.DLL Adware.Vundo/Variant-PrintDlgA C:\SYSTEM VOLUME INFORMATION\_RESTORE{263DC4CB-168D-41C9-A433-4A1769538FAB}\RP570\A0112504.DLL Trojan.Agent/Gen-Keygen D:\CONVERTXTODVD V3.1.0.18-FINAL-(NEW-WITH SERIAL KEYS)\VSO CONVERTXTODVD V3.1.0.18\KEYMAKER\KEYGEN.EXE |
|
|
Feb 23 2009, 03:21 AM
Post
#11
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT Monday, February 23, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, February 23, 2009 06:42:42 Records in database: 1833498 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan statistics: Files scanned: 125934 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 02:01:52 File name / Threat name / Threats count C:\Documents and Settings\Hollie\Desktop\regtools.vbs Infected: not-a-virus:RiskTool.VBS.DisReg.a 1 |
|
|
Feb 23 2009, 03:23 AM
Post
#12
|
|
|
New Member ![]() Posts: 9 OS: windows xp |
Computer is running 100000000% times better... Thanks alot here is the Hijack log after all the scans..
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:22:06 AM, on 2/23/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: hp psc 1000 series.lnk = ? O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v47/wwspades/wwspades.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\ O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- End of file - 8036 bytes |
|
|
Feb 23 2009, 01:51 PM
Post
#13
|
|
![]() Trusted Helper Posts: 4,592 From: London, UK OS: XP |
Hello BBJrDA
congratulations, your logs are clean and another fix is in the can weldone on putting avast on your machine, you need an antivirus program in this post we will clear away the fix tools (this is so that should you ever be re-infected, you will download updated versions and it will also remove the quarantined Malware from your computer), reset your restore points (there will be infections lurking in there) and i will leave you with some ideas on how to enhance the protection of your machine against future infection. ====STEP 1==== Follow these steps to uninstall Combofix, the tools used in the removal of malware and to flush your system restore points
====STEP 2==== Please download the OTCleanIt by OldTimer.
====IDEAS TO SPEED UP YOUR MACHINE==== this page http://users.telenet.be/bluepatchy/miekiem...owcomputer.html gives some good ideas on how to improve the efficiency of your machine and has one or two useful links to help you further. ====AND FINALLY==== The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein best wishes andrewuk |
|
|
Mar 1 2009, 04:14 PM
Post
#14
|
|
![]() Trusted Helper Posts: 4,592 From: London, UK OS: XP |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
13 / 1,435 | 28th October 2008 - 12:34 PM miket5567 started - last by Essexboy |
|||||
![]() |
0 / 62 | 3rd February 2009 - 05:36 PM lisabel started - last by lisabel |
|||||
![]() |
12 / 581 | 25th February 2009 - 04:01 PM kewleb started - last by Rorschach112 |
|||||
![]() |
2 / 82 | 3rd November 2009 - 11:29 AM mkdons4eva started - last by andrewuk |
|||||
|
Time is now: 20th November 2009 - 11:49 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising