Please Help! .."Warning! Potential Spyware Operation!, hijackthis.log, ComboFix log.txt and the Uninstall Manager (uninstall_ |
![]() ![]() |
Please Help! .."Warning! Potential Spyware Operation!, hijackthis.log, ComboFix log.txt and the Uninstall Manager (uninstall_ |
Dec 24 2007, 04:10 AM
Post
#1
|
|
|
New Member ![]() Posts: 1 OS: XP Professional |
Hi.. My PC keeps giving me a pop-up saying
Warning! Potential spyware operation! Your computer is making unorthorized copies of your system and internet files. Run full scan to prevent any unorthorised access to your files! Click yes to download spyware remover... I click "no" and it keeps popping up every few minutes or so. When I click "yes" it tries to open the site gomyjit.com SYMPTOMS: no access to the control panel and the task manager, The Norton Antivirus CANNOT be started, UNABLE to browse the internet evn though my DSL line is connected (checked by pinging different sites) I went thru previous posts and have tried SmitfraudFix, ComboFix, ATF-Cleaner.exe both in SAFE mode and NORMAL mode. So far i have been unsuccessful. Even tried re-installing norton but it does not OPEN after installation. The LATEST logfiles are pasted below: FOR HiJackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:06:13 AM, on 12/25/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam10\QuickCam10.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\CASIO\Photo Loader\Plauto.exe C:\Program Files\Citrix\ICA Client\pnagent.exe C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing) O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll (file missing) O2 - BHO: 0 - {5252F0C8-81C1-4CFF-70A1-A5683A1D472D} - C:\Program Files\ComPlus Applications\zysi.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [GhostSurf Reminder] "C:\Program Files\GhostSurf 2005\Privacy Control Center.exe" reminder O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Medichi] medichi.exe O4 - HKLM\..\Run: [Medichi2] medichi2.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT" O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - Startup: Scheduler.lnk = C:\Program Files\GhostSurf 2005\Scheduler daemon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe O4 - Global Startup: Program Neighborhood Agent.lnk = ? O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: English<->Polish - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Polish) for Windows\Plugins\IE.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: English<->Polish - {F12BFB07-328B-1E4B-96DF-FBB732B3B36D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Polish) for Windows\Plugins\IE.htm O9 - Extra 'Tools' menuitem: English<->Polish - {F12BFB07-328B-1E4B-96DF-FBB732B3B36D} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Polish) for Windows\Plugins\IE.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://download.windowsupdate.com O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1146302350468 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe -- End of file - 10942 bytes HiJackThis Uninstall Manager: ACDSee 4.0 ACDSee 7.0 Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Reader 7.0.9 Adobe Shockwave Player Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver Call of Duty - United Offensive CC_ccProxyExt ccCommon ccPxyCore Citrix Presentation Server Client Citrix Web Client Google Earth High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Intel® PRO Network Adapters and Drivers iPod for Windows 2005-10-12 iPod for Windows 2006-03-23 iTunes J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 3 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 9 Java 6 Update 2 Java 6 Update 3 Java SE Runtime Environment 6 Update 1 LingvoSoft Suite 2007 English<->Polish for Windows LiveReg (Symantec Corporation) LiveUpdate 2.5 (Symantec Corporation) Logitech Audio Echo Cancellation Component Logitech QuickCam Logitech Video Enumerator Logitech® Camera Driver Macromedia Shockwave Player Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft PowerPoint Viewer 97 Microsoft User-Mode Driver Framework Feature Pack 1.0 MSN MSRedist MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MVision Nero Suite Norton AntiSpam Norton AntiSpam Norton AntiVirus 2005 Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security 2005 (Symantec Corporation) Norton WMI Update Norton WMI Update OIN Partner Phrasebook for Pocket PC (English to Polish) Photo Loader 2.1E Power2Go 4.0 PowerCinema 3.0 QuickTime Realtek High Definition Audio Driver Rugby Challenge 2006 Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Smart Menus (Windows Live Toolbar) SPBBC Splinter Cell Pandora Tomorrow SweetIM For Internet Explorer 3.0b Symantec Script Blocking Installer SymNet The Sims 2 The Sims™ 2 Seasons Trust WB-1400T Webcam Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live Messenger Windows Live Sign-in Assistant Windows Live Toolbar Windows Live Toolbar Windows Live Toolbar Extension (Windows Live Toolbar) Windows Live Toolbar Feed Detector (Windows Live Toolbar) Windows Live Toolbar Feed Detector (Windows Live Toolbar) Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 XMLinst Yahoo! Install Manager Yahoo! Search Protection For ComboFix: ComboFix 07-12-24.7 - user 2007-12-25 3:09:25.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.615 [GMT 4:00] Running from: C:\Documents and Settings\user\Desktop\Spyware Removal\yyyy.exe . ((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 ))))))))))))))))))))))))))))))) . 2007-12-25 03:05 . 2007-12-25 03:05 <DIR> d-------- C:\Program Files\Trend Micro 2007-12-25 03:01 . 2007-12-25 03:01 <DIR> d-------- C:\WINDOWS\LastGood 2007-12-25 01:21 . 2007-12-25 01:23 <DIR> d-------- C:\Program Files\Norton Internet Security 2007-12-25 01:20 . 2007-12-25 01:22 <DIR> d-------- C:\Program Files\Symantec 2007-12-25 01:20 . 2004-08-26 14:03 104,144 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-12-25 01:20 . 2004-08-26 14:03 83,168 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-12-25 01:19 . 2007-12-25 01:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec 2007-12-25 01:13 . 2007-12-25 01:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2007-12-24 05:29 . 2007-12-25 02:05 4,266 --a------ C:\WINDOWS\system32\tmp.reg 2007-12-24 05:28 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe 2007-12-24 05:28 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-12-24 03:56 . 2007-12-24 03:56 <DIR> d-------- C:\Program Files\RegCure 2007-12-22 23:15 . 2007-12-22 23:15 0 --a------ C:\WINDOWS\wsystmp_ozf.exe 2007-12-22 15:36 . 2007-12-22 15:36 0 --a------ C:\WINDOWS\wsystmp_nkq.exe 2007-12-22 15:32 . 2007-12-25 02:56 6,144 --a------ C:\WINDOWS\system32\user32.dat 2007-12-22 15:27 . 2007-12-25 02:54 8,192 --a------ C:\WINDOWS\medichi2.exe 2007-12-22 15:27 . 2007-12-25 02:54 5,632 --a------ C:\WINDOWS\medichi.exe 2007-12-22 15:26 . 2007-12-22 15:26 35,840 --a------ C:\WINDOWS\wsystmp_gof.exe 2007-12-22 09:30 . 2007-12-22 09:30 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Symantec 2007-12-09 18:16 . 2007-12-24 03:56 <DIR> d-------- C:\Program Files\a-squared Anti-Malware 2007-12-09 15:06 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2007-12-09 15:06 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-12-09 15:06 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-12-09 15:06 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2007-12-09 14:58 . 2007-12-24 03:55 <DIR> d-------- C:\Program Files\RogueRemover FREE 2007-12-09 13:18 . 2007-12-09 13:18 <DIR> d-------- C:\Program Files\ECTACO 2007-12-09 13:04 . 2007-12-09 15:54 <DIR> d-------- C:\Program Files\XoftSpySE 2007-12-09 10:56 . 2007-12-09 13:17 <DIR> d-------- C:\Program Files\ErrorSmart 2007-12-09 10:56 . 2007-12-09 13:17 <DIR> d-------- C:\Documents and Settings\user\Application Data\ErrorSmart 2007-12-07 16:20 . 2007-12-09 13:19 <DIR> d-------- C:\Program Files\Spyware Doctor 2007-12-07 13:56 . 2007-12-07 16:41 <DIR> d-------- C:\WINDOWS\system32\NtmsData 2007-12-07 13:34 . 2007-12-07 13:34 196,608 --a------ C:\WINDOWS\system32\AcroIEHelper.dll 2007-12-07 12:57 . 2007-12-07 12:57 0 --a------ C:\WINDOWS\wsystmp_yur.exe 2007-12-07 12:11 . 2007-12-07 12:11 11,776 --a------ C:\WINDOWS\wsystmp_wlp.exe 2007-12-07 12:05 . 2007-12-07 12:05 0 --a------ C:\WINDOWS\wsystmp_pwy.exe 2007-12-07 11:46 . 2007-12-07 11:46 30,583 --a------ C:\WINDOWS\wsystmp_swq.exe 2007-12-04 01:44 . 2007-12-04 01:44 2,852 --a------ C:\WINDOWS\system32\AcroIEHelper.xml . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-24 22:54 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs 2007-12-24 21:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-12-24 21:21 10,344 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys 2007-12-24 00:07 --------- d-----w C:\Program Files\Yahoo! 2007-12-24 00:07 --------- d-----w C:\Program Files\Transparent 2007-12-24 00:07 --------- d-----w C:\Program Files\Karting 2007-12-24 00:07 --------- d-----w C:\Program Files\Formula Challenge 2007-12-24 00:07 --------- d-----w C:\Program Files\Call of Duty 2007-12-22 11:26 37,888 ----a-w C:\WINDOWS\system32\drivers\beep.sys 2007-12-11 10:04 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-12-09 15:58 --------- d-----w C:\Program Files\Macrogaming 2007-12-07 12:20 --------- d-----w C:\Program Files\Google 2007-11-30 08:39 --------- d-----w C:\Program Files\Windows Live Toolbar 2007-11-18 18:44 --------- d-----w C:\Documents and Settings\user\Application Data\U3 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-12 12:26 --------- d-----w C:\Program Files\EA GAMES 2007-11-12 08:24 --------- d-----w C:\Program Files\iTunes 2007-11-12 08:24 --------- d-----w C:\Program Files\iPod 2007-11-12 08:23 --------- d-----w C:\Program Files\QuickTime 2007-11-04 02:38 221,184 ----a-w C:\WINDOWS\system32\UAService7.exe 2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-29 04:49 --------- d-----w C:\Program Files\Java 2007-10-27 13:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-09-27 12:47 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-06-01 17:55 22 ----a-w C:\Program Files\zia03232 2007-06-01 17:55 22 ----a-w C:\Program Files\c.zip 2007-06-01 17:55 22 ----a-w C:\Program Files\b.zip 2007-06-01 17:55 22 ----a-w C:\Program Files\a.zip 2007-06-01 08:15 25,214 ----a-w C:\Program Files\B.ico 2007-06-01 08:15 25,214 ----a-w C:\Program Files\A.ico 2007-03-31 11:12 201 ----a-w C:\Documents and Settings\user\q.bat 2007-03-14 19:11 114 ----a-w C:\Documents and Settings\user\hhjj.bat 2007-03-08 09:11 75 ----a-w C:\Documents and Settings\user\n.bat 2007-03-08 09:11 63 ----a-w C:\Documents and Settings\user\yyd.bat 2007-03-08 09:11 1,641 ----a-w C:\Documents and Settings\user\x.dat 2007-02-11 08:10 190 ----a-w C:\Documents and Settings\user\ggg.bat . ((((((((((((((((((((((((((((( snapshot@2007-12-25_ 1.53.17.89 ))))))))))))))))))))))))))))))))))))))))) . + 2007-03-06 01:22:34 22,752 -c----w C:\WINDOWS\$NtUninstallKB942763$\spcustom.dll + 2007-03-06 01:22:36 14,048 -c----w C:\WINDOWS\$NtUninstallKB942763$\spmsg.dll + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst.exe + 2007-03-06 01:22:59 716,000 -c----w C:\WINDOWS\$NtUninstallKB942763$\update.exe + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB942763$\updspapi.dll + 2007-03-06 01:22:34 22,752 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spcustom.dll + 2007-03-06 01:22:36 14,048 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spmsg.dll + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst.exe + 2007-03-06 01:22:59 716,000 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\update.exe + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\updspapi.dll - 2007-12-12 06:29:00 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe + 2007-12-24 23:02:28 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe - 2007-12-12 06:29:00 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2007-12-24 23:02:28 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2007-12-12 06:29:00 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe + 2007-12-24 23:02:28 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe - 2007-12-12 06:29:00 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe + 2007-12-24 23:02:28 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe - 2007-12-12 06:29:00 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2007-12-24 23:02:28 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2007-12-12 06:29:00 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2007-12-24 23:02:28 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2007-12-12 06:29:00 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2007-12-24 23:02:28 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2007-12-12 06:29:00 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2007-12-24 23:02:28 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe - 2007-12-12 06:29:00 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe + 2007-12-24 23:02:28 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2007-12-12 06:29:00 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2007-12-24 23:02:28 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2007-12-12 06:29:00 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2007-12-24 23:02:28 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2007-12-12 06:29:00 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2007-12-24 23:02:28 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe - 2007-12-12 06:29:00 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe + 2007-12-24 23:02:27 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}] C:\Program Files\NewDotNet\newdotnet7_48.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5252F0C8-81C1-4CFF-70A1-A5683A1D472D}] C:\Program Files\ComPlus Applications\zysi.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Power2GoExpress"="" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:00] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 18:59] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-08-12 11:02] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50] "High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 15:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe] "SoundMan"="SOUNDMAN.EXE" [2004-06-17 20:12 C:\WINDOWS\SOUNDMAN.EXE] "AlcWzrd"="ALCWZRD.EXE" [2004-06-17 19:43 C:\WINDOWS\ALCWZRD.EXE] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 21:10] "PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" [2004-11-03 16:53] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "GhostSurf Reminder"="C:\Program Files\GhostSurf 2005\Privacy Control Center.exe" [] "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2006-12-22 12:27] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-12-22 12:28] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 18:59] "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-08-12 11:02] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36] "Medichi"="medichi.exe" [2007-12-25 02:54 C:\WINDOWS\medichi.exe] "Medichi2"="medichi2.exe" [2007-12-25 02:54 C:\WINDOWS\medichi2.exe] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 13:25] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 23:22] "IS CfgWiz"="C:\Program Files\Norton Internet Security\cfgwiz.exe" [2004-08-17 22:36] "URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-08-31 02:29] "SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-08-05 17:23] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26] Photo Loader supervisory.lnk - C:\Program Files\CASIO\Photo Loader\Plauto.exe [2006-10-04 17:43:31] Program Neighborhood Agent.lnk - C:\WINDOWS\Installer\{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}\Icon80951CEC.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe [2007-10-05 12:59:28] R0 DiMaint;Eicon Maintenance Driver;C:\WINDOWS\system32\DRIVERS\DISDN\dimaint.sys [2001-08-17 12:13] R2 DiCapi;Eicon CAPI 2.0 Driver;C:\WINDOWS\system32\DRIVERS\DISDN\capi20.sys [2001-08-17 12:13] S3 DiWan;Eicon Driver for all DIVA PnP cards;C:\WINDOWS\system32\DRIVERS\DISDN\Diwan.sys [2001-08-17 12:14] S3 sony_ssm.sys;sony_ssm.sys;C:\DOCUME~1\user\LOCALS~1\Temp\sony_ssm.sys [] S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2004-06-24 15:54] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I] \Shell\AutoRun\command - I:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder "2007-12-10 07:36:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-12-24 22:24:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job" - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE "2007-12-23 23:30:00 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job" - C:\Program Files\ErrorSmart\ErrorSmart.ex - C:\Program Files\ErrorSmart "2007-12-24 21:23:29 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE "2007-12-24 21:16:20 C:\WINDOWS\Tasks\XoftSpySE 2.job" - C:\Program Files\XoftSpySE\XoftSpy.exe "2007-12-24 23:00:00 C:\WINDOWS\Tasks\XoftSpySE.job" - C:\Program Files\XoftSpySE\XoftSpy.exe . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-25 03:11:03 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-25 3:11:36 . 2007-12-24 23:02:30 --- E O F --- I REALLY REALLY WOULD APPRECIATE ANY HELP THAT I CAN GET !!! :-( Please do let me know if you need any more additional information. thanks, dxbdude |
|
|
Dec 27 2007, 12:29 PM
Post
#2
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Hello and welcome dxbdude
Sorry for the delay Please download Deckard's System Scanner (DSS) and save it to your Desktop.
Also Please do an online scan with Kaspersky WebScanner Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
Post back all the requested logs and we will go from there If you have since resolved this issue could you let me know please so we can close the topic it would be appreciated |
|
|
Jan 4 2008, 01:36 PM
Post
#3
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
29 / 8,889 | 27th May 2005 - 07:38 PM thejenny100 started - last by don77 |
|||||
![]() |
16 / 1,036 | 12th April 2008 - 10:33 PM coolcricket started - last by kahdah |
|||||
![]() |
17 / 3,685 | 6th January 2008 - 06:52 PM Stomp1 started - last by kahdah |
|||||
![]() |
0 / 515 | 23rd November 2007 - 01:27 AM andre123 started - last by andre123 |
|||||
|
Time is now: 7th November 2009 - 08:18 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising