popups and windows error messages when starting computer, popups and error messages |
![]() ![]() |
popups and windows error messages when starting computer, popups and error messages |
Jul 11 2007, 06:01 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 21 OS: xp |
Scan saved at 7:46:05 PM, on 7/11/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16441) getting popups when IE is running and some when it is not running. ran norton, spyware scan, adaware and AVG. AVG got rid of alot however computer is still running slow and when starting the computer now getting error messages from logitech and from error loading C:\windows\system32\j7291038.dll module can't be found. i have already ran avg in safe mode and created a system restore point and now to top it off under display i can't click on any background pictures it will let me put my own picture on the background but none of the windows pictures will let me click on them i can only click on the color. please help Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {13BAA56A-9570-AC65-EA8E-EDE19CE7FD52} - (no file) O2 - BHO: Class - {143B9440-CA24-BED6-D9CD-08CC6A984764} - C:\WINDOWS\system32\ieys32.dll (file missing) O2 - BHO: Class - {15FEC491-F0D8-A206-B818-8D1D3FEDF979} - C:\WINDOWS\system32\sysjt32.dll (file missing) O2 - BHO: Class - {2AB80E5C-C6A3-016D-788D-E1F289A65E42} - C:\WINDOWS\winag32.dll (file missing) O2 - BHO: (no name) - {2AD27B78-A144-13BF-3CFD-8C2B118FCB77} - (no file) O2 - BHO: Class - {2C0087A1-5D6B-3765-B30B-8A302FBA4596} - C:\WINDOWS\addzb.dll (file missing) O2 - BHO: Class - {3AE414DC-B2A7-0DAD-989F-AC39ADF529E6} - C:\WINDOWS\system32\crie32.dll (file missing) O2 - BHO: Class - {3E7061C4-43FC-71F4-46DC-05A0D8524F6C} - C:\WINDOWS\system32\appms.dll (file missing) O2 - BHO: Class - {4B1C5C48-BA9D-4905-65D8-B9E278BF991D} - C:\WINDOWS\system32\mspc.dll (file missing) O2 - BHO: Class - {4CD05B77-C677-4D01-5562-25BA68012376} - C:\WINDOWS\apict.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Class - {563AC50A-6D00-C342-5EC7-D1C5C40E2122} - C:\WINDOWS\system32\msef32.dll (file missing) O2 - BHO: Class - {5DAA3B7C-6DEC-B6D5-9597-81AFF0B315AA} - C:\WINDOWS\system32\mfcme.dll (file missing) O2 - BHO: Class - {63AEC6B0-2656-D7C1-9D55-6B66F78A3D1A} - C:\WINDOWS\system32\iewo.dll (file missing) O2 - BHO: Class - {69B41F32-4AC6-1E89-433B-C41C1477D07C} - C:\WINDOWS\msiv32.dll (file missing) O2 - BHO: Class - {83241F15-A38D-4603-9874-0E32E3A2D544} - C:\WINDOWS\ntrl.dll (file missing) O2 - BHO: Class - {8A8EABA7-19AA-BB2B-F288-8E8741D4A2E0} - C:\WINDOWS\ntpn32.dll (file missing) O2 - BHO: Class - {8F69ADF9-A5DE-30DA-0B84-99655E5A16A4} - C:\WINDOWS\nettl.dll (file missing) O2 - BHO: Class - {96316EB2-0E4E-6A7E-7A88-DD575904EDB4} - C:\WINDOWS\ieqp32.dll (file missing) O2 - BHO: Class - {9FBCDEFF-A6FC-C42E-2DA5-84537095BAA5} - C:\WINDOWS\system32\appon32.dll (file missing) O2 - BHO: Class - {A1A0A8B0-1426-AEE6-1AF3-A0AEC3BAA6FA} - C:\WINDOWS\appvt.dll (file missing) O2 - BHO: Class - {A3D347B5-8D22-1E55-4D3E-C94C91F76762} - C:\WINDOWS\apikr32.dll (file missing) O2 - BHO: Class - {A5C17366-4766-30CF-5AD1-138CC5B3E64A} - C:\WINDOWS\crkv.dll (file missing) O2 - BHO: Class - {B8A40086-20B8-C1F2-809A-00534310B657} - C:\WINDOWS\system32\apprw.dll (file missing) O2 - BHO: Class - {C054F454-DB2C-0434-31BF-C3C717973C71} - C:\WINDOWS\system32\d3ve.dll (file missing) O2 - BHO: (no name) - {c29ffbe7-9286-40b8-8121-cf9475315eba} - C:\WINDOWS\system32\dsqops.dll (file missing) O2 - BHO: Class - {CC492B23-D765-1168-B1BB-2E0624A5E876} - C:\WINDOWS\appvz32.dll (file missing) O2 - BHO: Class - {DCB7AA47-29E8-5669-EB30-7BCD8254F742} - C:\WINDOWS\ipqy.dll (file missing) O2 - BHO: Class - {DECD8E91-E600-DF80-A5DB-061BB58F74D4} - C:\WINDOWS\ieyf.dll (file missing) O2 - BHO: Class - {EBA74261-7CAA-F270-26F4-4E2A669761D1} - C:\WINDOWS\ntne.dll (file missing) O2 - BHO: Class - {F05E944D-A6BE-48F3-A206-5BFEB880123F} - C:\WINDOWS\system32\sysew.dll (file missing) O4 - HKLM\..\Run: [winmu32.exe] C:\WINDOWS\winmu32.exe O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf O4 - HKLM\..\Run: [LanManNTR] C:\Documents and Settings\Owner\Desktop\aff_test_morton.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [j7291038] rundll32 C:\WINDOWS\system32\j7291038.dll sook O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll (file missing) O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://financeworks.mathxl.com/wizmodules/...GenXInstall.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://financeworks.mathxl.com/applets/Pea...InstallAsst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab O16 - DPF: {F8B8AF16-CECF-4002-9CC0-1E18029D7770} (FWPlayer Control) - http://financeworks.mathxl.com/applets/FWPlayer.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: mssms - {554A0D4D-FE36-4A33-8526-172CDC545691} - C:\WINDOWS\mssms.dll (file missing) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qwerty12.exe (file missing) O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing) O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing) O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing) O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe This post has been edited by jessliv82: Jul 11 2007, 06:05 PM
Attached File(s)
|
|
|
Jul 12 2007, 07:23 AM
Post
#2
|
|
|
Visiting Staff Posts: 313 From: BC, Canada OS: Xp |
Hi, welcome to G2G!
You have a brood of infections there.. Click start > control panel > add/remove programs.. The following is an optional removal.. Logitech® Desktop Messenger (LDM) is a free service designed to deliver software support, news and information you can use. LDM ensures that you have simple, speedy, and effortless access to product upgrades, technology tips, and technology news and offers that are relevant to you. LDM delivers information right to your desktop, allowing you to take advantage of all of the advanced features of the Logitech products you own, while staying abreast of new computer-related product and service developments (Logitech and otherwise) that are applicable to your life. Once a week, when connected to the internet, Logitech Desktop Messenger will automatically connect with Logitech servers to see if there are any new messages for you. It performs this check during idle time to avoid slowing down other applications that may be accessing the Internet. If there is a message on the server, then Logitech Desktop Messenger will download the message utilizing bandwidth that would otherwise be unused. After the message is downloaded, Logitech Desktop Messenger will wait for one minute of keyboard and mouse inactivity before displaying the message on your screen. I suggest doing all updates yourself and removing this application. _________ Download combofix.exe 1. Save it to your desktop. 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply along with a fresh HijackThis log. Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall. _________ Please download FindAWF: http://noahdfear.net/downloads/FindAWF.exe Save the file to the Desktop Double-click the FindAWF icon. If a Security Alert shows, allow the program to run. As instructed, press any key to continue. Use the following option: Press 1 then Enter to scan for bak folders The scan may take a while, please be patient. When done, a text file, Find AWF report is produced. Please provide Find AWF report in your reply. If by any chance you lose the report produced, click Start>Run, type %temp%\findawf\awf.txt. It will open the report again. |
|
|
Jul 12 2007, 04:29 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 21 OS: xp |
thank you so much for responding so quickly I got all three reports they are below trying to do the best I can don't understand computers much thanks for the directions. I can't understand how all of this is getting on my computer. I am not sure about deleting the logitech because that is what my mouse is and I don't want it to stop working will removing that program cause any problems looking forward to fixing the rest .
Thanks Jessica okay ran combo fix here is the report "Owner" - 2007-07-12 17:54:26 - ComboFix 07-07-13 - Service Pack 2 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\Owner\APPLIC~1.\.rdr.ini C:\DOCUME~1\Owner\Desktop.\internet explorer.lnk C:\DOCUME~1\Owner\Desktop\internet.lnk C:\temp\tn3 C:\WINDOWS\cs_cache.ini C:\WINDOWS\search_res.txt C:\WINDOWS\system32\tmp3F.tmp.dll C:\WINDOWS\wr.txt ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_CORE -------\LEGACY_DOMAINSERVICE -------\LEGACY_NET_AGENT -------\LEGACY_NWSAPAGENT -------\core -------\DomainService -------\Net Agent -------\NwSapAgent ((((((((((((((((((((((((( Files Created from 2007-06-12 to 2007-07-12 ))))))))))))))))))))))))))))))) 2007-07-12 17:52 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-11 00:31 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-07-11 00:16 <DIR> d-------- C:\HJT 2007-07-10 23:27 <DIR> d-------- C:\VundoFix Backups 2007-07-06 20:51 <DIR> d-------- C:\Program Files\Riverdeep 2007-07-06 20:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Riverdeep 2007-07-05 14:00 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\The Learning Company 2007-07-05 13:39 274,432 --a------ C:\WINDOWS\TLCUninstall.exe 2007-07-05 13:39 <DIR> d-------- C:\Program Files\The Learning Company 2007-07-05 13:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\The Learning Company 2007-07-04 23:32 86,016 --a------ C:\WINDOWS\unvise32.exe 2007-07-04 23:32 <DIR> d-------- C:\Program Files\Edmark 2007-07-04 23:24 <DIR> d-------- C:\Program Files\brighter child 2007-07-04 23:15 69,632 --a------ C:\WINDOWS\system32\Clifford Uninstall.exe 2007-07-04 23:15 <DIR> d-------- C:\Program Files\Scholastic's Clifford 2007-07-02 21:19 2,621,442 --a------ C:\SYM_REGISTRY_BACKUP.reg 2007-06-17 20:25 <DIR> d-------- C:\WINDOWS\CWONDERS 2007-06-17 20:24 92,208 --a------ C:\WINDOWS\system\WING.DLL 2007-06-17 20:24 26,768 --a------ C:\WINDOWS\system\CTL3D.DLL 2007-06-17 20:24 243,680 --a------ C:\WINDOWS\UNINST16.EXE 2007-06-17 20:24 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL 2007-06-17 20:24 12,800 --a------ C:\WINDOWS\system32\WING32.DLL 2007-06-17 20:24 <DIR> d-------- C:\CWONDERS 2007-06-16 12:52 <DIR> d-------- C:\WINDOWS\system32\pmcubosf 2007-06-13 22:13 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys 2007-06-13 21:32 <DIR> d-------- C:\Program Files\Enigma Software Group 2007-06-13 20:49 <DIR> d-------- C:\WINDOWS\Spyware Slayer Settings 2007-06-13 15:03 238,790 --a------ C:\DOCUME~1\Owner\APPLIC~1\ZBScreenSaver_1.scr 2007-06-13 15:02 238,790 --a------ C:\DOCUME~1\Owner\APPLIC~1\ZBScreenSaver.scr 2007-06-13 15:00 238,790 --a------ C:\WINDOWS\system32\ZBScreenSaver_1.scr 2007-06-13 14:59 238,790 --a------ C:\WINDOWS\system32\ZBScreenSaver.scr 2007-06-12 22:00 <DIR> d-------- C:\Program Files\Common Files\ODBC (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-10 00:36:07 -------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-07-03 03:37:49 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\MSNInstaller 2007-06-28 18:35:47 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Corel 2007-06-28 02:25:48 -------- d-----w C:\Program Files\iTunes 2007-06-27 17:38:47 -------- d-----w C:\Program Files\EPSON Print CD 2007-06-14 02:00:33 -------- d-----w C:\Program Files\Common Files\Scanner 2007-06-12 07:27:05 1,809,075 --sh--w C:\WINDOWS\system32\ccbeg.ini2 2007-06-12 03:39:58 1,809,783 --sha-w C:\WINDOWS\system32\ccbeg.bak2 2007-06-12 02:57:27 -------- d-----w C:\Program Files\Norton AntiVirus 2007-06-12 02:28:22 -------- d-----w C:\Program Files\Symantec 2007-06-12 02:28:21 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-06-12 02:28:21 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-06-12 02:28:21 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL 2007-06-12 02:28:21 115,000 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-06-12 02:04:06 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\MSN6 2007-06-12 02:02:52 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\COMCASTTOOLBAR 2007-06-12 00:27:47 1,810,072 --sha-w C:\WINDOWS\system32\ccbeg.bak1 2007-06-06 02:25:40 444 ----a-w C:\WINDOWS\system32\d3d8caps.dat 2007-06-06 02:06:13 -------- d-----w C:\Program Files\Yahoo! Games 2007-06-06 01:56:44 -------- d--h--w C:\Program Files\InstallShield Installation Information 2007-06-06 01:56:19 -------- d-----w C:\Program Files\Common Files\ISPCOMP 2007-06-06 01:17:51 10 ----a-w C:\WINDOWS\popcinfo.dat 2007-06-05 02:08:51 -------- d-----w C:\Program Files\MUSICMATCH 2007-06-03 17:26:46 -------- d-----w C:\Program Files\QuickTime 2007-06-02 03:13:31 -------- d-----w C:\Program Files\Windows NT 2007-06-02 02:33:25 -------- d-----w C:\Program Files\Yahoo! 2007-06-02 02:32:59 -------- d-----w C:\Program Files\Spyware Slayer 2007-05-31 03:51:12 -------- d-----w C:\Program Files\Lavasoft 2007-05-31 03:50:16 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-05-31 03:32:43 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Lavasoft 2007-05-30 12:24:11 14 ----a-w C:\WINDOWS\bstdin.bin 2007-05-30 03:18:11 -------- d-----w C:\Program Files\Support.com 2007-05-30 03:17:51 -------- d-----w C:\Program Files\Messenger 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2006-12-25 20:27:59 36,808,256 ----a-w C:\Program Files\iTunesSetup.exe 2006-01-21 02:30:16 4,048,984 ----a-w C:\Program Files\LimeWireWin.exe 2005-10-10 20:54:00 46,672 ----a-w C:\DOCUME~1\Owner\APPLIC~1\GDIPFONTCACHEV1.DAT ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2004-12-14 01:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13BAA56A-9570-AC65-EA8E-EDE19CE7FD52}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{143B9440-CA24-BED6-D9CD-08CC6A984764}] C:\WINDOWS\system32\ieys32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15FEC491-F0D8-A206-B818-8D1D3FEDF979}] C:\WINDOWS\system32\sysjt32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AB80E5C-C6A3-016D-788D-E1F289A65E42}] C:\WINDOWS\winag32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AD27B78-A144-13BF-3CFD-8C2B118FCB77}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C0087A1-5D6B-3765-B30B-8A302FBA4596}] C:\WINDOWS\addzb.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AE414DC-B2A7-0DAD-989F-AC39ADF529E6}] C:\WINDOWS\system32\crie32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E7061C4-43FC-71F4-46DC-05A0D8524F6C}] C:\WINDOWS\system32\appms.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4B1C5C48-BA9D-4905-65D8-B9E278BF991D}] C:\WINDOWS\system32\mspc.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CD05B77-C677-4D01-5562-25BA68012376}] C:\WINDOWS\apict.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] 2005-05-31 01:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{563AC50A-6D00-C342-5EC7-D1C5C40E2122}] C:\WINDOWS\system32\msef32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DAA3B7C-6DEC-B6D5-9597-81AFF0B315AA}] C:\WINDOWS\system32\mfcme.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63AEC6B0-2656-D7C1-9D55-6B66F78A3D1A}] C:\WINDOWS\system32\iewo.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69B41F32-4AC6-1E89-433B-C41C1477D07C}] C:\WINDOWS\msiv32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83241F15-A38D-4603-9874-0E32E3A2D544}] C:\WINDOWS\ntrl.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A8EABA7-19AA-BB2B-F288-8E8741D4A2E0}] C:\WINDOWS\ntpn32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F69ADF9-A5DE-30DA-0B84-99655E5A16A4}] C:\WINDOWS\nettl.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96316EB2-0E4E-6A7E-7A88-DD575904EDB4}] C:\WINDOWS\ieqp32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9FBCDEFF-A6FC-C42E-2DA5-84537095BAA5}] C:\WINDOWS\system32\appon32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1A0A8B0-1426-AEE6-1AF3-A0AEC3BAA6FA}] C:\WINDOWS\appvt.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3D347B5-8D22-1E55-4D3E-C94C91F76762}] C:\WINDOWS\apikr32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A5C17366-4766-30CF-5AD1-138CC5B3E64A}] C:\WINDOWS\crkv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B8A40086-20B8-C1F2-809A-00534310B657}] C:\WINDOWS\system32\apprw.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C054F454-DB2C-0434-31BF-C3C717973C71}] C:\WINDOWS\system32\d3ve.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c29ffbe7-9286-40b8-8121-cf9475315eba}] C:\WINDOWS\system32\dsqops.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC492B23-D765-1168-B1BB-2E0624A5E876}] C:\WINDOWS\appvz32.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DCB7AA47-29E8-5669-EB30-7BCD8254F742}] C:\WINDOWS\ipqy.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DECD8E91-E600-DF80-A5DB-061BB58F74D4}] C:\WINDOWS\ieyf.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EBA74261-7CAA-F270-26F4-4E2A669761D1}] C:\WINDOWS\ntne.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F05E944D-A6BE-48F3-A206-5BFEB880123F}] C:\WINDOWS\system32\sysew.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-04-26 07:06 C:\WINDOWS\KHALMNPR.Exe] "NetscapeClient"="" [] "tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [] "LanManNTR"="C:\Documents and Settings\Owner\Desktop\aff_test_morton.exe" [] "BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 C:\WINDOWS\BCMSMMSG.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59] "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-02-07 18:39] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24] "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [] "EPSON Stylus Photo R320 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9FA.exe" [] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [] "@"="" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "RunNarrator"=Narrator.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] @=wallpaperstyle "DisableRegistryTools"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] Source= C:\ZBWallpaper_5.bmp FriendlyName= [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "{554A0D4D-FE36-4A33-8526-172CDC545691}"="C:\WINDOWS\mssms.dll" [] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] Contents of the 'Scheduled Tasks' folder 2007-07-12 22:09:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job 2007-07-10 13:00:00 C:\WINDOWS\tasks\At10.job 2007-07-09 14:00:00 C:\WINDOWS\tasks\At11.job 2007-07-09 15:00:00 C:\WINDOWS\tasks\At12.job 2007-07-12 17:00:00 C:\WINDOWS\tasks\At14.job 2007-07-12 20:00:00 C:\WINDOWS\tasks\At17.job 2007-07-08 05:00:00 C:\WINDOWS\tasks\At2.job 2007-07-08 06:00:00 C:\WINDOWS\tasks\At3.job 2007-07-08 07:00:00 C:\WINDOWS\tasks\At4.job 2007-07-08 08:00:00 C:\WINDOWS\tasks\At5.job 2007-07-08 09:00:00 C:\WINDOWS\tasks\At6.job 2007-07-08 10:00:00 C:\WINDOWS\tasks\At7.job 2007-07-08 11:00:00 C:\WINDOWS\tasks\At8.job 2007-07-08 12:00:00 C:\WINDOWS\tasks\At9.job 2007-07-10 00:53:39 C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Owner.job ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-12 18:06:47 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKCU\Software\Microsoft\Windows\CurrentVersion\Run EPSON Stylus Photo R320 Series = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9FA.EXE /P30 "EPSON Stylus Photo R320 Series" /M "Stylus Photo R320" /EF scanning hidden files ... ************************************************************************** Completion time: 2007-07-12 18:12:26 C:\ComboFix-quarantined-files.txt ... 2007-07-12 18:11 --- E O F --- ran the find awf here is the report Find AWF report by noahdfear ©2006 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 10/30/2006 10:36 AM 256,576 iTunesHelper.exe 1 File(s) 256,576 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 10/25/2006 07:58 PM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\SPYWAR~1\BAK 06/05/2007 10:05 PM 9 CurrentHwnd.ssf 06/05/2007 10:05 PM 0 LogFile.txt 07/27/2005 01:17 PM 1,040,384 SpywareSlayer.Exe 3 File(s) 1,040,393 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 04/07/2003 03:07 AM 114,688 hkcmd.exe 04/07/2003 03:19 AM 155,648 igfxtray.exe 2 File(s) 270,336 bytes Directory of C:\PROGRA~1\COMMON~1\ISPCOMP\BAK 10/19/2006 04:52 PM 110,080 InstallService.exe 1 File(s) 110,080 bytes Directory of C:\PROGRA~1\EPSON\INKMON~1\BAK 12/07/2001 05:48 AM 258,118 InkMonitor.exe 1 File(s) 258,118 bytes Directory of C:\PROGRA~1\MUSICM~1\MUSICM~1\BAK 01/19/2006 11:06 AM 11,776 mimboot.exe 1 File(s) 11,776 bytes Directory of C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\BAK 09/14/2003 12:36 AM 50,688 WkUFind.exe 1 File(s) 50,688 bytes Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK 12/07/2004 12:31 AM 36,975 jusched.exe 1 File(s) 36,975 bytes Directory of C:\PROGRA~1\LOGITECH\DESKTO~1\8876480\PROGRAM\BAK 03/13/2007 08:03 PM 67,128 LogitechDesktopMessenger.exe 1 File(s) 67,128 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 04/26/2004 03:00 AM 98,304 E_FATI9FA.EXE 1 File(s) 98,304 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 256576 Oct 30 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 256576 Oct 30 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 Jun 27 2007 "C:\WINDOWS\Installer\{446DBFFA-4088-48E3-8932-74316BA4CAE4}\iTunesIco.exe" 108096 Oct 30 2006 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.2.16\iTunesSetupAdmin.exe" 282624 Oct 25 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 9 Jun 5 2007 "C:\Program Files\Spyware Slayer\bak\CurrentHwnd.ssf" 652 Jul 12 2007 "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\logfile.txt" 0 Jun 5 2007 "C:\Program Files\Spyware Slayer\bak\LogFile.txt" 1040384 Jul 27 2005 "C:\Program Files\Spyware Slayer\bak\SpywareSlayer.Exe" 114688 Apr 7 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Apr 7 2003 "C:\DELL\drivers\R60084\Graphics\Win2000\hkcmd.exe" 155648 Apr 7 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Apr 7 2003 "C:\DELL\drivers\R60084\Graphics\Win2000\igfxtray.exe" 110080 Oct 19 2006 "C:\Program Files\Common Files\ISPCOMP\bak\InstallService.exe" 258118 Dec 7 2001 "C:\Program Files\EPSON\Ink Monitor\bak\InkMonitor.exe" 11776 Jan 19 2006 "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\bak\mimboot.exe" 11776 Feb 12 2006 "C:\Program Files\MUSICMATCH\Musicmatch Update\MMJB\mimboot.exe" 50688 Sep 14 2003 "C:\Program Files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe" 36975 Dec 7 2004 "C:\Program Files\Java\jre1.5.0_01\bin\bak\jusched.exe" 67128 Mar 13 2007 "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe" 98304 Apr 26 2004 "C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_photo_r36590\E_FATI9FA.EXE" 98304 Apr 26 2004 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\E_FATI9FA.EXE" end of report and here is the new hijackthis report Logfile of HijackThis v1.99.1 Scan saved at 6:23:19 PM, on 7/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16441) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\notepad.exe C:\HJT\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {13BAA56A-9570-AC65-EA8E-EDE19CE7FD52} - (no file) O2 - BHO: Class - {143B9440-CA24-BED6-D9CD-08CC6A984764} - C:\WINDOWS\system32\ieys32.dll (file missing) O2 - BHO: Class - {15FEC491-F0D8-A206-B818-8D1D3FEDF979} - C:\WINDOWS\system32\sysjt32.dll (file missing) O2 - BHO: Class - {2AB80E5C-C6A3-016D-788D-E1F289A65E42} - C:\WINDOWS\winag32.dll (file missing) O2 - BHO: (no name) - {2AD27B78-A144-13BF-3CFD-8C2B118FCB77} - (no file) O2 - BHO: Class - {2C0087A1-5D6B-3765-B30B-8A302FBA4596} - C:\WINDOWS\addzb.dll (file missing) O2 - BHO: Class - {3AE414DC-B2A7-0DAD-989F-AC39ADF529E6} - C:\WINDOWS\system32\crie32.dll (file missing) O2 - BHO: Class - {3E7061C4-43FC-71F4-46DC-05A0D8524F6C} - C:\WINDOWS\system32\appms.dll (file missing) O2 - BHO: Class - {4B1C5C48-BA9D-4905-65D8-B9E278BF991D} - C:\WINDOWS\system32\mspc.dll (file missing) O2 - BHO: Class - {4CD05B77-C677-4D01-5562-25BA68012376} - C:\WINDOWS\apict.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Class - {563AC50A-6D00-C342-5EC7-D1C5C40E2122} - C:\WINDOWS\system32\msef32.dll (file missing) O2 - BHO: Class - {5DAA3B7C-6DEC-B6D5-9597-81AFF0B315AA} - C:\WINDOWS\system32\mfcme.dll (file missing) O2 - BHO: Class - {63AEC6B0-2656-D7C1-9D55-6B66F78A3D1A} - C:\WINDOWS\system32\iewo.dll (file missing) O2 - BHO: Class - {69B41F32-4AC6-1E89-433B-C41C1477D07C} - C:\WINDOWS\msiv32.dll (file missing) O2 - BHO: Class - {83241F15-A38D-4603-9874-0E32E3A2D544} - C:\WINDOWS\ntrl.dll (file missing) O2 - BHO: Class - {8A8EABA7-19AA-BB2B-F288-8E8741D4A2E0} - C:\WINDOWS\ntpn32.dll (file missing) O2 - BHO: Class - {8F69ADF9-A5DE-30DA-0B84-99655E5A16A4} - C:\WINDOWS\nettl.dll (file missing) O2 - BHO: Class - {96316EB2-0E4E-6A7E-7A88-DD575904EDB4} - C:\WINDOWS\ieqp32.dll (file missing) O2 - BHO: Class - {9FBCDEFF-A6FC-C42E-2DA5-84537095BAA5} - C:\WINDOWS\system32\appon32.dll (file missing) O2 - BHO: Class - {A1A0A8B0-1426-AEE6-1AF3-A0AEC3BAA6FA} - C:\WINDOWS\appvt.dll (file missing) O2 - BHO: Class - {A3D347B5-8D22-1E55-4D3E-C94C91F76762} - C:\WINDOWS\apikr32.dll (file missing) O2 - BHO: Class - {A5C17366-4766-30CF-5AD1-138CC5B3E64A} - C:\WINDOWS\crkv.dll (file missing) O2 - BHO: Class - {B8A40086-20B8-C1F2-809A-00534310B657} - C:\WINDOWS\system32\apprw.dll (file missing) O2 - BHO: Class - {C054F454-DB2C-0434-31BF-C3C717973C71} - C:\WINDOWS\system32\d3ve.dll (file missing) O2 - BHO: (no name) - {c29ffbe7-9286-40b8-8121-cf9475315eba} - C:\WINDOWS\system32\dsqops.dll (file missing) O2 - BHO: Class - {CC492B23-D765-1168-B1BB-2E0624A5E876} - C:\WINDOWS\appvz32.dll (file missing) O2 - BHO: Class - {DCB7AA47-29E8-5669-EB30-7BCD8254F742} - C:\WINDOWS\ipqy.dll (file missing) O2 - BHO: Class - {DECD8E91-E600-DF80-A5DB-061BB58F74D4} - C:\WINDOWS\ieyf.dll (file missing) O2 - BHO: Class - {EBA74261-7CAA-F270-26F4-4E2A669761D1} - C:\WINDOWS\ntne.dll (file missing) O2 - BHO: Class - {F05E944D-A6BE-48F3-A206-5BFEB880123F} - C:\WINDOWS\system32\sysew.dll (file missing) O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf O4 - HKLM\..\Run: [LanManNTR] C:\Documents and Settings\Owner\Desktop\aff_test_morton.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll (file missing) O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://financeworks.mathxl.com/wizmodules/...GenXInstall.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://financeworks.mathxl.com/applets/Pea...InstallAsst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab O16 - DPF: {F8B8AF16-CECF-4002-9CC0-1E18029D7770} (FWPlayer Control) - http://financeworks.mathxl.com/applets/FWPlayer.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O20 - AppInit_DLLs: O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: mssms - {554A0D4D-FE36-4A33-8526-172CDC545691} - C:\WINDOWS\mssms.dll (file missing) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing) O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing) O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe This post has been edited by Angelfire777: Jul 13 2007, 07:03 PM |
|
|
Jul 12 2007, 04:34 PM
Post
#4
|
|
|
Member ![]() ![]() Posts: 21 OS: xp |
I also just removed Logitech® Desktop Messenger (LDM)
as you instructed me to do |
|
|
Jul 13 2007, 03:08 AM
Post
#5
|
|
|
Visiting Staff Posts: 313 From: BC, Canada OS: Xp |
I'll get back to you tomorrow if it's ok.. I'm going out tonight
|
|
|
Jul 13 2007, 06:52 PM
Post
#6
|
|
|
Visiting Staff Posts: 313 From: BC, Canada OS: Xp |
Hi,
Are you using McAfee Antivirus? I see that you have a setup for limewire..So befoew you install it, I will warn you that p2p programs such as limewire can serve as vectors for malware to enter your system through the files downloaded there. Almost half of the available files for download are infected with malware so I recommend that you do not use it. Is this a desktop component that you use? C:\ZBWallpaper_5.bmp *Click Start > Control Panel > Add or Remove Programs and uninstall the items I listed in bold if found. SpyHunter The application above was before in the list of Rogue Antispyware programs. It was once part of the group where they trick users to buying their software. I recommend that you uninstall it. Spywareslayer This program is listed in the rogue antispyware application list and up until now, it uses dastardly ways to promote its product. Please uninstall it. __________ Double-click the FindAWF icon once again If a Security Alert shows, allow the program to run. As instructed, press any key to continue. Use the following option: Press 2 then Enter to restore files from bak folders A text file opens called: files.txt Click below the line and paste the following list of files to be restored: C:\Program Files\QuickTime\bak\qttask.exe C:\WINDOWS\system32\bak\hkcmd.exe C:\WINDOWS\system32\bak\igfxtray.exe C:\Program Files\Common Files\ISPCOMP\bak\InstallService.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe C:\Program Files\Java\jre1.5.0_01\bin\bak\jusched.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\E_FATI9FA.EXE Next, close and click Yes to save the changes. Once files.txt is saved, FindAWF does the following: -It attempts to terminate the process represented by each filename on the list, if running -Deletes the rogue file from the parent folder, if present -Copies the original file to the parent folder When done with the above, it automatically runs a new scan and opens a new log. Please provide the new FindAWF log in your reply. If by any chance you lose the report produced, click Start>Run, type %temp%\findawf\awf.txt. It will open the report again. ___________ Combofix Deletions
QUOTE File:: C:\WINDOWS\system32\ccbeg.ini2 C:\WINDOWS\system32\ccbeg.bak2 C:\WINDOWS\system32\ccbeg.bak1 C:\WINDOWS\bstdin.bin C:\WINDOWS\tasks\At10.job C:\WINDOWS\tasks\At11.job C:\WINDOWS\tasks\At12.job C:\WINDOWS\tasks\At14.job C:\WINDOWS\tasks\At17.job C:\WINDOWS\tasks\At2.job C:\WINDOWS\tasks\At3.job C:\WINDOWS\tasks\At4.job C:\WINDOWS\tasks\At5.job C:\WINDOWS\tasks\At6.job C:\WINDOWS\tasks\At7.job C:\WINDOWS\tasks\At8.job C:\WINDOWS\tasks\At9.job C:\Program Files\LimeWireWin.exe (include this line only if you decide to not use limewire) Folder:: C:\WINDOWS\system32\pmcubosf C:\WINDOWS\Spyware Slayer Settings C:\Program Files\Logitech\Desktop Messenger C:\Program Files\Spyware Slayer C:\Program Files\Enigma Software Group (include this line only if you uninstalled Spyhunter) Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13BAA56A-9570-AC65-EA8E-EDE19CE7FD52}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{143B9440-CA24-BED6-D9CD-08CC6A984764}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15FEC491-F0D8-A206-B818-8D1D3FEDF979}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AB80E5C-C6A3-016D-788D-E1F289A65E42}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AD27B78-A144-13BF-3CFD-8C2B118FCB77}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C0087A1-5D6B-3765-B30B-8A302FBA4596}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AE414DC-B2A7-0DAD-989F-AC39ADF529E6}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E7061C4-43FC-71F4-46DC-05A0D8524F6C}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4B1C5C48-BA9D-4905-65D8-B9E278BF991D}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CD05B77-C677-4D01-5562-25BA68012376}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{563AC50A-6D00-C342-5EC7-D1C5C40E2122}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DAA3B7C-6DEC-B6D5-9597-81AFF0B315AA}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63AEC6B0-2656-D7C1-9D55-6B66F78A3D1A}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69B41F32-4AC6-1E89-433B-C41C1477D07C}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83241F15-A38D-4603-9874-0E32E3A2D544}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A8EABA7-19AA-BB2B-F288-8E8741D4A2E0}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F69ADF9-A5DE-30DA-0B84-99655E5A16A4}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96316EB2-0E4E-6A7E-7A88-DD575904EDB4}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9FBCDEFF-A6FC-C42E-2DA5-84537095BAA5}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1A0A8B0-1426-AEE6-1AF3-A0AEC3BAA6FA}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3D347B5-8D22-1E55-4D3E-C94C91F76762}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A5C17366-4766-30CF-5AD1-138CC5B3E64A}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B8A40086-20B8-C1F2-809A-00534310B657}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C054F454-DB2C-0434-31BF-C3C717973C71}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c29ffbe7-9286-40b8-8121-cf9475315eba}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC492B23-D765-1168-B1BB-2E0624A5E876}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DCB7AA47-29E8-5669-EB30-7BCD8254F742}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DECD8E91-E600-DF80-A5DB-061BB58F74D4}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EBA74261-7CAA-F270-26F4-4E2A669761D1}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F05E944D-A6BE-48F3-A206-5BFEB880123F}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LDM"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "{554A0D4D-FE36-4A33-8526-172CDC545691}"=- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"="" [-HKEY_CLASSES_ROOT\PROTOCOLS\Protocol\bwfile-8876480] Filelook:: C:\WINDOWS\system32\ZBScreenSaver.scr C:\Documents and Settings\Owner\Desktop\aff_test_morton.exe Dirlook:: C:\Program Files\Common Files\Scanner
Please do an online scan with Kaspersky WebScanner Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
This post has been edited by Angelfire777: Jul 13 2007, 06:57 PM |
|
|
Jul 13 2007, 08:44 PM
|