Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Help with Spyaxe and others [RESOLVED]


  • This topic is locked This topic is locked

#16
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
I hate to tell you this but ComboFix does the same show hourglass for an instant and nothing. Also, to be honest with you, at this point I don't even know what is running on my computer in terms of protection and guard. I'm also not even sure how to turn off whatever is running. LMFAO talk about messed up...I appreciate your patience.

I am heading out for a bit, I hope you're still around when I return, I miss being online... Darn time zones eh?!
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
I will be here :)

Okay do the following when you return:

Right click on Combofix and choose rename name it to kahdah.exe and then try to run it like this:
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\kahdah.exe" /KillAll


  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply.

Let me know how it goes and we will go from there. :)
  • 0

#18
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
Ok...it loaded up a progress bar for ComboFix but did not generate a log. Unless it saved it somewhere. :)
  • 0

#19
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
AUGH something called Ultimate Defender just downloaded and is now scanning my computer!!!!!!! Is that part of ComboFix? I'm going to stop the scan. I hope.


Ok...it finished scanning before I stopped it so I just exited and then removed it (I hope) via Add/Remove. I hope things aren't more complicated now...

Edited by angelinhi, 06 February 2008 - 09:11 PM.

  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
No Ultimate defender is Malware.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode,double click on Kahdah.exe and see if it will run.

ALso double click on the Fixthis.reg file I had you create on your desktop earlier.

If Combofix (kahdah.exe) fails to run reboot and do the following:

* Go here to run an online scannner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Check next options: Remove found threats and Scan unwanted applications.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

  • 0

#21
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
Ok this may be a first...it installed however when I click "Start" for the scan, it initializes then gives me an "Error: Update Failed (200)" message. :)


Oh and yes, I made sure to be in IE.

Edited by angelinhi, 06 February 2008 - 09:48 PM.

  • 0

#22
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Okay try this one then:

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

  • 0

#23
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
That Panda scan really takes awhile...here's the log:


Incident Status Location

Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\327882R2FWJFW\nircmd.cfexe
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\327882R2FWJFW\nircmd.com
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.casalemedia.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.atdmt.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.burstnet.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.casalemedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.fastclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[media.fastclick.net/w/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.fastclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.mediaplex.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[www.burstbeacon.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.advertising.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.overture.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.bluestreak.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.realmedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.realmedia.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.bfast.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.trafficmp.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[searchportal.information.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[citi.bridgetrack.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.com.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-1.txt[.tucows.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.mediaplex.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.tribalfusion.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.fastclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.atdmt.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.fastclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.advertising.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[www.burstbeacon.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.burstnet.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.trafficmp.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[ad.yieldmanager.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.questionmarket.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.adrevolver.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies-2.txt[.bfast.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Mozilla\Firefox\Profiles\c8zf815x.default\cookies.txt[.doubleclick.net/]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\kahdah.exe[327882R2FWJFW\nircmd.com]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\kahdah.exe[327882R2FWJFW\nircmd.cfexe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\SmitfraudFix\Process.exe
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\SmitfraudFix\Reboot.exe
Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\SmitfraudFix\restart.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\smitRem.exe[smitRem/Process.exe]
Adware:Adware/UltimateDefender Not disinfected C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe
Potentially unwanted tool:Application/UltimateDefender Not disinfected C:\WINDOWS\braviax.exe
Potentially unwanted tool:Application/UltimateDefender Not disinfected C:\WINDOWS\system32\braviax.exe
Possible Virus. Not disinfected C:\WINDOWS\system32\dllcache\beep.sys
Possible Virus. Not disinfected C:\WINDOWS\system32\drivers\beep.sys
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\users32.dat
Adware:Adware/UltimateDefender Not disinfected C:\WINDOWS\system32\winivstr.exe
Potentially unwanted tool:Application/UltimateDefender Not disinfected C:\_OTMoveIt\MovedFiles\02052008_150925\Windows\braviax.exe
  • 0

#24
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\winivstr.exe /d
    C:\WINDOWS\system32\users32.dat /d
    C:\WINDOWS\system32\drivers\beep.sys /d
    C:\WINDOWS\system32\dllcache\beep.sys /d
    C:\WINDOWS\system32\dllcache\beep.sys /d
    C:\WINDOWS\system32\braviax.exe /d
    C:\WINDOWS\braviax.exe /d
    C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe /d
    C:\Program Files\Coupons /d
    C:\Program Files\UltimateDefender /d
    C:\Program Files\UltimateCleaner /d
    C:\Program Files\udsetup.exe /d
    C:\Program Files\ucsetup.exe /d

  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
=======================================
After that Please download RogueRemover by RubberDucky here.
  • Double-click rr-free-setup.exe to begin installing the program.
  • Follow the setup instructions for installation.
  • Double-click the RogueRemover icon on your desktop.
  • Once the program runs, select Check for Updates.
  • When prompted, select Check for Updates.
  • If prompted again, click Download to receive the latest updates.
  • When completed, close the update window.
  • Next, click Scan
  • If it detects anything, select to remove all objects found.
  • Close RogueRemover
===========================================
After that try to run Superantispyware again.
Post that log when it gets done.

Let me know how it goes.

Edited by kahdah, 07 February 2008 - 03:10 AM.

  • 0

#25
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
OMG I'm freaking excited lol, the red Spyaxe icon is GONE and AVG just kicked on and updated itself!!!!! Here's the log, I rebooted right before this:


[Custom Input]
< C:\WINDOWS\system32\winivstr.exe /d >
< C:\WINDOWS\system32\users32.dat /d >
File delete failed. C:\WINDOWS\system32\users32.dat scheduled to be deleted on reboot.
< C:\WINDOWS\system32\drivers\beep.sys /d >
< C:\WINDOWS\system32\dllcache\beep.sys /d >
< C:\WINDOWS\system32\dllcache\beep.sys /d >
File/Folder C:\WINDOWS\system32\dllcache\beep.sys not found.
< C:\WINDOWS\system32\braviax.exe /d >
File delete failed. C:\WINDOWS\system32\braviax.exe scheduled to be deleted on reboot.
< C:\WINDOWS\braviax.exe /d >
< C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe /d >
File/Folder C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe not found.
< C:\Program Files\Coupons /d >
C:\Program Files\Coupons\Uninstall deleted successfully.
C:\Program Files\Coupons deleted successfully.
< C:\Program Files\UltimateDefender /d >
File/Folder C:\Program Files\UltimateDefender not found.
< C:\Program Files\UltimateCleaner /d >
File/Folder C:\Program Files\UltimateCleaner not found.
< C:\Program Files\udsetup.exe /d >
File/Folder C:\Program Files\udsetup.exe not found.
< C:\Program Files\ucsetup.exe /d >
File/Folder C:\Program Files\ucsetup.exe not found.


I was able to run the Superantispy but I got over-enthused and quarantined everything. Here's a HJT log I ran in normal mode just now:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:20 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe
C:\windows\RTHDCPL.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\windows\zHotkey.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\BigFix\bigfix.exe
C:\windows\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Secunia\PSI (RC1)\psi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = By Hawaiian Telcom
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" /uninstall
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: .protected
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O4 - Global Startup: .protected
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://www.pandasecurity.com
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/b...lineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1177835440018
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - AppInit_DLLs: cru629.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/OWNER~1.YOU/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 7239 bytes

Edited by angelinhi, 07 February 2008 - 04:58 PM.

  • 0

Advertisements


#26
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Okay try to again run combofix.
  • 0

#27
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
ComboFix 08-02.05.3 - Owner 2008-02-07 13:25:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1308 [GMT -10:00]
Running from: C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\kahdah.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Start Menu\Programs\Startup\.protected
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\RECYCLER\desktopA.sys
C:\windows\.protected
C:\windows\system32\drivers\etc\.protected
C:\windows\system32\f3PSSavr.scr
D:\Autorun.inf

----- BITS: Possible infected sites -----

hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.

2008-02-07 12:04 . 2008-02-07 12:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-07 12:04 . 2008-02-07 12:04 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\SUPERAntiSpyware.com
2008-02-07 12:04 . 2008-02-07 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-07 12:03 . 2008-02-07 12:03 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-02-07 11:58 . 2008-02-07 11:58 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Grisoft
2008-02-06 18:09 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-06 18:08 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\ahhbhhijljyx.sys
2008-02-06 17:57 . 2008-02-06 17:57 16,384 --a------ C:\WINDOWS\system32\nod32se.exe
2008-02-06 17:43 . 2008-02-06 17:43 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-02-06 15:06 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-06 15:01 . 2008-02-06 15:01 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-06 14:51 . 2008-02-06 14:51 <DIR> d-------- C:\Program Files\Secunia
2008-02-06 14:45 . 2008-02-06 14:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-06 14:45 . 2008-02-06 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-05 18:20 . 2008-02-07 11:51 6,144 --a------ C:\WINDOWS\system32\cru629.dat
2008-02-05 18:20 . 2008-02-07 11:51 6,144 --a------ C:\WINDOWS\cru629.dat
2008-02-05 18:00 . 2008-02-05 18:00 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\TASK
2008-02-05 17:51 . 2008-02-05 17:51 <DIR> d-------- C:\Deckard
2008-02-05 15:15 . 2008-02-05 15:15 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\DoctorWeb
2008-02-05 15:09 . 2008-02-05 15:09 <DIR> d-------- C:\_OTMoveIt
2008-02-03 15:57 . 2008-02-03 15:57 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-03 15:48 . 2007-05-30 02:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-03 09:17 . 2008-02-06 19:16 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-03 09:17 . 2008-02-06 18:05 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-03 07:48 . 2008-02-03 07:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-03 07:46 . 2008-02-03 15:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-02 22:47 . 2008-02-02 22:47 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-02-02 19:51 . 2007-08-01 16:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-02 19:38 . 2008-02-02 21:03 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\HouseCall 6.6
2008-02-02 19:34 . 2008-02-02 19:46 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\.housecall6.6
2008-01-19 11:47 . 2008-01-19 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-16 16:55 . 2008-01-28 19:44 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-01-14 18:02 . 2008-02-07 13:41 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-14 18:02 . 2008-01-14 18:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-14 17:52 . 2008-02-02 19:09 <DIR> d-------- C:\Temp
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 22:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 04:42 --------- d-----w C:\Program Files\iTunes
2008-02-07 04:36 --------- d-----w C:\Program Files\BigFix
2008-02-07 01:02 --------- d-----w C:\Program Files\Java
2008-02-07 00:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-03 23:38 --------- d-----w C:\Program Files\Trend Micro
2008-02-03 05:11 --------- d-----w C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\LimeWire
2008-02-03 04:27 --------- d-----w C:\Program Files\Tales of Pirates Online
2008-01-22 18:49 --------- d-----w C:\Program Files\Avery Wizard 3.1
2008-01-22 09:18 7,808 ----a-w C:\windows\system32\drivers\psi_mf.sys
2008-01-19 21:41 --------- d-----w C:\Program Files\ONWIND
2008-01-17 03:08 --------- d-----w C:\Program Files\iPod
2008-01-17 03:06 --------- d-----w C:\Program Files\QuickTime
2007-12-22 17:56 --------- d-----w C:\Program Files\FlashGet
2007-12-22 03:21 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2007-12-21 21:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-21 00:36 --------- d-----w C:\Program Files\Common Files\Avery
2007-12-12 01:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-08-17 20:33 214 ----a-w C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 09:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 09:00 33280 C:\WINDOWS\system32\rundll32.exe]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 15:18 151552]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 09:49 163840]
"TM Outbreak Agent"="C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" [2006-09-13 19:00 290816]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-13 23:01 16010752 C:\WINDOWS\RTHDCPL.exe]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"PCClient.exe"="C:\Program Files\Trend Micro\Antivirus\PCClient.exe" [2006-09-13 19:00 634949]
"pccguide.exe"="C:\Program Files\Trend Micro\Antivirus\pccguide.exe" [2006-09-13 19:00 950337]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 19:02 53248]
"nwiz"="nwiz.exe" [2005-09-18 05:32 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 09:00 33280 C:\WINDOWS\system32\rundll32.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 13:16 1121792]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 17:56 64512]
"CHotkey"="zHotkey.exe" [2004-12-08 14:57 550912 C:\WINDOWS\zHotkey.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 13:19 77312 C:\WINDOWS\arpwrmsg.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-21 15:30 1191936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-10 23:25 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40 5367608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 15:34 5419008]

C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Start Menu\Programs\Startup\
Secunia PSI (RC1).lnk - C:\Program Files\Secunia\PSI (RC1)\psi.exe [2008-02-05 00:36:24 610304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2004-05-12 15:18 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 11:24 49152 C:\Program Files\HP\HP Software Update\HPWuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McRegWiz]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
--a------ 2005-12-09 15:44 139264 C:\Program Files\Digital Media Reader\readericon45G.exe

R2 UxTuneUp;TuneUp Theme Extension;C:\windows\System32\svchost.exe [2004-08-10 09:00]
R3 PSI;PSI;C:\windows\system32\DRIVERS\psi_mf.sys [2008-01-21 23:18]
S3 motccgp;Motorola USB Composite Device Driver;C:\windows\system32\DRIVERS\motccgp.sys [2007-06-18 15:19]
S3 motccgpfl;MotCcgpFlService;C:\windows\system32\DRIVERS\motccgpfl.sys [2007-01-22 19:33]
S3 MotDev;Motorola Inc. USB Device;C:\windows\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 03:21:01 C:\windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-02-01 04:51:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-07 06:00:02 C:\windows\Tasks\wrSpySweeper_09EEB5A6D6184C088C38B77A5194AB4C.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_09EEB5A6D6184C088C38B77A5194AB4C
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
"2008-02-06 04:53:24 C:\windows\Tasks\wrSpySweeper_E7B0D801988345FA9C093AB02846C23E.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_E7B0D801988345FA9C093AB02846C23E
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 13:41:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BigFix\bigfix.exe
.
**************************************************************************
.
Completion time: 2008-02-07 13:44:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 23:44:00
.
2008-01-09 18:47:27 --- E O F ---
  • 0

#28
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Awesome :)

1. Please open Notepad
  • Click Start , then Run
  • type in notepad in the Run Box then hit ok.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\drivers\ahhbhhijljyx.sys
C:\WINDOWS\system32\cru629.dat
C:\WINDOWS\cru629.dat
C:\WINDOWS\system32\users32.dat 
C:\WINDOWS\system32\winivstr.exe 
C:\WINDOWS\system32\drivers\beep.sys 
C:\WINDOWS\system32\dllcache\beep.sys 
C:\WINDOWS\system32\braviax.exe 
C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe 
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#29
angelinhi

angelinhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 59 posts
It didn't ask to re-boot this time but I did anyway. I got an Windows Security Alert about no firewall is on...is that important? There's a red shield with an x in the icon tray.

Anyway, here's the CF log:

ComboFix 08-02.05.3 - Owner 2008-02-07 15:07:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1449 [GMT -10:00]
Running from: C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\kahdah.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Local Settings\Temporary Internet Files\Content.IE5\FUGIZAAN\udefender_setup[1].exe
C:\WINDOWS\cru629.dat
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\cru629.dat
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\ahhbhhijljyx.sys
C:\WINDOWS\system32\drivers\beep.sys
C:\WINDOWS\system32\users32.dat
C:\WINDOWS\system32\winivstr.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cru629.dat
C:\WINDOWS\system32\cru629.dat
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\ahhbhhijljyx.sys
C:\WINDOWS\system32\drivers\beep.sys

.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.

2008-02-07 12:04 . 2008-02-07 12:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-07 12:04 . 2008-02-07 12:04 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\SUPERAntiSpyware.com
2008-02-07 12:04 . 2008-02-07 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-07 12:03 . 2008-02-07 12:03 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-02-07 11:58 . 2008-02-07 11:58 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\Grisoft
2008-02-06 18:09 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-06 17:57 . 2008-02-06 17:57 16,384 --a------ C:\WINDOWS\system32\nod32se.exe
2008-02-06 17:43 . 2008-02-06 17:43 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-02-06 17:02 . 2004-08-10 09:00 388,608 --a------ C:\kmd.exe
2008-02-06 15:06 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-06 15:01 . 2008-02-06 15:01 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-06 14:51 . 2008-02-06 14:51 <DIR> d-------- C:\Program Files\Secunia
2008-02-06 14:45 . 2008-02-06 14:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-06 14:45 . 2008-02-06 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-05 18:00 . 2008-02-05 18:00 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\TASK
2008-02-05 17:51 . 2008-02-05 17:51 <DIR> d-------- C:\Deckard
2008-02-05 15:15 . 2008-02-05 15:15 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\DoctorWeb
2008-02-05 15:09 . 2008-02-05 15:09 <DIR> d-------- C:\_OTMoveIt
2008-02-03 15:57 . 2008-02-03 15:57 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-03 15:48 . 2007-05-30 02:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-03 09:17 . 2008-02-06 19:16 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-03 09:17 . 2008-02-06 18:05 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-03 07:48 . 2008-02-03 07:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-03 07:46 . 2008-02-03 15:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-02 22:47 . 2008-02-02 22:47 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-02-02 19:51 . 2007-08-01 16:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-02 19:38 . 2008-02-02 21:03 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\HouseCall 6.6
2008-02-02 19:34 . 2008-02-02 19:46 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\.housecall6.6
2008-01-19 11:47 . 2008-01-19 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-16 16:55 . 2008-01-28 19:44 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-01-14 18:02 . 2008-02-07 13:41 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-14 18:02 . 2008-01-14 18:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-14 17:52 . 2008-02-02 19:09 <DIR> d-------- C:\Temp
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 22:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 04:42 --------- d-----w C:\Program Files\iTunes
2008-02-07 04:36 --------- d-----w C:\Program Files\BigFix
2008-02-07 01:29 4,358 ----a-w C:\windows\system32\tmp.reg
2008-02-07 01:02 --------- d-----w C:\Program Files\Java
2008-02-07 00:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-06 10:03 85,504 ----a-w C:\windows\system32\VACFix.exe
2008-02-03 23:38 --------- d-----w C:\Program Files\Trend Micro
2008-02-03 05:11 --------- d-----w C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\LimeWire
2008-02-03 04:27 --------- d-----w C:\Program Files\Tales of Pirates Online
2008-01-28 00:37 81,920 ----a-w C:\windows\system32\IEDFix.exe
2008-01-22 18:49 --------- d-----w C:\Program Files\Avery Wizard 3.1
2008-01-22 09:18 7,808 ----a-w C:\windows\system32\drivers\psi_mf.sys
2008-01-19 21:41 --------- d-----w C:\Program Files\ONWIND
2008-01-17 03:08 --------- d-----w C:\Program Files\iPod
2008-01-17 03:06 --------- d-----w C:\Program Files\QuickTime
2007-12-22 17:56 --------- d-----w C:\Program Files\FlashGet
2007-12-22 03:21 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2007-12-21 21:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-21 00:36 --------- d-----w C:\Program Files\Common Files\Avery
2007-12-14 21:32 12,632 ----a-w C:\windows\system32\lsdelete.exe
2007-12-12 01:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-08-17 20:33 214 ----a-w C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 09:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 09:00 33280 C:\WINDOWS\system32\rundll32.exe]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 15:18 151552]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 09:49 163840]
"TM Outbreak Agent"="C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" [2006-09-13 19:00 290816]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-13 23:01 16010752 C:\WINDOWS\RTHDCPL.exe]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"PCClient.exe"="C:\Program Files\Trend Micro\Antivirus\PCClient.exe" [2006-09-13 19:00 634949]
"pccguide.exe"="C:\Program Files\Trend Micro\Antivirus\pccguide.exe" [2006-09-13 19:00 950337]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 19:02 53248]
"nwiz"="nwiz.exe" [2005-09-18 05:32 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 09:00 33280 C:\WINDOWS\system32\rundll32.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 13:16 1121792]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 17:56 64512]
"CHotkey"="zHotkey.exe" [2004-12-08 14:57 550912 C:\WINDOWS\zHotkey.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 13:19 77312 C:\WINDOWS\arpwrmsg.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-21 15:30 1191936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-10 23:25 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40 5367608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 15:34 5419008]

C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Start Menu\Programs\Startup\
Secunia PSI (RC1).lnk - C:\Program Files\Secunia\PSI (RC1)\psi.exe [2008-02-05 00:36:24 610304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2004-05-12 15:18 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 11:24 49152 C:\Program Files\HP\HP Software Update\HPWuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McRegWiz]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
--a------ 2005-12-09 15:44 139264 C:\Program Files\Digital Media Reader\readericon45G.exe

R2 UxTuneUp;TuneUp Theme Extension;C:\windows\System32\svchost.exe [2004-08-10 09:00]
R3 PSI;PSI;C:\windows\system32\DRIVERS\psi_mf.sys [2008-01-21 23:18]
S3 motccgp;Motorola USB Composite Device Driver;C:\windows\system32\DRIVERS\motccgp.sys [2007-06-18 15:19]
S3 motccgpfl;MotCcgpFlService;C:\windows\system32\DRIVERS\motccgpfl.sys [2007-01-22 19:33]
S3 MotDev;Motorola Inc. USB Device;C:\windows\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 03:21:01 C:\windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-02-01 04:51:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-07 06:00:02 C:\windows\Tasks\wrSpySweeper_09EEB5A6D6184C088C38B77A5194AB4C.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_09EEB5A6D6184C088C38B77A5194AB4C
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
"2008-02-06 04:53:24 C:\windows\Tasks\wrSpySweeper_E7B0D801988345FA9C093AB02846C23E.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_E7B0D801988345FA9C093AB02846C23E
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 15:09:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-07 15:10:24
ComboFix-quarantined-files.txt 2008-02-08 01:10:21
ComboFix2.txt 2008-02-07 23:44:03
.
2008-01-09 18:47:27 --- E O F ---



HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:29 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\windows\RTHDCPL.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\windows\zHotkey.exe
C:\windows\ARPWRMSG.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\Secunia\PSI (RC1)\psi.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" /uninstall
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://www.pandasecurity.com
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/b...lineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1177835440018
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/OWNER~1.YOU/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 7051 bytes

Edited by angelinhi, 07 February 2008 - 07:20 PM.

  • 0

#30
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Are you using trend Micro's firewall?
If so then try to enable it.

============================
Go ahead and uninstall all of these programs:
SUPERAntiSpyware
RogueRemover FREE
EsetOnlineScanner
ActiveScan


then please delete these folders
C:\Deckard
C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\DoctorWeb
=================================================
Then after that please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
================================================================
And as a final check please do the following:
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP