Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Random pop ups, pos1-? files.


  • Please log in to reply

#1
Aphikins

Aphikins

    Member

  • Member
  • PipPip
  • 11 posts
Here is the hijack this log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:47:27, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\SBC Self Support Tool\bin\mad.exe
C:\PROGRA~1\SBCSEL~1\ASSTCO~1\MOTIVE~1.EXE
C:\Program Files\SBC Self Support Tool\SMARTB~1\MotiveSB.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Other (downloads, links, etc)\HiJackThis_v2.exe
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\explorer.exe
D:\Program Files\BitComet\BitComet.exe
E:\Program Files\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "D:\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [QdrPack12] "C:\Program Files\QdrPack\QdrPack12.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKUS\S-1-5-18\..\Run: [IESet] IExplorer.dll .dbt (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [IESet] IExplorer.dll .dbt (User 'Default user')
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gabby\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
O23 - Service: NBService - Nero AG - E:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6584 bytes




And the uninstall list :

Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
AT&T Self Support Tool
BroadJump Client Foundation
CCleaner (remove only)
Combined Community Codec Pack 2007-07-22
Corel Paint Shop Pro X
Creative WebCam Live! Driver (1.01.01.0730)
GameTap
Highlight Viewer (Windows Live Toolbar)
HijackThis 2.0.2
Hotfix for Windows XP (KB926239)
Internet Speed Monitor
IrfanView (remove only)
Java™ 6 Update 3
Logitech Desktop Messenger
Logitech QuickCam
Logitech® Camera Driver
Map Button (Windows Live Toolbar)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft User-Mode Driver Framework Feature Pack 1.0
MVision
Nero 7 Essentials
neroxml
NVIDIA Drivers
Opera 9.22
PowerDVD
Realtek AC'97 Audio
Smart Menus (Windows Live Toolbar)
SUPERAntiSpyware Professional
Windows Installer 3.1 (KB893803)
Windows Live Favorites for Windows Live Toolbar
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Xfire (remove only)
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar




I've tried the combofix, uninstalling outterinfo (sp), AVG, SUPERAntiSpyware, and a host of others to no avail. I keep getting random pop ups, some not even appearing.. but you can hear the sounds of them popping up, as well as sometimes an announcer in the background with no picture. It gets so bad that I will be playing an online game and it will knock the screen like a pop up occured, to where I have to click on it to choose to bring it "up front" so to speak. It's now happening to internet explorer as I'm typing this right here.

I know it's not much information, but I would really like to find a way to fix this instead of just... going out and buying a whole new computer /again/. =)


Thank you for any and all help that is to come.

Aph.
  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Aphikins

Welcome to G2Go. :)
===================
I do not see any ANtivirus software present so.

The first thing I will need you to do is to Download this anti-virus program and install it.
This is free.
AVG free
=====================================================================
I know you have tried Combofix but I would like for you to try it again please.

Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
  • 0

#3
Aphikins

Aphikins

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Sorry for the late responce! Work is kicking my tail :) Anyways, had a few problems installing the AVG, kept saying some of the installation files were corrupt.. said to redownload.. and redownload.. well, I'm sure you get the picture haha. Anyways, here's the logs!


Combofix :

ComboFix 08-02-25.3 - Gabby 2008-02-29 9:51:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.689 [GMT -6:00]
Running from: C:\Documents and Settings\Gabby\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Gabby\My Documents\WNSXS~1
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\Temporary
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\bwwaivgl.dll
C:\WINDOWS\system32\crhgimvl.ini
C:\WINDOWS\system32\epbuymkb.dllbox
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\fadgsd.exe
C:\WINDOWS\system32\gdywovyp.ini
C:\WINDOWS\system32\hnpnstqu.dll
C:\WINDOWS\system32\hxmvaddc.ini
C:\WINDOWS\system32\icutrbws.dll
C:\WINDOWS\system32\iexplorer.dll .dbt
C:\WINDOWS\system32\ineWc01
C:\WINDOWS\system32\jjxiamny.ini
C:\WINDOWS\system32\mydhlcbt.dll
C:\WINDOWS\system32\ovcbbejy.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\plincuto.ini
C:\WINDOWS\system32\psmwwniq.dll
C:\WINDOWS\system32\rsvyb.bak1
C:\WINDOWS\system32\rsvyb.bak2
C:\WINDOWS\system32\rsvyb.ini
C:\WINDOWS\system32\rsvyb.ini2
C:\WINDOWS\system32\rsvyb.tmp
C:\WINDOWS\system32\slwlxeax.ini
C:\WINDOWS\system32\tbclhdym.ini
C:\WINDOWS\system32\tdcggkij.dll
C:\WINDOWS\system32\v6
C:\WINDOWS\system32\vfpxpogu.dll
C:\WINDOWS\system32\vkevqefc.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wnphcuux.ini
C:\WINDOWS\system32\xcdyvivo.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-27 23:19 . 2008-02-27 23:27 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-27 23:19 . 2008-02-27 23:28 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-24 02:05 . 2008-02-24 02:05 <DIR> d-------- C:\Program Files\CCleaner
2008-02-24 01:59 . 2008-02-24 01:59 136,111 --a------ C:\WINDOWS\POTA777444.exe
2008-02-24 00:12 . 2007-07-18 18:39 490,776 -ra------ C:\WINDOWS\system32\drivers\LV561AV.SYS
2008-02-24 00:12 . 2007-07-18 18:43 490,008 -ra------ C:\WINDOWS\system32\LVUI2.dll
2008-02-24 00:12 . 2007-07-18 18:44 465,432 -ra------ C:\WINDOWS\system32\LVUI2RC.dll
2008-02-24 00:12 . 2007-07-18 18:40 416,280 -ra------ C:\WINDOWS\system32\lvcodec2.dll
2008-02-24 00:12 . 2007-07-18 18:40 195,096 -ra------ C:\WINDOWS\system32\lvci1110.dll
2008-02-24 00:12 . 2007-07-18 17:54 58,163 -ra------ C:\WINDOWS\system32\lvcoinst.ini
2008-02-24 00:12 . 2007-07-18 18:44 41,752 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-02-24 00:12 . 2007-07-18 17:55 19,344 -ra------ C:\WINDOWS\system32\Repository.reg
2008-02-24 00:03 . 2008-02-24 00:03 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-02-23 23:36 . 2008-02-24 00:02 <DIR> d-------- C:\Program Files\Logitech
2008-02-23 23:36 . 2008-02-24 00:12 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2008-02-23 23:36 . 2008-02-23 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-02-23 23:31 . 2008-02-23 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-02-23 22:28 . 2008-02-24 00:51 26,823 ---hs---- C:\WINDOWS\system32\gtbqxajb.ini
2008-02-23 02:28 . 2008-02-23 02:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-22 22:28 . 2008-02-22 22:28 26,583 ---hs---- C:\WINDOWS\system32\teddkdmq.ini
2008-02-21 22:27 . 2008-02-22 22:28 26,523 ---hs---- C:\WINDOWS\system32\smtxwxtq.ini
2008-02-21 10:22 . 2008-02-26 18:50 136,640 --a------ C:\WINDOWS\BMbf1f185a.xml
2008-02-21 10:22 . 2008-02-26 09:25 22 --a------ C:\WINDOWS\pskt.ini
2008-02-20 10:20 . 2008-02-20 10:20 294 ---hs---- C:\WINDOWS\system32\dmmcmlyp.ini
2008-02-19 21:06 . 2008-02-26 01:46 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-19 19:20 . 2008-02-19 19:20 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2008-02-19 10:41 . 2008-02-19 10:41 <DIR> d-------- C:\WINDOWS\wofk
2008-02-19 10:14 . 2008-02-21 09:18 36,864 --a------ C:\WINDOWS\system32\fwehg.exe
2008-02-19 10:14 . 2008-02-20 02:18 36,864 --a------ C:\WINDOWS\gsdfr5yhgjng.exe
2008-02-19 10:14 . 2008-02-21 09:18 36,864 --a------ C:\WINDOWS\f5egfdsgw.exe
2008-02-19 02:06 . 2008-02-19 02:06 <DIR> d-------- C:\Program Files\Opera
2008-02-19 00:54 . 2008-02-19 00:54 26,096 --a------ C:\WINDOWS\system32\pmnkllk.dll
2008-02-18 23:11 . 2008-02-18 23:11 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-02-18 22:34 . 2008-02-19 00:32 40,960 --a------ C:\WINDOWS\system32\hjjtgyg.exe
2008-02-18 22:34 . 2008-02-19 00:32 40,960 --a------ C:\WINDOWS\gfderygfh.exe
2008-02-18 22:30 . 2008-02-18 22:30 <DIR> d-------- C:\Documents and Settings\Gabby\Application Data\Motive
2008-02-18 22:28 . 2008-02-18 22:28 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-02-18 10:18 . 2008-02-18 10:18 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-02-17 23:19 . 2008-02-17 23:19 270,698 --a------ C:\WINDOWS\system32\L1E67.tmp
2008-02-17 23:19 . 2008-02-17 23:19 181,965 --a------ C:\WINDOWS\system32\LF2E7.tmp
2008-02-17 23:19 . 2008-02-17 23:19 400 --a------ C:\WINDOWS\system32\L5BA0.tmp
2008-02-14 16:22 . 2007-01-31 09:58 43,387 --a------ C:\WINDOWS\browser.exe
2008-02-14 16:22 . 2007-01-31 09:58 6,246 --a------ C:\WINDOWS\atty.ico
2008-02-14 16:21 . 2008-02-14 16:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-02-14 16:21 . 2005-05-10 00:36 81,920 --------- C:\WINDOWS\system32\W32n50.dll
2008-02-14 16:21 . 2005-05-10 00:36 17,162 --------- C:\WINDOWS\system32\Pcandis5.sys
2008-02-14 16:21 . 2005-05-10 00:36 16,848 --------- C:\WINDOWS\system32\Pcandis4.sys
2008-02-14 16:21 . 2005-05-10 00:36 16,073 --------- C:\WINDOWS\system32\Pcandis3.vxd
2008-02-14 16:20 . 2008-02-14 16:20 <DIR> d-------- C:\WINDOWS\Motive
2008-02-14 16:20 . 2008-02-18 22:29 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-02-14 16:19 . 2008-02-18 22:28 <DIR> d-------- C:\Program Files\SBC Self Support Tool
2008-02-14 16:08 . 2008-02-14 16:08 <DIR> d-------- C:\Program Files\BroadJump
2008-02-14 16:03 . 2001-01-12 16:09 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2008-02-14 16:03 . 2001-01-12 18:04 171,280 --a------ C:\WINDOWS\system32\jit.dll
2008-02-14 16:03 . 2001-01-12 18:04 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-02-14 16:03 . 2001-01-12 18:04 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-02-14 16:03 . 2001-01-12 16:27 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-02-14 16:03 . 2001-01-12 16:10 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-02-14 15:47 . 2007-01-31 09:58 266,240 --------- C:\WINDOWS\SBCDSL.exe
2008-02-14 15:47 . 2007-01-31 09:58 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
2008-02-14 13:43 . 2008-02-14 13:43 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-02-13 12:22 . 2008-02-13 12:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-13 12:14 . 2008-02-13 12:14 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-02-13 12:10 . 2008-02-19 21:09 <DIR> d-------- C:\Documents and Settings\Gabby\Application Data\Ahead
2008-02-13 12:04 . 2008-02-13 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-13 11:57 . 2008-02-13 12:00 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-02-13 11:57 . 2008-02-13 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-02-09 12:27 . 2008-02-14 15:45 2,876 --a------ C:\WINDOWS\ACROREAD.INI
2008-01-30 20:02 . 2008-01-30 20:02 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 15:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-28 00:03 --------- d-----w C:\Documents and Settings\Gabby\Application Data\uTorrent
2008-02-22 06:46 20,480 ----a-w C:\WINDOWS\quit.exe
2008-02-14 22:03 155,995 ----a-w C:\WINDOWS\java\Packages\MZXZ7PR9.ZIP
2008-02-08 17:25 --------- d-----w C:\Documents and Settings\Gabby\Application Data\Xfire
2008-01-15 04:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Xfire
2008-01-09 18:02 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Xfire
2008-01-09 07:49 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-01-08 18:23 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\uTorrent
2008-01-08 18:06 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Media Player Classic
2008-01-02 00:28 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Yahoo!
2008-01-01 22:50 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Grisoft
2007-12-28 22:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-04 09:46 142 ----a-w C:\Program Files\page.html
2006-12-03 01:05 2,522 ----a-w C:\Program Files\func.js
2006-11-25 07:57 482 ----a-w C:\Program Files\Del.js
.

------- Sigcheck -------

28f288e08a098df3c0eb6aa813bb41fd C:\WINDOWS\system32\drivers\tcpip.sys
-c--a-w 359,040 2007-11-27 04:40:38 C:\WINDOWS\system32\dllcache\tcpip.sys
----a-w 359,040 2007-11-27 04:40:38 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"DAEMON Tools Pro Agent"="D:\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 07:08 136136]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 17:36 455968]
"QdrPack12"="C:\Program Files\QdrPack\QdrPack12.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 08:28 577536 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-06-15 16:20 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 16:20 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 16:20 6803456]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]

C:\Documents and Settings\Aphikins\Start Menu\Programs\Startup\
Xfire.lnk - E:\Xfire\xfire.exe [2008-01-30 20:02:36 2880336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2008-02-14 16:19:14 217088]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-02-24 00:03:19 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]

[HKLM\~\startupfolder\C:^Documents and Settings^Gabby^Start Menu^Programs^Startup^IMVU.lnk]
path=C:\Documents and Settings\Gabby\Start Menu\Programs\Startup\IMVU.lnk
backup=C:\WINDOWS\pss\IMVU.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bc2c2bc6]
C:\WINDOWS\system32\lvmighrc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
E:\Program Files\BitComet\BitComet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
--a------ 2002-09-10 21:26 368706 C:\Program Files\BroadJump\Client Foundation\CFD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2007-09-06 07:08 136136 D:\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IESet]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-06-25 08:47 1057064 E:\Nero 7\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2007-08-23 17:36 455968 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2005-08-24 07:51 442455 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-06-15 16:20 6803456 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-06-25 08:47 1629480 E:\Nero 7\InCD\NBHGui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uaq]
C:\Documents and Settings\Gabby\Application Data\?asks\r?gedit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAble]
C:\Program Files\WinAble\winable.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSControlService"=3 (0x3)
"DomainService"=2 (0x2)
"PavPrSrv"=2 (0x2)
"LightScribeService"=2 (0x2)
"InCDsrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"E:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"E:\\Xfire\\xfire.exe"=
"D:\\Program Files\\utorrent\\utorrent.exe"=
"D:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10048:TCP"= 10048:TCP:BitComet 10048 TCP
"10048:UDP"= 10048:UDP:BitComet 10048 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys []
S2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys []
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dde30040-84e0-11dc-9900-000d8734a114}]
\Shell\AutoRun\command - G:\LaunchU3.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 15:31:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 09:58:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2008-02-29 10:01:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-29 16:01:08
ComboFix2.txt 2007-12-28 22:46:53





Hijack!This log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:23, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
E:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "D:\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [QdrPack12] "C:\Program Files\QdrPack\QdrPack12.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gabby\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: NBService - Nero AG - E:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6602 bytes
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
No problem :)

1. Please open Notepad
  • Click Start , then Run
  • type in notepad in the Run Box then hit ok.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\POTA777444.exe
C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
C:\WINDOWS\system32\gtbqxajb.ini
C:\WINDOWS\system32\teddkdmq.ini
C:\WINDOWS\system32\smtxwxtq.ini
C:\WINDOWS\BMbf1f185a.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\dmmcmlyp.ini
C:\WINDOWS\system32\fwehg.exe
C:\WINDOWS\gsdfr5yhgjng.exe
C:\WINDOWS\f5egfdsgw.exe
C:\WINDOWS\system32\pmnkllk.dll
C:\WINDOWS\browser.exe
C:\WINDOWS\atty.ico
C:\WINDOWS\quit.exe
C:\Program Files\func.js
C:\Program Files\Del.js
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\system32\lvmighrc.dll
Folder::
C:\Program Files\QdrPack
C:\Program Files\WinAble
C:\WINDOWS\system32\windows 
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QdrPack12"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bc2c2bc6]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IESet]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uaq]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAble]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"DomainService"=-
"MSControlService"=-
Driver::
MSControlService
DomainService
Dirlook::
C:\WINDOWS\wofk


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Edited by kahdah, 29 February 2008 - 10:59 AM.

  • 0

#5
Aphikins

Aphikins

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Combofix Log :


ComboFix 08-02-25.3 - Gabby 2008-02-29 22:34:52.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.584 [GMT -6:00]
Running from: C:\Documents and Settings\Gabby\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gabby\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\Del.js
C:\Program Files\func.js
C:\WINDOWS\atty.ico
C:\WINDOWS\BMbf1f185a.xml
C:\WINDOWS\browser.exe
C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
C:\WINDOWS\f5egfdsgw.exe
C:\WINDOWS\gsdfr5yhgjng.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\POTA777444.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\quit.exe
C:\WINDOWS\system32\dmmcmlyp.ini
C:\WINDOWS\system32\fwehg.exe
C:\WINDOWS\system32\gtbqxajb.ini
C:\WINDOWS\system32\lvmighrc.dll
C:\WINDOWS\system32\pmnkllk.dll
C:\WINDOWS\system32\smtxwxtq.ini
C:\WINDOWS\system32\teddkdmq.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Del.js
C:\WINDOWS\atty.ico
C:\WINDOWS\BMbf1f185a.xml
C:\WINDOWS\browser.exe
C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
C:\WINDOWS\f5egfdsgw.exe
C:\WINDOWS\gsdfr5yhgjng.exe
C:\WINDOWS\POTA777444.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\quit.exe
C:\WINDOWS\system32\dmmcmlyp.ini
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\fwehg.exe
C:\WINDOWS\system32\gtbqxajb.ini
C:\WINDOWS\system32\pmnkllk.dll
C:\WINDOWS\system32\smtxwxtq.ini
C:\WINDOWS\system32\teddkdmq.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_MSCONTROLSERVICE
-------\MSControlService


((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.

2008-02-29 10:09 . 2008-02-29 10:09 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-29 10:09 . 2008-02-29 10:11 <DIR> d-------- C:\Documents and Settings\Gabby\Application Data\AVG7
2008-02-29 10:08 . 2008-02-29 22:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-27 23:19 . 2008-02-27 23:27 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-27 23:19 . 2008-02-27 23:28 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-24 02:05 . 2008-02-24 02:05 <DIR> d-------- C:\Program Files\CCleaner
2008-02-24 00:12 . 2007-07-18 18:39 490,776 -ra------ C:\WINDOWS\system32\drivers\LV561AV.SYS
2008-02-24 00:12 . 2007-07-18 18:43 490,008 -ra------ C:\WINDOWS\system32\LVUI2.dll
2008-02-24 00:12 . 2007-07-18 18:44 465,432 -ra------ C:\WINDOWS\system32\LVUI2RC.dll
2008-02-24 00:12 . 2007-07-18 18:40 416,280 -ra------ C:\WINDOWS\system32\lvcodec2.dll
2008-02-24 00:12 . 2007-07-18 18:40 195,096 -ra------ C:\WINDOWS\system32\lvci1110.dll
2008-02-24 00:12 . 2007-07-18 17:54 58,163 -ra------ C:\WINDOWS\system32\lvcoinst.ini
2008-02-24 00:12 . 2007-07-18 18:44 41,752 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-02-24 00:12 . 2007-07-18 17:55 19,344 -ra------ C:\WINDOWS\system32\Repository.reg
2008-02-23 23:36 . 2008-02-24 00:02 <DIR> d-------- C:\Program Files\Logitech
2008-02-23 23:36 . 2008-02-24 00:12 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2008-02-23 23:36 . 2008-02-23 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-02-23 23:31 . 2008-02-23 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-02-23 02:28 . 2008-02-23 02:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-19 21:06 . 2008-02-26 01:46 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-19 19:20 . 2008-02-19 19:20 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2008-02-19 10:41 . 2008-02-19 10:41 <DIR> d-------- C:\WINDOWS\wofk
2008-02-19 02:06 . 2008-02-19 02:06 <DIR> d-------- C:\Program Files\Opera
2008-02-18 23:11 . 2008-02-18 23:11 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-02-18 22:34 . 2008-02-19 00:32 40,960 --a------ C:\WINDOWS\system32\hjjtgyg.exe
2008-02-18 22:34 . 2008-02-19 00:32 40,960 --a------ C:\WINDOWS\gfderygfh.exe
2008-02-18 22:30 . 2008-02-18 22:30 <DIR> d-------- C:\Documents and Settings\Gabby\Application Data\Motive
2008-02-18 22:28 . 2008-02-18 22:28 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-02-18 10:18 . 2008-02-18 10:18 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-02-17 23:19 . 2008-02-17 23:19 270,698 --a------ C:\WINDOWS\system32\L1E67.tmp
2008-02-17 23:19 . 2008-02-17 23:19 181,965 --a------ C:\WINDOWS\system32\LF2E7.tmp
2008-02-17 23:19 . 2008-02-17 23:19 400 --a------ C:\WINDOWS\system32\L5BA0.tmp
2008-02-14 16:21 . 2008-02-14 16:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-02-14 16:21 . 2005-05-10 00:36 81,920 --------- C:\WINDOWS\system32\W32n50.dll
2008-02-14 16:21 . 2005-05-10 00:36 17,162 --------- C:\WINDOWS\system32\Pcandis5.sys
2008-02-14 16:21 . 2005-05-10 00:36 16,848 --------- C:\WINDOWS\system32\Pcandis4.sys
2008-02-14 16:21 . 2005-05-10 00:36 16,073 --------- C:\WINDOWS\system32\Pcandis3.vxd
2008-02-14 16:20 . 2008-02-14 16:20 <DIR> d-------- C:\WINDOWS\Motive
2008-02-14 16:20 . 2008-02-18 22:29 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-02-14 16:19 . 2008-02-18 22:28 <DIR> d-------- C:\Program Files\SBC Self Support Tool
2008-02-14 16:08 . 2008-02-14 16:08 <DIR> d-------- C:\Program Files\BroadJump
2008-02-14 16:03 . 2001-01-12 16:09 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2008-02-14 16:03 . 2001-01-12 18:04 171,280 --a------ C:\WINDOWS\system32\jit.dll
2008-02-14 16:03 . 2001-01-12 18:04 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-02-14 16:03 . 2001-01-12 18:04 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-02-14 16:03 . 2001-01-12 16:27 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-02-14 16:03 . 2001-01-12 16:10 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-02-14 15:47 . 2007-01-31 09:58 266,240 --------- C:\WINDOWS\SBCDSL.exe
2008-02-14 15:47 . 2007-01-31 09:58 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
2008-02-14 13:43 . 2008-02-14 13:43 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-02-13 12:22 . 2008-02-13 12:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-13 12:14 . 2008-02-13 12:14 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-02-13 12:10 . 2008-02-19 21:09 <DIR> d-------- C:\Documents and Settings\Gabby\Application Data\Ahead
2008-02-13 12:04 . 2008-02-13 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-13 11:57 . 2008-02-13 12:00 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-02-13 11:57 . 2008-02-13 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-02-09 12:27 . 2008-02-14 15:45 2,876 --a------ C:\WINDOWS\ACROREAD.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-29 15:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-28 00:03 --------- d-----w C:\Documents and Settings\Gabby\Application Data\uTorrent
2008-02-14 22:03 155,995 ----a-w C:\WINDOWS\java\Packages\MZXZ7PR9.ZIP
2008-02-08 17:25 --------- d-----w C:\Documents and Settings\Gabby\Application Data\Xfire
2008-01-31 02:02 54,608 ----a-w C:\WINDOWS\system32\xfcodec.dll
2008-01-15 04:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Xfire
2008-01-09 18:02 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Xfire
2008-01-09 07:49 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-01-08 18:23 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\uTorrent
2008-01-08 18:06 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Media Player Classic
2008-01-02 00:28 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Yahoo!
2008-01-01 22:50 --------- d-----w C:\Documents and Settings\Aphikins\Application Data\Grisoft
2007-10-04 09:46 142 ----a-w C:\Program Files\page.html
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\WINDOWS\wofk ----

2008-02-19 10:41 310 --a------ C:\WINDOWS\wofk\wofk.dat


------- Sigcheck -------

28f288e08a098df3c0eb6aa813bb41fd C:\WINDOWS\system32\drivers\tcpip.sys
-c--a-w 359,040 2007-11-27 04:40:38 C:\WINDOWS\system32\dllcache\tcpip.sys
----a-w 359,040 2007-11-27 04:40:38 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"DAEMON Tools Pro Agent"="D:\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 07:08 136136]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 17:36 455968]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 08:28 577536 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-06-15 16:20 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 16:20 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 16:20 6803456]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-29 22:22 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-29 10:09 219136]

C:\Documents and Settings\Aphikins\Start Menu\Programs\Startup\
Xfire.lnk - E:\Xfire\xfire.exe [2008-01-30 20:02:36 2880336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2008-02-14 16:19:14 217088]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-02-24 00:03:19 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]

[HKLM\~\startupfolder\C:^Documents and Settings^Gabby^Start Menu^Programs^Startup^IMVU.lnk]
path=C:\Documents and Settings\Gabby\Start Menu\Programs\Startup\IMVU.lnk
backup=C:\WINDOWS\pss\IMVU.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
E:\Program Files\BitComet\BitComet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
--a------ 2002-09-10 21:26 368706 C:\Program Files\BroadJump\Client Foundation\CFD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2007-09-06 07:08 136136 D:\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-06-25 08:47 1057064 E:\Nero 7\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2007-08-23 17:36 455968 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2005-08-24 07:51 442455 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-06-15 16:20 6803456 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-06-25 08:47 1629480 E:\Nero 7\InCD\NBHGui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PavPrSrv"=2 (0x2)
"LightScribeService"=2 (0x2)
"InCDsrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"E:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"E:\\Xfire\\xfire.exe"=
"D:\\Program Files\\utorrent\\utorrent.exe"=
"D:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10048:TCP"= 10048:TCP:BitComet 10048 TCP
"10048:UDP"= 10048:UDP:BitComet 10048 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys []
S2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dde30040-84e0-11dc-9900-000d8734a114}]
\Shell\AutoRun\command - G:\LaunchU3.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 04:31:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 22:40:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2008-02-29 22:42:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-01 04:42:36
ComboFix2.txt 2008-02-29 16:01:19
ComboFix3.txt 2007-12-28 22:46:53





HijackThis log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:43:32, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
E:\Program Files\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "D:\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gabby\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - E:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6430 bytes
  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#7
Aphikins

Aphikins

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Kapersky :


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, March 02, 2008 08:42:06
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/03/2008
Kaspersky Anti-Virus database records: 592992
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 173642
Number of viruses found: 6
Number of infected objects: 21
Number of suspicious objects: 0
Duration of the scan process: 05:37:27

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Gabby\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_9ABC_2C52_BC2C_2B69\dfsr.db Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_9ABC_2C52_BC2C_2B69\fsr.log Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_9ABC_2C52_BC2C_2B69\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_9ABC_2C52_BC2C_2B69\tmp.edb Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Windows Live Contacts\[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Application Data\Microsoft\Windows Live Contacts\[email protected]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Temp\~DFAAF6.tmp Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Temp\~DFAB21.tmp Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Temp\~DFBB45.tmp Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Temp\~DFBB6E.tmp Object is locked skipped
C:\Documents and Settings\Gabby\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gabby\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gabby\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\SBC Self Support Tool\log\mpbtn.log Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\POTA777444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\QooBox\Quarantine\C\WINDOWS\POTA777444.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\p9\liopud89104.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\p9\liopud89104.exe.vir NSIS: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C8530363-3F51-47DA-94F2-444469CAAC83}\RP105\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\L1E67.tmp/stream/data0004 Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\WINDOWS\system32\L1E67.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\WINDOWS\system32\L1E67.tmp NSIS: infected - 2 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\$Recycle.Bin\S-1-5-21-1597228987-3882115303-404358983-1000\$RVQJXTM\CMDOW_EX_.vir/cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
D:\$Recycle.Bin\S-1-5-21-1597228987-3882115303-404358983-1000\$RVQJXTM\CMDOW_EX_.vir CAB: infected - 1 skipped
D:\48513c3804a2b5b01d\admparse.dll Object is locked skipped
D:\48513c3804a2b5b01d\advpack.dll Object is locked skipped
D:\48513c3804a2b5b01d\browseui.dll Object is locked skipped
D:\48513c3804a2b5b01d\corpol.dll Object is locked skipped
D:\48513c3804a2b5b01d\custsat.dll Object is locked skipped
D:\48513c3804a2b5b01d\dxtmsft.dll Object is locked skipped
D:\48513c3804a2b5b01d\dxtrans.dll Object is locked skipped
D:\48513c3804a2b5b01d\extmgr.dll Object is locked skipped
D:\48513c3804a2b5b01d\hmmapi.dll Object is locked skipped
D:\48513c3804a2b5b01d\icardie.dll Object is locked skipped
D:\48513c3804a2b5b01d\icrav03.rat Object is locked skipped
D:\48513c3804a2b5b01d\ie4uinit.exe Object is locked skipped
D:\48513c3804a2b5b01d\ieakeng.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieaksie.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieakui.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieapfltr.dll Object is locked skipped
D:\48513c3804a2b5b01d\iedkcs32.dll Object is locked skipped
D:\48513c3804a2b5b01d\iedw.exe Object is locked skipped
D:\48513c3804a2b5b01d\ieencode.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieframe.dll Object is locked skipped
D:\48513c3804a2b5b01d\iepeers.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieproxy.dll Object is locked skipped
D:\48513c3804a2b5b01d\iernonce.dll Object is locked skipped
D:\48513c3804a2b5b01d\iertutil.dll Object is locked skipped
D:\48513c3804a2b5b01d\iesetup.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieudinit.exe Object is locked skipped
D:\48513c3804a2b5b01d\ieui.dll Object is locked skipped
D:\48513c3804a2b5b01d\ieuinit.inf Object is locked skipped
D:\48513c3804a2b5b01d\iexplore.exe Object is locked skipped
D:\48513c3804a2b5b01d\imgutil.dll Object is locked skipped
D:\48513c3804a2b5b01d\inetcpl.cpl Object is locked skipped
D:\48513c3804a2b5b01d\inseng.dll Object is locked skipped
D:\48513c3804a2b5b01d\install.ins Object is locked skipped
D:\48513c3804a2b5b01d\jscript.dll Object is locked skipped
D:\48513c3804a2b5b01d\jsproxy.dll Object is locked skipped
D:\48513c3804a2b5b01d\licmgr10.dll Object is locked skipped
D:\48513c3804a2b5b01d\msfeeds.dll Object is locked skipped
D:\48513c3804a2b5b01d\msfeeds.mof Object is locked skipped
D:\48513c3804a2b5b01d\msfeedsbs.dll Object is locked skipped
D:\48513c3804a2b5b01d\msfeedsbs.mof Object is locked skipped
D:\48513c3804a2b5b01d\msfeedssync.exe Object is locked skipped
D:\48513c3804a2b5b01d\mshta.exe Object is locked skipped
D:\48513c3804a2b5b01d\mshtml.dll Object is locked skipped
D:\48513c3804a2b5b01d\mshtml.tlb Object is locked skipped
D:\48513c3804a2b5b01d\mshtmled.dll Object is locked skipped
D:\48513c3804a2b5b01d\mshtmler.dll Object is locked skipped
D:\48513c3804a2b5b01d\msls31.dll Object is locked skipped
D:\48513c3804a2b5b01d\msrating.dll Object is locked skipped
D:\48513c3804a2b5b01d\mstime.dll Object is locked skipped
D:\48513c3804a2b5b01d\occache.dll Object is locked skipped
D:\48513c3804a2b5b01d\occache.ini Object is locked skipped
D:\48513c3804a2b5b01d\pngfilt.dll Object is locked skipped
D:\48513c3804a2b5b01d\shdocvw.dll Object is locked skipped
D:\48513c3804a2b5b01d\shlwapi.dll Object is locked skipped
D:\48513c3804a2b5b01d\spmsg.dll Object is locked skipped
D:\48513c3804a2b5b01d\spuninst.exe Object is locked skipped
D:\48513c3804a2b5b01d\spupdsvc.exe Object is locked skipped
D:\48513c3804a2b5b01d\tdc.ocx Object is locked skipped
D:\48513c3804a2b5b01d\ticrf.rat Object is locked skipped
D:\48513c3804a2b5b01d\update\idndl.exe Object is locked skipped
D:\48513c3804a2b5b01d\update\ie7.cat Object is locked skipped
D:\48513c3804a2b5b01d\update\iecustom.dll Object is locked skipped
D:\48513c3804a2b5b01d\update\iereseticons.exe Object is locked skipped
D:\48513c3804a2b5b01d\update\iesetup.exe Object is locked skipped
D:\48513c3804a2b5b01d\update\legitlibm.dll Object is locked skipped
D:\48513c3804a2b5b01d\update\nlsdl.exe Object is locked skipped
D:\48513c3804a2b5b01d\update\update.exe Object is locked skipped
D:\48513c3804a2b5b01d\update\update.exe.manifest Object is locked skipped
D:\48513c3804a2b5b01d\update\update.inf Object is locked skipped
D:\48513c3804a2b5b01d\update\update.ver Object is locked skipped
D:\48513c3804a2b5b01d\update\updspapi.dll Object is locked skipped
D:\48513c3804a2b5b01d\update\xmllitesetup.exe Object is locked skipped
D:\48513c3804a2b5b01d\url.dll Object is locked skipped
D:\48513c3804a2b5b01d\urlmon.dll Object is locked skipped
D:\48513c3804a2b5b01d\vbscript.dll Object is locked skipped
D:\48513c3804a2b5b01d\vgx.dll Object is locked skipped
D:\48513c3804a2b5b01d\webcheck.dll Object is locked skipped
D:\48513c3804a2b5b01d\webcheck.ini Object is locked skipped
D:\48513c3804a2b5b01d\winfxdocobj.exe Object is locked skipped
D:\48513c3804a2b5b01d\wininet.dll Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45A05.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45A06.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45A07.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45A08.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45A09.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\45E06.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\E_SBASE.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\E_si10e3.exe Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\FONTA.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\FONTB.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\FONTP.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\INK2.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\INK_E.HTM Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_1.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_2.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_3.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_4.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_5.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_6.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_7.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_8.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_CAUT.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_ICTOP.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_SPACE.GIF Object is locked skipped
D:\Program Files\Common Files\EPSON\HTML\EPSON Stylus Photo 870\R_WARN.GIF Object is locked skipped
D:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a628c29c7009db2ebb3819ae26b56b8b_f0eaf3bd-a472-4961-b9b4-8933fc5c197a Object is locked skipped
D:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_f0eaf3bd-a472-4961-b9b4-8933fc5c197a Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\keyfinder.exe RarSFX: infected - 2 skipped
D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\Power DVD TMP\Power DVD Deluxe v7.0+Keygen\Setup_exe.vir Object is locked skipped
E:\C drive things\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\19af382323be8b258a37c35dca752d67_e15a358f-e011-4898-b816-7feeaa884027 Object is locked skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\24dda1dc2fe2983cc3e71d301d86a865_e15a358f-e011-4898-b816-7feeaa884027 Object is locked skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d577578a169fc5a7f95f055cee8874a_e15a358f-e011-4898-b816-7feeaa884027 Object is locked skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ea3035eec6bed77f51d8ab8f8daf4f2_e15a358f-e011-4898-b816-7feeaa884027 Object is locked skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
E:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
E:\Documents and Settings\Gabby\Local Settings\Temp\hsperfdata_Gabby\2764 Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.



Wow.. took five hours! :)
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\keyfinder.exe 
    E:\C drive things\Program Files\MSN Messenger\riched20.dll 
    C:\WINDOWS\system32\L1E67.tmp
    C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix
    C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix.exe
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
==================
Also post a new Hijackthis log and let me know how things are running?
  • 0

#9
Aphikins

Aphikins

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
MoveIt Log :

D:\Users\KoE_Dae'Loki.41D99EAAEDBD4E5\Desktop\keyfinder.exe moved successfully.
DllUnregisterServer procedure not found in E:\C drive things\Program Files\MSN Messenger\riched20.dll
E:\C drive things\Program Files\MSN Messenger\riched20.dll NOT unregistered.
E:\C drive things\Program Files\MSN Messenger\riched20.dll moved successfully.
C:\WINDOWS\system32\L1E67.tmp moved successfully.
C:\Documents and Settings\Aphikins\Desktop\Booooooooogers\SmitfraudFix moved successfully.
C:\Documents and Settings\Gabby\Desktop\Booooooooogers\SmitfraudFix.exe moved successfully.

OTMoveIt2 v1.0.20 log created on 03022008_210629




HijackThis Log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:08:42, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\rsvp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\NeverwinterNights\NWN\nwmain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "D:\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gabby\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - E:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6730 bytes





As for how it's running... OH my God.. near perfect! Thank you ooh so much for all you've done so far to help me :)
  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)
================
Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    [list]
  • Posted Image

The above procedure will delete and do the following:

  • ComboFix and its associated files and folders.
  • VundoFix backups, if present
  • The C:\Deckard folder, if present
  • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Clean System Restore points.

Also delete\uninstall anything that we used that is left over.
==========================================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP