Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Reproducing trojans Its been 3 days of viruses and trjoans [RESOLVED]


  • This topic is locked This topic is locked

#1
bunny298

bunny298

    Member

  • Member
  • PipPip
  • 14 posts
:) Hello, four days ago, I started getting pop up ads from setthetrend. I have done many different scans. I have done trojan hunter, 4 trojans found, I have done avg anti virus, it found 3 trojans, I ran combofix, it didnt find anything, I ran avg anti-spyware according to your instrustions here, in the safe mode, it found several things, but I couldnt save a report, because it said no report. I have run CC Cleaner. I have run ad-aware, which found a few things, and put them in quarantene. I also ran super anti-spyware accordning to your instructions. I tried several times to run the online panda, only to get locked up every single time due to the pop ups from whatever is attacking my pc. I will be on my desktop, no browser opened, and and ad will start playing..you hear the sound of the ad, but no windows are opened. So I do a cntl, alt, del, and see that an IEExplore window is being used, but its not being displayed. My clock has been changed to a different setting, even though I have reset it, it keeps going back to 16:14 instead of 4:14. I have had to change my home page. And even though I have done all these scans, clean ups and what not, I still am having the same issues. Here is a log of Hijack and Ill also enclose the log for superanti-spyware.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:05, on 2008-03-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\fxssvc.exe
C:\WINDOWS1\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\antiviirus.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\DOCUME~1\Teri\LOCALS~1\Temp\FhVqhzAh.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com...p/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/...erInstaller.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1167442701283
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://games.bellsou...bugs/axhost.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: VolumeRunOnce - {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS1\system32\HPZipm12.exe

--
End of file - 7314 bytes


here is the combo fix log
ComboFix 08-03-04.1 - Teri 2008-03-04 4:03:45.1 - FAT32x86
Running from: C:\Documents and Settings\Teri\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\77775482.exe
C:\Program Files\Common Files\download

.
((((((((((((((((((((((((( Files Created from 2008-02-04 to 2008-03-04 )))))))))))))))))))))))))))))))
.

2008-03-04 01:00 . 2008-03-04 01:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-04 01:00 . 2008-03-04 01:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2008-03-04 00:34 . 2008-03-04 00:34 16,588 --a------ C:\Program Files\tmp161081.exe
2008-03-04 00:17 . 2008-03-04 00:17 16,456 --a------ C:\Program Files\tmp156895.exe
2008-03-04 00:05 . 2008-03-04 04:23 54,156 --ah----- C:\WINDOWS1\QTFont.qfn
2008-03-04 00:05 . 2008-03-04 00:06 1,409 --a------ C:\WINDOWS1\QTFont.for
2008-03-03 22:00 . 2008-03-03 22:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SUPERAntiSpyware.com
2008-03-03 21:59 . 2008-03-03 21:59 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-03 21:59 . 2008-03-03 21:59 <DIR> d-------- C:\Documents and Settings\Teri\Application Data\SUPERAntiSpyware.com
2008-03-03 21:57 . 2008-03-03 21:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-03 21:55 . 2008-03-03 21:55 1,238,736 --a------ C:\MGtools.exe
2008-03-03 21:18 . 2008-03-03 21:18 16,496 --a------ C:\Program Files\tmp134022.exe
2008-03-03 19:42 . 2008-03-03 16:26 299,008 --a------ C:\WINDOWS1\apdqnxp.dll
2008-03-03 19:42 . 2008-03-03 19:42 35,604 --a------ C:\Program Files\instaler.exe
2008-03-03 19:42 . 2008-03-03 19:43 16,468 --a------ C:\Program Files\tmp2311413.exe
2008-03-03 19:42 . 2008-03-03 19:42 11,960 --a------ C:\Program Files\antiviirus.exe
2008-03-03 19:22 . 2008-03-03 19:22 <DIR> d-------- C:\Program Files\FBrowsingAdvisor
2008-03-03 19:22 . 2008-03-03 19:22 <DIR> d-------- C:\Program Files\FBrowserAdvisor
2008-03-03 19:22 . 2008-03-03 19:22 <DIR> d-------- C:\Program Files\ContextProgram
2008-03-03 19:22 . 2006-04-14 23:05 9,952 --a------ C:\regxpcom.exe
2008-02-23 16:12 . 2008-02-23 16:12 193,880 -rah----- C:\WINDOWS1\system32\cpnprt2.cid
2008-02-23 16:11 . 2008-02-23 16:11 <DIR> d-------- C:\WINDOWS1\Cache
2008-02-23 16:11 . 2008-02-23 16:11 <DIR> d-------- C:\Program Files\Coupons
2008-02-22 12:48 . 2008-02-22 12:48 <DIR> d-------- C:\Program Files\iPod
2008-02-22 12:46 . 2008-02-22 12:47 <DIR> d-------- C:\Program Files\iTunes
2008-02-22 12:41 . 2008-02-22 12:41 <DIR> d-------- C:\Program Files\QuickTime
2008-02-15 16:16 . 2008-02-15 16:16 1,071 --a------ C:\WINDOWS1\AWMODEM.INF
2008-02-15 16:11 . 2008-02-15 16:11 <DIR> d-------- C:\WINDOWS1\system32\FxsTmp
2008-02-06 19:11 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS1\system32\lfgif13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS1\system32\ltkrn13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS1\system32\ltimg13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS1\system32\lfcmp13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS1\system32\ltdis13n.dll
2008-02-06 19:10 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS1\system32\ltefx13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS1\system32\ltfil13n.dll
2008-02-06 19:10 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS1\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 09:24 16,540 ----a-w C:\Program Files\tmp579272.exe
2008-01-26 22:05 --------- d-----w C:\Program Files\Bonjour
2008-01-11 05:53 44,544 ------w C:\WINDOWS1\system32\dllcache\pngfilt.dll
2008-01-10 22:00 --------- d-----w C:\Documents and Settings\Teri\Application Data\CamTrack
2007-12-19 23:01 347,136 ------w C:\WINDOWS1\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS1\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 ------w C:\WINDOWS1\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS1\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS1\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS1\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ----a-w C:\WINDOWS1\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS1\system32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS1\system32\dllcache\oleaut32.dll
2005-01-18 05:08 266 --sh--w C:\Program Files\desktop.ini
2005-01-18 05:08 11,079 ---h--w C:\Program Files\folder.htt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4D1D56C-3EC9-2F5D-FAA3-4112CCDD61DC}]
2007-12-30 15:48 1019904 --a------ C:\Program Files\ContextProgram\ContextProgram-2.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS1\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-06-08 18:50 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-21 05:08 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"antiviirus"="C:\Program Files\antiviirus.exe" [2008-03-03 19:42 11960]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 05:09 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"VolumeRunOnce"= {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll [2008-03-03 19:42 18690]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^ WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\ WinCinema Manager.lnk
backup=C:\WINDOWS1\pss\ WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS1\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS1\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS1\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS1\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS1\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS1\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^PalStart.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\PalStart.lnk
backup=C:\WINDOWS1\pss\PalStart.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-06-08 18:50 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free]
C:\Program Files\DriveCleaner Free\UDC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2005-01-12 14:54 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS1\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-27 15:22 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS1\\System32\\FXSCLNT.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R2 ASPIXNT;ASPIXNT;C:\WINDOWS1\system32\drivers\ASPIXNT.sys [1999-02-15 18:06]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS1\system32\DRIVERS\AN983.sys [2004-08-04 00:31]
R3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS1\system32\Drivers\Icam3.sys [2001-08-17 14:05]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 04:23:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS1\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Teri\LOCALS~1\Temp\Ty7PkhKo.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2008-03-04 4:37:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-04 09:37:26
.
2008-02-13 00:17:44 --- E O F ---


superAntiSpyware log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/04/2008 at 10:39 PM

Application Version : 4.0.1154

Core Rules Database Version : 3414
Trace Rules Database Version: 1406

Scan type : Complete Scan
Total Scan Time : 03:01:20

Memory items scanned : 353
Memory threats detected : 1
Registry items scanned : 5613
Registry threats detected : 2
File items scanned : 74298
File threats detected : 14

Trojan.Downloader-AntiViirus
C:\PROGRAM FILES\ANTIVIIRUS.EXE
C:\PROGRAM FILES\ANTIVIIRUS.EXE
[antiviirus] C:\PROGRAM FILES\ANTIVIIRUS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#antiviirus [ C:\Program Files\antiviirus.exe ]
C:\WINDOWS1\Prefetch\ANTIVIIRUS.EXE-10A2E3A4.pf

Adware.Tracking Cookie
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][3].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][4].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP462\A0062586.EXE

Adware.SurfSideKick
C:\SYSTEM VOLUME INFORMATION\_RESTORE{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP461\A0060458.EXE



Another SuperAntispyware log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/03/2008 at 11:57 PM

Application Version : 4.0.1154

Core Rules Database Version : 3413
Trace Rules Database Version: 1405

Scan type : Complete Scan
Total Scan Time : 01:28:53

Memory items scanned : 406
Memory threats detected : 0
Registry items scanned : 5569
Registry threats detected : 1
File items scanned : 43486
File threats detected : 93

Adware.Tracking Cookie
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][4].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\Documents and Settings\Teri\Cookies\[email protected][3].txt
C:\Documents and Settings\Teri\Cookies\[email protected][3].txt
C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][2].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][1].txt
C:\WINDOWS\Cookies\[email protected][1].txt

Adware.SurfSideKick
C:\Program Files\Common Files\VCClient\ClientUpdater.bat
C:\Program Files\Common Files\VCClient\ICSharpCode.SharpZipLib.dll
C:\Program Files\Common Files\VCClient\VCClient.exe
C:\Program Files\Common Files\VCClient\VCClient.exe.config
C:\Program Files\Common Files\VCClient\VCMain.exe
C:\Program Files\Common Files\VCClient\VCUpdate.exe
C:\Program Files\Common Files\VCClient\VCUpdate.exe.config
C:\Program Files\Common Files\VCClient\Version.txt
C:\Program Files\Common Files\VCClient\temp.txt
C:\Program Files\Common Files\VCClient

Adware.ClickSpring/Yazzle
C:\Program Files\Cowabanga\License.txt
C:\Program Files\Cowabanga

Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#zip [ {79702dfb-cde5-434a-96aa-9b2e975e6e3e} ]

Edited by bunny298, 07 March 2008 - 06:30 PM.

  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello bunny298

Welcome to G2Go. :)
=====================
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thank you for replying. here are the two logs

Deckard's System Scanner v20071014.68
Run by Teri on 2008-03-11 12:20:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
17: 2008-03-11 16:20:56 UTC - RP469 - Deckard's System Scanner Restore Point
16: 2008-03-10 17:39:21 UTC - RP468 - System Checkpoint
15: 2008-03-09 17:27:20 UTC - RP467 - System Checkpoint
14: 2008-03-08 16:49:36 UTC - RP466 - System Checkpoint
13: 2008-03-07 13:03:42 UTC - RP465 - System Checkpoint


-- First Restore Point --
1: 2008-02-25 17:15:38 UTC - RP453 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 191 MiB (512 MiB recommended).
System Drive C: has 1.25 GiB (less than 15%) free.


-- HijackThis (run as Teri.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:02, on 2008-03-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\WINDOWS1\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\fxssvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\Teri\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Teri.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS1\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com...p/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/...erInstaller.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1167442701283
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://games.bellsou...bugs/axhost.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: VolumeRunOnce - {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS1\system32\HPZipm12.exe

--
End of file - 7154 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 ASPIXNT - c:\windows1\system32\drivers\aspixnt.sys <Not Verified; LSI Logic; LSI ASPI Extensions for Windows NT>
R2 MCSTRM - c:\windows1\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>

S1 InCDPass - c:\windows1\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows1\system32\drivers\incdrm.sys (file missing)
S3 iAimTV2 - c:\windows1\system32\drivers\watv03nt.sys (file missing)
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S4 InCDFs (InCD File System) - c:\windows1\system32\drivers\incdfs.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E965-E325-11CE-BFC1-08002BE10318}
Description: CD-ROM Drive
Device ID: IDE\CDROMSONY_!_!_CE-RW!_CRY230ED!_______________4YS1____\5&23A79097&0&0.0.0
Manufacturer: (Standard CD-ROM drives)
Name: SONY ! ! CE-RW! CRY230ED!
PNP Device ID: IDE\CDROMSONY_!_!_CE-RW!_CRY230ED!_______________4YS1____\5&23A79097&0&0.0.0
Service: cdrom


-- Scheduled Tasks -------------------------------------------------------------

2008-03-07 12:10:36 284 --a------ C:\WINDOWS1\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-02-11 and 2008-03-11 -----------------------------

2008-03-08 16:22:29 0 dr-h----- C:\Documents and Settings\Teri\Recent
2008-03-08 14:39:00 0 d-------- C:\Documents and Settings\Teri\Application Data\SecondLife
2008-03-08 14:36:55 0 d-------- C:\Program Files\SecondLife
2008-03-06 16:03:33 0 d-------- C:\Program Files\Trend Micro
2008-03-05 03:26:41 8576 --a------ C:\WINDOWS1\system32\drivers\amhhmeydnhml.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-03-05 02:46:25 8576 --a------ C:\WINDOWS1\system32\drivers\tirvitovqkjf.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-03-05 02:17:38 0 d-------- C:\WINDOWS1\system32\ActiveScan
2008-03-05 00:15:03 0 d-------- C:\WINDOWS1\system32\Kaspersky Lab
2008-03-04 16:41:17 0 d-------- C:\Documents and Settings\Teri\Application Data\Grisoft
2008-03-04 10:59:20 0 d-------- C:\Documents and Settings\Teri\Application Data\TrojanHunter
2008-03-04 04:52:17 11254 --a------ C:\WINDOWS1\system32\locate.com
2008-03-04 04:49:10 0 d-------- C:\MGtools
2008-03-04 04:01:50 68096 --a------ C:\WINDOWS1\system32\zip.exe
2008-03-04 04:01:50 98816 --a------ C:\WINDOWS1\system32\sed.exe
2008-03-04 04:01:50 80412 --a------ C:\WINDOWS1\system32\grep.exe
2008-03-04 04:01:50 73728 --a------ C:\WINDOWS1\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-04 03:51:01 0 d-------- C:\Program Files\CCleaner
2008-03-04 01:00:23 0 d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Spybot - Search & Destroy
2008-03-03 22:00:44 0 d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\SUPERAntiSpyware.com
2008-03-03 21:59:51 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-03 21:59:49 0 d-------- C:\Documents and Settings\Teri\Application Data\SUPERAntiSpyware.com
2008-03-03 21:57:41 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-03 21:55:34 1238736 --a------ C:\MGtools.exe
2008-03-03 19:33:30 0 d-------- C:\Documents and Settings\Teri\Application Data\WinRAR
2008-03-03 19:22:46 9952 --a------ C:\regxpcom.exe
2008-03-03 19:22:44 0 d-------- C:\Program Files\FBrowsingAdvisor
2008-03-03 19:22:41 0 d-------- C:\Program Files\FBrowserAdvisor
2008-02-23 16:11:56 0 d-------- C:\WINDOWS1\Cache
2008-02-23 16:11:51 0 d-------- C:\Program Files\Coupons
2008-02-22 12:48:19 0 d-------- C:\Program Files\iPod
2008-02-22 12:46:58 0 d-------- C:\Program Files\iTunes
2008-02-22 12:41:14 0 d-------- C:\Program Files\QuickTime
2008-02-15 16:11:50 0 d-------- C:\WINDOWS1\system32\FxsTmp


-- Find3M Report ---------------------------------------------------------------

2008-01-26 17:05:40 0 d-------- C:\Program Files\Bonjour


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-21 05:08]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13]
"MSConfig"="C:\WINDOWS1\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-08-04 02:56]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS1\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"VolumeRunOnce"= {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^ WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\ WinCinema Manager.lnk
backup=C:\WINDOWS1\pss\ WinCinema Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS1\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS1\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS1\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS1\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS1\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS1\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^PalStart.lnk]
path=C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup\PalStart.lnk
backup=C:\WINDOWS1\pss\PalStart.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free]
"C:\Program Files\DriveCleaner Free\UDC.exe" /min

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS1\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet




-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8002 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-03-11 12:25:14 ------------





Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel Pentium III processor
Percentage of Memory in Use: 74%
Physical Memory (total/avail): 190.3 MiB / 48.25 MiB
Pagefile Memory (total/avail): 466.06 MiB / 267.55 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1942.39 MiB

A: is Removable (No Media)
C: is Fixed (FAT32) - 13.97 GiB total, 1.25 GiB free.
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - QUANTUM FIREBALLlct15 15 - 13.99 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 13.99 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AntivirusOverride is set.

AV: AVG 7.5.518 v7.5.518 (Grisoft)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk 9.0"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe:*:Disabled:AC3 audio (ac3)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS1\\System32\\FXSCLNT.exe"="C:\\WINDOWS1\\System32\\FXSCLNT.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS1
APPDATA=C:\Documents and Settings\Teri\Application Data
BLASTER=A220 I7 D1 H7 P330 T6
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=XYZ-ZRMYEAV1VOK
ComSpec=C:\WINDOWS1\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Teri
LOGONSERVER=\\XYZ-ZRMYEAV1VOK
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS1\system32;C:\WINDOWS1;C:\WINDOWS1\system32\wbem;C:\Program Files\QuickTime\QTSystem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0803
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SBPCI=C:\SBPCI
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS1
TEMP=C:\DOCUME~1\Teri\LOCALS~1\Temp
TMP=C:\DOCUME~1\Teri\LOCALS~1\Temp
USERDOMAIN=XYZ-ZRMYEAV1VOK
USERNAME=Teri
USERPROFILE=C:\Documents and Settings\Teri
windir=C:\WINDOWS1


-- User Profiles ---------------------------------------------------------------

Teri (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS1\IsUninst.exe -fC:\WINDOWS1\USBUnins.isu
--> C:\WINDOWS1\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS1\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS1\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS1\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS1\UNRecode.exe /UNINSTALL
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS1\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX --> C:\WINDOWS1\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Adobe Shockwave Player --> C:\WINDOWS1\system32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINDOWS1\system32\MACROMED\SHOCKW~1\Install.log
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
AVG Free Edition --> C:\Program Files\Grisoft\AVG Free\setup.exe /UNINSTALL
BellSouth® Internet Services Dialer --> C:\PROGRA~1\BELLSO~1\DIALER\UNWISE.EXE C:\PROGRA~1\BELLSO~1\DIALER\INSTALL.LOG
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
dBpowerAMP --> "C:\WINDOWS1\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS1\system32\SpoonUninstall-dBpowerAMP.dat
FBrowsingAdvisor --> "C:\Program Files\FBrowsingAdvisor\unins000.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS1\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hoyle Solitaire & Mah Jong Tiles --> C:\WINDOWS1\IsUninst.exe -fC:\SIERRA\SOLTILES\Uninst.isu
HP Image Zone 4.2 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 4.2 --> "C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
HP Software Update --> MsiExec.exe /X{457791C5-D702-4143-A7B2-2744BE9573F2}
Intel® Create & Share™ Software --> C:\WINDOWS1\IsUninst.exe -f"C:\Program Files\Intel\Createshare\program\CKUninst.isu"
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 8 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LimeWire 4.14.10 --> "C:\Program Files\LimeWire\uninstall.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS1\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Picture It! Express 2000 --> MsiExec.exe /I{A586D09E-1D2C-11D3-9A6B-00105A98B681}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS1\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Word 2000 --> MsiExec.exe /I{00170409-78E1-11D2-B60F-006097C998E7}
Microsoft Works 2000 --> MsiExec.exe /I{56364334-9530-11D2-BFFC-00C04FA329AA}
Nero 7 Demo --> MsiExec.exe /I{84B2CF01-194D-2284-B313-F2E0D78D1033}
PaltalkScene --> "C:\WINDOWS\Paltalk Messenger\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml"
Panda ActiveScan --> C:\WINDOWS1\system32\ASUninst.exe Panda ActiveScan
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Reality Fusion VarietyPack --> C:\WINDOWS1\IsUninst.exe -f"C:\Program Files\Intel\Createshare\program\Reality Fusion VarietyPack\Uninst.isu"
SecondLife (remove only) --> "C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Windows Media Format 11 runtime --> "C:\WINDOWS1\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Word in Works Suite add-in --> MsiExec.exe /I{0DB93918-2A77-11D3-805A-00C04FA329AA}
Yahoo! Browser Services --> C:\PROGRA~1\YAHOO!\COMMON\unyext.exe
Yahoo! Install Manager --> C:\WINDOWS1\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\WINDOWS1\system32\regsvr32 /u /s C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll
Yahoo! Messenger --> C:\PROGRA~1\YAHOO!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG
Yahoo! Photos Easy Upload Tool --> C:\Program Files\Yahoo!\Common\ydropper_uninst.exe /ylog=C:\PROGRA~1\YAHOO!\PHOTOS\UPLOADER\install.log
Yahoo! Photos Print-at-Home Tool --> C:\WINDOWS1\unins000.exe
Yahoo! Toolbar --> C:\PROGRA~1\YAHOO!\COMMON\UNYT.EXE


-- Application Event Log -------------------------------------------------------

Event Record #/Type1640 / Error
Event Submitted/Written: 03/10/2008 11:05:48 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application paltalk.exe, version 9.91.2725.0, faulting module paltalk.exe, version 9.91.2725.0, fault address 0x0004b403.
Processing media-specific event for [paltalk.exe!ws!]

Event Record #/Type1626 / Error
Event Submitted/Written: 03/07/2008 03:20:28 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application paltalk.exe, version 9.91.2725.0, faulting module webvideo.dll, version 1.2.2725.0, fault address 0x00010c93.
Processing media-specific event for [paltalk.exe!ws!]

Event Record #/Type1591 / Warning
Event Submitted/Written: 03/05/2008 02:58:37 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type1585 / Error
Event Submitted/Written: 03/04/2008 08:27:35 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16608, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type1579 / Warning
Event Submitted/Written: 03/04/2008 08:16:46 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type11019 / Error
Event Submitted/Written: 03/10/2008 11:25:48 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The AVG Anti-Spyware Guard service terminated unexpectedly. It has done this 1 time(s).

Event Record #/Type11003 / Error
Event Submitted/Written: 03/10/2008 11:13:30 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Windows Time service terminated with the following error:
%%126

Event Record #/Type10983 / Error
Event Submitted/Written: 03/08/2008 04:20:36 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Windows Time service terminated with the following error:
%%126

Event Record #/Type10964 / Error
Event Submitted/Written: 03/08/2008 04:09:47 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Windows Time service terminated with the following error:
%%126

Event Record #/Type10951 / Error
Event Submitted/Written: 03/08/2008 03:04:53 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Security Center service terminated with the following error:
%%16389



-- End of Deckard's System Scanner: finished at 2008-03-11 12:25:14 ------------
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Go ahead and uninstall AVG antispyware.

Then:
Make sure that you paste the following file paths under the yellow bar within the OTMoveit2 program or it will not work correctly.


Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\Coupons
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\VolumeRunOnce
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free
    C:\Program Files\DriveCleaner Free

  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
======================
Then::
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
  • 0

#5
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thank you. I have done what you asked. Here is the first log

[Custom Input]
< C:\Program Files\Coupons >
C:\Program Files\Coupons moved successfully.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\VolumeRunOnce >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\VolumeRunOnce deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free\\ deleted successfully.
< C:\Program Files\DriveCleaner Free >
File/Folder C:\Program Files\DriveCleaner Free not found.

OTMoveIt2 v1.0.21 log created on 03122008_015056


and here is the log for Malwarebytes

Malwarebytes' Anti-Malware 1.08
Database version: 480

Scan type: Full Scan (C:\|)
Objects scanned: 108129
Time elapsed: 1 hour(s), 5 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\contextprogram.precachebrowserhost (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\contextprogram.precachebrowserhost.1 (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4c1aff62-c4fb-dc22-f1dd-20f26a27ec12} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\contextprogram.browserwatcher (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\contextprogram.browserwatcher.1 (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{926ea0f6-080a-0778-9569-cac35c7f03b8} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\contextprogram.pornpro_bho (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\contextprogram.pornpro_bho.1 (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e4d1d56c-3ec9-2f5d-faa3-4112ccdd61dc} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{018fe159-4a56-8237-0211-989634717eb4} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2f560603-a26f-c7e9-5e30-08dba79699c4} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bf798913-adc2-4304-2b4e-876f60917aab} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{9f009604-ac89-957d-19a5-5815b478e169} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{e2010c89-dc4c-e7bf-aa56-e826b40072a0} (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\ContextProgram (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\PlayMP3 (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ContextProgram.DLL (AdWare.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fbrowsingadvisor_is1 (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowserAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.

Files Infected:
C:\regxpcom.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\XPCOMEvents.dll (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP462\A0061537.dll (AdWare.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP460\A0060442.dll (AdWare.Agent) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\unins000.dat (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\main.db (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\Logo.png (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\unins000.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please go HERE to run Panda's TotalScan
  • Select the bubble for Full scan
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • Then the scan will begin
  • When the scan completes, click the Save button on the right of Scan details
  • Save it to a convenient location. Post the contents of the TotalScan report

  • 0

#7
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Here is the log from Panda

;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-03-12 14:33:30
PROTECTIONS: 1
MALWARE: 15
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
AVG 7.5.518 7.5.518 Yes Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00145599 Adware/SAHAgent Adware No 0 Yes No C:\WINDOWS\Downloaded Program Files\setup4002b.ini
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\FOUND.007\FILE0004.CHK
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\FOUND.007\FILE0000.CHK
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][2].txt
00237282 Adware/Deskwizz Adware No 0 No No C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP463\A0062726.EXE[DH.dll]
00256508 Spyware/SurfSideKick Spyware No 1 Yes No C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP461\A0060458.EXE
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Teri\Cookies\[email protected][1].txt
00446053 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP463\A0062726.EXE
00680377 Adware/Vog Adware No 1 No No C:\WINDOWS\DHU.exe[DHTool.exe]
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP462\A0061488.EXE
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{3E54D4BA-E6E1-4BB3-85DE-30D35D571DBF}\RP462\A0061479.EXE
;===============================================================================
=================================================================================
===================
SUSPECTS
Location
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\DHU.exe
    C:\FOUND.007
    C:\WINDOWS\Downloaded Program Files\setup4002b.ini
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
==========
Please post a new Hijackthis log please.
  • 0

#9
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Ok here it is

C:\WINDOWS\DHU.exe moved successfully.
C:\FOUND.007 moved successfully.
C:\WINDOWS\Downloaded Program Files\setup4002b.ini moved successfully.

OTMoveIt2 v1.0.21 log created on 03132008_012212
  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please re-open Hijackthis and click on "Do a system scan only"
Then place a check mark next to this entry below:

O21 - SSODL: VolumeRunOnce - {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll (file missing)

Now click on Fix Checked and then close Hijackthis.
========================
Download the HostsXpert 4.2 - Hosts File Manager Here
Unzip HostsXpert 4.2 - Hosts File Manager to your desktop

Open up the HostsXpert 4.2 - Hosts File Manager program.
  • Click on Make Writable at the top left hand corner.
  • Then click on Restore MS Hosts File
  • then click on Make Host File read only
  • close program
=============================
Cleanup::
  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

Please then delete\uninstall anything else that we have used.

=================================
After that please update your Java:
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Ugrading Java:After that
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
====================================
Then I will need you to reset your System Restore points, please note that you will need to log into your computer with an account which has full administrator access.
You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
1. Turn off System Restore.
Click on *Start
Right-click *My Computer
Click *Properties
Click the *System Restore tab
Check *Turn off System Restore
Click *Apply, and then click *OK.

2. Reboot.

3. Turn ON System Restore.
Click on *Start
Right-click *My Computer
Click *Properties
*UN-Check *Turn off System Restore*
Check *Turn on System Restore
Click *Apply, and then click *OK.


How to Turn On and Turn Off System Restore in Windows XP
http://support.micro...kb/310405/en-us
=====================================================================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#11
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thank you, I did as you asked, but where you said to do the hijack and the O21 - SSODL: VolumeRunOnce - {a56e2296-ed7d-4325-8d34-2f46bc29edf2} - C:\WINDOWS1\Installer\{a56e2296-ed7d-4325-8d34-2f46bc29edf2}\VolumeRunOnce.dll (file missing) it wasnt there. So I continued on with the rest of your suggestions. I still have one more question. How do I get my clock on the tray bottom right hand corner, to go back to regular time instead of 24 hour clock?

Edited by bunny298, 13 March 2008 - 06:59 PM.

  • 0

#12
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Go to Start >Control Panel >Date ,Time and regional settings.
Click on Regional and language options.
Next to the section that says your regional language (mine is English) click on customise.
Click on the Time tab at the top.
The next to time format make sure that it looks like this >h:mm:ss tt if it doesn't then change it to that.
Then click apply then ok.
Then apply then ok again and you should be good to go. :)

Let me know if that takes care of it?
==========================
It is fine about the entry in Hijackthis.
  • 0

#13
bunny298

bunny298

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
THANK YOU THANK YOU THANK YOU.... You are the best!!!!!!!!!!!!!!!!!!!!!!!!!....
I recommend you to anyone I know that has issues with their pcs.
Many thanks and blessings to you.
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#15
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP