Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I can't rid my pc of the"antispywareupdates.net virus" [


  • This topic is locked This topic is locked

#16
littlebull_25

littlebull_25

    Member

  • Member
  • PipPipPip
  • 610 posts
Hello Gregorious,

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.


F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleaner\registrycleaner2008.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\rtelelibu.html


Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
Reboot into safe mode.

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\RegistryCleaner\registrycleaner2008.exe
    C:\Program Files\Windows Media Player\rtelelibu.html
    C:\WINDOWS\system32\WS2Fix.exe
    C:\WINDOWS\system32\VCCLSID.exe 
    C:\WINDOWS\system32\dumphive.exe
    C:\WINDOWS\system32\Process.exe 
    C:\WINDOWS\system32\SrchSTS.exe 
    C:\WINDOWS\system32\VACFix.exe 
    C:\WINDOWS\system32\IEDFix.exe
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

[*]Close all other windows before proceeding.
[*]Double-click on dss.exe and follow the prompts.
[*]When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.[/list]
Post a new hjt log.

Please post back with OTMoveIt results, main.txt and extra.txt, and a new hjt log.
  • 0

Advertisements


#17
gregorious

gregorious

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
File/Folder C:\Program Files\RegistryCleaner\registrycleaner2008.exe not found.
File/Folder C:\Program Files\Windows Media Player\rtelelibu.html not found.
C:\WINDOWS\system32\WS2Fix.exe moved successfully.
C:\WINDOWS\system32\VCCLSID.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\VACFix.exe moved successfully.
C:\WINDOWS\system32\IEDFix.exe moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03312008_125319
Deckard's System Scanner v20071014.68
Run by Greg on 2008-03-31 13:22:42
Computer is in Safe Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 254 MiB (512 MiB recommended).


-- HijackThis (run as Greg.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:22:54 PM, on 3/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Greg\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://coldwellnsmk...ing/ieatgpc.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 7932 bytes

-- Files created between 2008-02-29 and 2008-03-31 -----------------------------

2008-03-30 17:22:43 0 d-------- C:\Program Files\Citrix
2008-03-28 12:22:00 1906 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-26 15:34:17 0 d-------- C:\Documents and Settings\Greg\Application Data\Malwarebytes
2008-03-26 15:33:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-26 15:33:51 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-25 17:27:15 0 d-------- C:\WINDOWS\ERUNT
2008-03-22 23:59:51 0 dr-h----- C:\$VAULT$.AVG
2008-03-22 22:49:01 0 d-------- C:\Documents and Settings\Greg\Application Data\AVG7
2008-03-22 22:48:22 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-22 22:47:39 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-22 19:17:58 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-22 19:12:54 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-22 19:12:54 0 d-------- C:\Documents and Settings\Greg\Application Data\SUPERAntiSpyware.com
2008-03-22 19:11:55 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-22 12:39:18 0 d-------- C:\Documents and Settings\Greg\Application Data\Grisoft
2008-03-22 12:38:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-19 23:30:19 0 d-------- C:\Program Files\Enigma Software Group
2008-03-19 12:11:39 0 d-------- C:\Program Files\ACW
2008-03-19 09:57:50 0 d--h----- C:\WINDOWS\PIF
2008-03-19 09:07:01 0 d-------- C:\Documents and Settings\Greg\Application Data\HouseCall 6.6
2008-03-17 10:14:27 0 d-------- C:\54ee06f03b176c86f2272e296e
2008-03-16 21:22:25 0 d-------- C:\WINDOWS\system32\??stem
2008-03-16 21:21:58 0 d-------- C:\WINDOWS\F?nts


-- Find3M Report ---------------------------------------------------------------

2008-03-22 19:11:55 0 d-------- C:\Program Files\Common Files
2008-03-22 18:16:10 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-22 09:16:03 0 d-------- C:\Program Files\Trend Micro
2008-03-17 19:55:17 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-14 00:16:28 0 d-------- C:\Program Files\Lavasoft


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/24/2005 12:22 AM]
"PicasaNet"="C:\Program Files\Hello\Hello.exe" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/22/2005 12:48 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/22/2005 12:44 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [09/20/2005 11:06 AM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [06/21/2006 01:14 PM]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [12/14/2004 02:12 AM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 06:32 PM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [06/08/2005 04:24 PM]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [06/08/2005 04:14 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 05:25 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [03/22/2008 10:52 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [06/08/2005 03:44 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]

C:\Documents and Settings\Greg\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 7:16:50 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [9/16/2006 5:48:16 PM]
dlbcserv.lnk - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe [9/17/2005 6:32:56 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,




-- End of Deckard's System Scanner: finished at 2008-03-31 13:23:25 ------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:34:10 PM, on 3/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://coldwellnsmk...ing/ieatgpc.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 8957 bytes
DSS only opened one notepad. Greg.
  • 0

#18
gregorious

gregorious

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Hi, haven't heard from you in a few days. Things are looking much better (no pop ups I can recall & no unauthorized searches) but I still have a blue tint on all of my icons. Any response will be greatly appreciated. Greg.
  • 0

#19
littlebull_25

littlebull_25

    Member

  • Member
  • PipPipPip
  • 610 posts
Hello Gregorious,

There maybe a delay between my posts as I am in training and have to have my fix checked by one of our experts before I can post it.

Open notepad and copy/paste the text in the quotebox below into it:

DirLook::
C:\54ee06f03b176c86f2272e296e



Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt" which I will need in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post back with ComboFix.txt.
  • 0

#20
gregorious

gregorious

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Where do I get the combofix from??? I don't have that. Greg
  • 0

#21
gregorious

gregorious

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
It's cool. I downloaded it from another post on the site.

ComboFix 08-04-04.1 - Greg 2008-04-05 13:43:15.1 - NTFSx86
Running from: C:\Documents and Settings\Greg\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Greg\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\fnts~1
C:\WINDOWS\system32\stem~1

.
((((((((((((((((((((((((( Files Created from 2008-03-05 to 2008-04-05 )))))))))))))))))))))))))))))))
.

2008-04-04 14:00 . 2007-10-24 01:47 282,112 --a------ C:\WINDOWS\system32\TBDB0.tmp
2008-03-31 12:53 . 2008-03-31 12:53 <DIR> d-------- C:\_OTMoveIt
2008-03-30 17:22 . 2008-03-30 17:22 <DIR> d-------- C:\Program Files\Citrix
2008-03-28 12:47 . 2008-03-28 12:47 <DIR> d-------- C:\Deckard
2008-03-28 12:22 . 2008-03-28 12:22 1,906 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-26 15:34 . 2008-03-26 15:34 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\Malwarebytes
2008-03-26 15:33 . 2008-03-26 15:33 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-26 15:33 . 2008-03-26 15:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-25 17:27 . 2008-03-25 17:27 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-25 17:00 . 2008-03-25 18:22 <DIR> d-------- C:\SDFix
2008-03-22 22:49 . 2008-04-05 08:00 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\AVG7
2008-03-22 22:48 . 2008-03-22 22:48 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-22 22:47 . 2008-03-22 22:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-22 19:17 . 2008-03-22 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-22 19:12 . 2008-04-04 11:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-22 19:12 . 2008-03-22 19:12 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\SUPERAntiSpyware.com
2008-03-22 19:11 . 2008-03-22 19:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-22 12:39 . 2008-03-22 12:39 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\Grisoft
2008-03-22 12:38 . 2008-03-22 22:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-22 12:38 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-19 23:30 . 2008-03-19 23:30 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-19 12:11 . 2008-03-19 12:11 <DIR> d-------- C:\Program Files\ACW
2008-03-19 09:57 . 2008-03-19 09:57 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-19 09:07 . 2008-03-19 09:34 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\HouseCall 6.6
2008-03-17 00:26 . 2008-03-17 00:26 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-03-16 00:46 . 2008-03-27 23:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-16 00:46 . 2008-03-16 00:46 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 11:23 . 2004-08-04 00:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 16:29 --------- d-----w C:\Program Files\Jasc Software Inc
2008-04-05 16:17 --------- d-----w C:\Documents and Settings\Greg\Application Data\Jasc Software Inc
2008-03-22 13:16 --------- d-----w C:\Program Files\Trend Micro
2008-03-20 22:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-17 23:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-14 04:16 --------- d-----w C:\Program Files\Lavasoft
2008-02-14 04:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2005-09-01 16:36 0 ---ha-w C:\Documents and Settings\Greg\Application Data\hpothb07.dat
2005-07-08 18:26 164 ---ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-07-08 18:26 0 ---ha-w C:\Documents and Settings\Stacy\hpothb07.dat
2005-07-08 18:26 0 ---ha-w C:\Documents and Settings\NetworkService\hpothb07.dat
2005-07-08 18:26 0 ---ha-w C:\Documents and Settings\LocalService\hpothb07.dat
2005-07-08 18:26 0 ---ha-w C:\Documents and Settings\Greg\hpothb07.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\54ee06f03b176c86f2272e296e ----

2008-03-17 10:14 788 --ah----- C:\54ee06f03b176c86f2272e296e\$shtdwn$.req
2007-11-07 16:32 63488 --a------ C:\54ee06f03b176c86f2272e296e\vs_setup.msi
2007-11-07 16:26 982008 --a------ C:\54ee06f03b176c86f2272e296e\WapUI.dll
2007-11-07 16:26 97280 --a------ C:\54ee06f03b176c86f2272e296e\DeleteTemp.exe
2007-11-07 16:26 96768 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1041.dll
2007-11-07 16:26 95736 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1041.dll
2007-11-07 16:26 93696 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1042.dll
2007-11-07 16:26 92664 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1042.dll
2007-11-07 16:26 90104 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1028.dll
2007-11-07 16:26 89080 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.2052.dll
2007-11-07 16:26 84992 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1028.dll
2007-11-07 16:26 83456 --a------ C:\54ee06f03b176c86f2272e296e\setupres.2052.dll
2007-11-07 16:26 687104 --a------ C:\54ee06f03b176c86f2272e296e\VSScenario.dll
2007-11-07 16:26 627712 --a------ C:\54ee06f03b176c86f2272e296e\VS70UIMgr.dll
2007-11-07 16:26 411136 --a------ C:\54ee06f03b176c86f2272e296e\VSBaseReqs.dll
2007-11-07 16:26 276472 --a------ C:\54ee06f03b176c86f2272e296e\dlmgr.dll
2007-11-07 16:26 269304 --a------ C:\54ee06f03b176c86f2272e296e\Setup.EXE
2007-11-07 16:26 177152 --a------ C:\54ee06f03b176c86f2272e296e\HtmlLite.dll
2007-11-07 16:26 1361920 --a------ C:\54ee06f03b176c86f2272e296e\SitSetup.DLL
2007-11-07 16:26 136192 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1032.dll
2007-11-07 16:26 132096 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1036.dll
2007-11-07 16:26 131072 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1038.dll
2007-11-07 16:26 130560 --a------ C:\54ee06f03b176c86f2272e296e\setupres.3082.dll
2007-11-07 16:26 130048 --a------ C:\54ee06f03b176c86f2272e296e\setupres.2070.dll
2007-11-07 16:26 129536 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1031.dll
2007-11-07 16:26 127488 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1043.dll
2007-11-07 16:26 127488 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1040.dll
2007-11-07 16:26 126976 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1045.dll
2007-11-07 16:26 125440 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1030.dll
2007-11-07 16:26 124416 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1029.dll
2007-11-07 16:26 122368 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1049.dll
2007-11-07 16:26 121856 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1046.dll
2007-11-07 16:26 120832 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1035.dll
2007-11-07 16:26 120320 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1053.dll
2007-11-07 16:26 120320 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1044.dll
2007-11-07 16:26 119808 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1055.dll
2007-11-07 16:26 113656 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1032.dll
2007-11-07 16:26 112128 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1025.dll
2007-11-07 16:26 112120 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1036.dll
2007-11-07 16:26 111608 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1031.dll
2007-11-07 16:26 111096 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.3082.dll
2007-11-07 16:26 111096 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1038.dll
2007-11-07 16:26 110080 --a------ C:\54ee06f03b176c86f2272e296e\setupres.1037.dll
2007-11-07 16:26 110072 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.2070.dll
2007-11-07 16:26 110072 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1040.dll
2007-11-07 16:26 109568 --a------ C:\54ee06f03b176c86f2272e296e\setupres.dll
2007-11-07 16:26 109048 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1045.dll
2007-11-07 16:26 108536 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1043.dll
2007-11-07 16:26 108536 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1030.dll
2007-11-07 16:26 108536 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1029.dll
2007-11-07 16:26 107512 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.dll
2007-11-07 16:26 107512 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1046.dll
2007-11-07 16:26 107000 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1049.dll
2007-11-07 16:26 106488 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1055.dll
2007-11-07 16:26 106488 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1044.dll
2007-11-07 16:26 106488 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1035.dll
2007-11-07 16:26 105976 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1053.dll
2007-11-07 16:26 1059328 --a------ C:\54ee06f03b176c86f2272e296e\GenComp.dll
2007-11-07 16:26 1045504 --a------ C:\54ee06f03b176c86f2272e296e\VS_Setup.dll
2007-11-07 16:26 102904 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1025.dll
2007-11-07 16:26 101368 --a------ C:\54ee06f03b176c86f2272e296e\WapRes.1037.dll
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.3082.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.2070.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.2052.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1055.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1053.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1049.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1046.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1045.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1044.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1043.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1042.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1041.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1040.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1038.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1037.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1036.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1035.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1032.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1031.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1030.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1029.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1028.ini
2007-11-07 16:21 1178 --a------ C:\54ee06f03b176c86f2272e296e\locdata.1025.ini
2007-11-07 16:20 9452 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1037.RTF
2007-11-07 16:20 792 --a------ C:\54ee06f03b176c86f2272e296e\DefFactory.DAT
2007-11-07 16:20 7650 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1028.RTF
2007-11-07 16:20 7222 --a------ C:\54ee06f03b176c86f2272e296e\EULA.2052.RTF
2007-11-07 16:20 5584 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1038.RTF
2007-11-07 16:20 5208 --a------ C:\54ee06f03b176c86f2272e296e\logo.bmp
2007-11-07 16:20 5151 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1045.RTF
2007-11-07 16:20 5127 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1029.RTF
2007-11-07 16:20 4916 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1055.RTF
2007-11-07 16:20 4733 --a------ C:\54ee06f03b176c86f2272e296e\EULA.2070.RTF
2007-11-07 16:20 4731 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1036.RTF
2007-11-07 16:20 4708 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1040.RTF
2007-11-07 16:20 4676 --a------ C:\54ee06f03b176c86f2272e296e\EULA.3082.RTF
2007-11-07 16:20 4669 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1031.RTF
2007-11-07 16:20 4657 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1046.RTF
2007-11-07 16:20 4402 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1035.RTF
2007-11-07 16:20 4355 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1043.RTF
2007-11-07 16:20 4164 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1030.RTF
2007-11-07 16:20 4127 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1053.RTF
2007-11-07 16:20 3968 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1044.RTF
2007-11-07 16:20 3784 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1033.RTF
2007-11-07 16:20 24298 --a------ C:\54ee06f03b176c86f2272e296e\Setup.SDB
2007-11-07 16:20 15970 --a------ C:\54ee06f03b176c86f2272e296e\BaseLine.DAT
2007-11-07 16:20 15036 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1049.RTF
2007-11-07 16:20 14453 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1032.RTF
2007-11-07 16:20 1438 --a------ C:\54ee06f03b176c86f2272e296e\VS_Setup.PDI
2007-11-07 16:20 13170 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1041.RTF
2007-11-07 16:20 1178 --a------ C:\54ee06f03b176c86f2272e296e\LocData.INI
2007-11-07 16:20 11126 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1025.RTF
2007-11-07 16:20 10040 --a------ C:\54ee06f03b176c86f2272e296e\EULA.1042.RTF
2007-11-07 15:12 2533376 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\winforms.msp
2007-11-07 15:07 999936 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\prexp.msp
2007-11-07 15:02 6473216 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\NetFX_Other.msp
2007-11-07 15:00 3407360 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\NetFX_Core.msp
2007-11-07 14:58 908800 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\NetFX_CA.msp
2007-11-07 14:56 553472 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\dw.msp
2007-11-07 14:54 507392 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\crt.msp
2007-11-07 14:50 6055936 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\clr.msp
2007-11-07 14:46 3010560 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\ASPNET.msp
2007-11-07 14:43 91136 --a------ C:\54ee06f03b176c86f2272e296e\wcu\dotNetFramework\dotNetFX20\Netfx20a_x86.msi


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 15:44 196608]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-24 00:22 98304]
"PicasaNet"="C:\Program Files\Hello\Hello.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-22 00:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-22 00:44 126976]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-09-20 11:06 1397760]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 13:14 35328]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 18:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 16:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 16:14 217088]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-22 22:52 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-22 22:48 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-09-16 17:48:16 25214]
dlbcserv.lnk - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe [2005-09-17 18:32:56 315392]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= lvcodec2.dll
"MSVideo"= vfwwdm32.dll
"MSVideo8"= VfWWDM32.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=

S3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-04-13 16:31]
S3 ZD1211U(Linksys);Linksys Wireless-G USB Network Adapter Driver(Linksys);C:\WINDOWS\system32\DRIVERS\zd1211u.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-04-05 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-05 13:50:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [3816]

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-05 13:54:15
ComboFix-quarantined-files.txt 2008-04-05 17:53:57
Pre-Run: 20,889,239,552 bytes free
Post-Run: 20,874,674,176 bytes free
.
2008-03-19 19:22:31 --- E O F ---
  • 0

#22
littlebull_25

littlebull_25

    Member

  • Member
  • PipPipPip
  • 610 posts
Hello Gregorious,

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Please post back with kaspersky results, and a new hjt log.
  • 0

#23
gregorious

gregorious

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
KASPERSKY ONLINE SCANNER REPORT
Sunday, April 06, 2008 9:15:16 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/04/2008
Kaspersky Anti-Virus database records: 685825


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 59952
Number of viruses found 1
Number of infected objects 4
Number of suspicious objects 0
Duration of the scan process 01:34:50

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\Greg\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped

C:\Documents and Settings\Greg\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Greg\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Greg\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Greg\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Greg\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped

C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Temp\AVP10C.tmp Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Temp\AVP10D.tmp Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Temp\~DF4BD1.tmp Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Temp\~DF4BDC.tmp Object is locked skipped

C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Greg\ntuser.dat Object is locked skipped

C:\Documents and Settings\Greg\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Stacy\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0121950.exe Object is locked skipped

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP681\A0121982.exe Object is locked skipped

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\A0122033.exe Object is locked skipped

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\A0122039.exe Object is locked skipped

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP698\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:23:41 AM, on 4/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://coldwellnsmk...ing/ieatgpc.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 8640 bytes
  • 0

#24
littlebull_25

littlebull_25

    Member

  • Member
  • PipPipPip
  • 610 posts
Hello Gregorious,

Your logs look clean!

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image

  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

First, let's reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View tab.
* Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
* CHECK the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
Next, let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. Turn off System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Restart your computer.

3. Turn ON System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
[/list]System Restore will now be active again.

And then make sure to update your java it is very out of date, and probably how you got infected, older versions will leave your computer open for infection:

Updating Java and Clearing Cache
  • Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
  • It will say "Java Plug-in" under the icon.
    Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
  • If you are unable to update you can manually update by going here:
  • After the reboot, go back into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    Downloaded Applets
    Downloaded Applications
    Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
You should also have a good firewall. Here are 2 free ones available for personal use:and a good antivirus (these are also free for personal use):It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit monthly. And to keep your system clean run these free malware scanners
weekly, and be aware of what emails you open and websites you visit.

To learn more about how to protect yourself while on the internet read this article by Tony Klein: So how did I get infected in the first place?

Have a safe and happy computing day!
  • 0

#25
RiP

RiP

    Malware Expert

  • Retired Staff
  • 8,430 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP