Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Hijacker, Malware, Spyware Trojan has taken over my PC [RESOLVED]


  • This topic is locked This topic is locked

#1
Trainer12

Trainer12

    Member

  • Member
  • PipPip
  • 24 posts

My son has downloaded uBitorrent, and now he can't use Internet Explorer or any of the Microsoft Office Suite. Also, there remenants of an Anatomy and Physiology program called Our Body. I can't remove either of these programs let alone open up Control Panal and the Add/Remove pull down menu, to uninstall them.

I recently upgraded my hard drive from 40 to 160 G by cloning with Apticorn Easy GIG 2 and using Partition Majic. I have a Pentium 2392 with 1 G of RAM with Windows XP Home Edition with service Pack 2. I have ran through all of the steps you suggested. I have Grisoft AVG 7 and I can't upgrade to 8. There is something blocking it from downloading.

hIJACKER fILE,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:29 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\InCD\InCD\InCDsrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\WINDOWS\Web\aolservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
F:\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
F:\Apricorn\EZ Gig II\EZGigMonitor.exe
F:\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
F:\Apricorn\SMART-ER\SMART-ER.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Documents and Settings\Paul Roden\My Documents\PC's\HiJack This Scans\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
F:\Documents and Settings\Paul Roden\My Documents\PC's\HiJack This Scans\HiJacker Software\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://goggle.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EZGigMonitor.exe] F:\Apricorn\EZ Gig II\EZGigMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] F:\Apricorn\EZ Gig II\TimounterMonitor.exe
O4 - HKLM\..\Run: [Apricorn Scheduler Service] "C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMART-ER.lnk = F:\Apricorn\SMART-ER\SMART-ER.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.alter.net
O15 - Trusted Zone: http://www.alternet.org
O15 - Trusted Zone: http://maytag.custhelp.com
O15 - Trusted Zone: http://www.dailykos.com
O15 - Trusted Zone: http://www.dailyscare.com
O15 - Trusted Zone: http://www.democrats.org
O15 - Trusted Zone: http://www.dennis4president.com
O15 - Trusted Zone: http://*.eventful.com
O15 - Trusted Zone: http://www.everydayhealth.com
O15 - Trusted Zone: http://campaign.grisoft.com
O15 - Trusted Zone: http://www.kodak.com
O15 - Trusted Zone: http://www.kucinichtv.com
O15 - Trusted Zone: http://www.metrotimes.com
O15 - Trusted Zone: http://*.mylasalle.edu
O15 - Trusted Zone: http://home.myspace.com
O15 - Trusted Zone: http://*.pdamerica.org
O15 - Trusted Zone: http://www.sony.com
O15 - Trusted Zone: http://www.truthout.org
O15 - Trusted Zone: http://www.unionleader.com
O15 - Trusted Zone: http://blog.washingtonpost.com
O15 - Trusted Zone: http://paforkucinich.yahoogroups.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1201974964171
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://notes-srv1.la...e.edu/dwa7W.cab
O20 - Winlogon Notify: !SASWinLogon - F:\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apricorn Scheduler Service (AcrSch2Svc) - Apricorn - C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Services (AOL-SERVICE-v1) - Unknown owner - C:\WINDOWS\Web\aolservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - F:\InCD\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SMART-ER Service (SMART-ERService) - Apricorn - F:\Apricorn\SMART-ER\SMART-ER Service.exe

--
End of file - 11720 bytes


UNINSTALL LOG FILE:

Adobe Acrobat 7.0.9 Professional
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
AIM 6
AIMTunes
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
Apple Software Update
Apricorn EZ Gig II
AVG 7.5
Banctec Service Agreement
BJC-1000
Broadcom Management Programs
Conexant D850 56K V.9x DFVc Modem
Dell Driver Reset Tool
Dell Support
Desktop Doctor
Digital Line Detect
GdiplusUpgrade
HijackThis 1.99.1
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Extended Capabilities 6.1
HP Imaging Device Functions 6.1
HP Photosmart Essential
HP PSC & OfficeJet 6.1.A
HP Software Update
HP Solution Center and Imaging Support Tools 6.1
InCD
Intel® Extreme Graphics Driver
Internet Explorer Default Page
iTunes
Java™ 6 Update 3
LimeWire 4.16.2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows XP Video Decoder Checkup Utility
Mozilla Thunderbird (2.0.0.12)
Mozilla Thunderbird (2.0.0.6)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Musicmatch for Windows Media Player
Nero Digital
Nero Media Player
Nero OEM
Norton PartitionMagic 8.0
Online Documentation
Panda ActiveScan 2.0
QuickTime
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Shockwave
SMART-ER
SUPERAntiSpyware Free Edition
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Windows Defender Signatures
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781

Thanks, You guys and girls are the best!

Trainer12


  • 0

Advertisements


#2
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts

Hi Trainer12

welcome back to geekstogo smile.gif

i can see some malware in your logs which we will clear now, and we will also do a couple of scans to see what else is lurking on your machine. i will need to see those scans to fix the control panel issue.


====STEP 1====
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O15 - Trusted Zone: http://www.alter.net
O15 - Trusted Zone: http://www.alternet.org
O15 - Trusted Zone: http://maytag.custhelp.com
O15 - Trusted Zone: http://www.dailykos.com
O15 - Trusted Zone: http://www.dailyscare.com
O15 - Trusted Zone: http://www.democrats.org
O15 - Trusted Zone: http://www.dennis4president.com
O15 - Trusted Zone: http://*.eventful.com
O15 - Trusted Zone: http://www.everydayhealth.com
O15 - Trusted Zone: http://campaign.grisoft.com
O15 - Trusted Zone: http://www.kodak.com
O15 - Trusted Zone: http://www.kucinichtv.com
O15 - Trusted Zone: http://www.metrotimes.com
O15 - Trusted Zone: http://*.mylasalle.edu
O15 - Trusted Zone: http://home.myspace.com
O15 - Trusted Zone: http://*.pdamerica.org
O15 - Trusted Zone: http://www.sony.com
O15 - Trusted Zone: http://www.truthout.org
O15 - Trusted Zone: http://www.unionleader.com
O15 - Trusted Zone: http://blog.washingtonpost.com
O15 - Trusted Zone: http://paforkucinich.yahoogroups.com
O15 - Trusted Zone: http://www.youtube.com



Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


====STEP 2====
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


====STEP 3====
Please download Deckard's System Scanner (DSS) and save it to your Desktop.

  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

In your next reply could i see:
1. the malwarebytes log
2. the DSS logs

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk


  • 0

#3
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Andrewuk,

Malwarebytes' Anti-Malware 1.11
Database version: 658


Scan type: Full Scan (C:\|F:\|)
Objects scanned: 105705
Time elapsed: 53 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Deckard's System Scanner:

Deckard's System Scanner v20071014.68
Run by Paul Roden on 2008-04-19 19:24:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Paul Roden.exe) ------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:24:22 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\InCD\InCD\InCDsrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\WINDOWS\Web\aolservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
F:\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
F:\Apricorn\EZ Gig II\EZGigMonitor.exe
F:\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
F:\Apricorn\SMART-ER\SMART-ER.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
F:\Adobe\Acrobat 7.0\Acrobat\AcrobatInfo.exe
C:\Documents and Settings\Paul Roden\My Documents\New Folder\Documents and Settings\Paul Roden\My Documents\My Downloads\dss.exe
F:\DOCUME~1\PAULRO~1\MYDOCU~1\PC's\HIJACK~1\HIJACK~1\Paul Roden.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://goggle.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EZGigMonitor.exe] F:\Apricorn\EZ Gig II\EZGigMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] F:\Apricorn\EZ Gig II\TimounterMonitor.exe
O4 - HKLM\..\Run: [Apricorn Scheduler Service] "C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMART-ER.lnk = F:\Apricorn\SMART-ER\SMART-ER.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://maytag.custhelp.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1201974964171
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://notes-srv1.la...e.edu/dwa7W.cab
O20 - Winlogon Notify: !SASWinLogon - F:\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apricorn Scheduler Service (AcrSch2Svc) - Apricorn - C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Services (AOL-SERVICE-v1) - Unknown owner - C:\WINDOWS\Web\aolservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - F:\InCD\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SMART-ER Service (SMART-ERService) - Apricorn - F:\Apricorn\SMART-ER\SMART-ER Service.exe

--
End of file - 10698 bytes

-- Files created between 2008-03-19 and 2008-04-19 -----------------------------

2008-04-19 15:36:51 6029312 --a------ C:\Documents and Settings\Paul Roden\ntuser.dat
2008-04-19 10:38:49 0 d-------- C:\HardDriv
2008-04-19 10:05:04 0 d--hs---- C:\found.000
2008-04-19 07:16:56 0 d-------- C:\Program Files\Symantec
2008-04-18 00:30:51 0 d-------- C:\Program Files\Panda Security
2008-04-17 06:29:54 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\SUPERAntiSpyware.com
2008-04-17 06:29:16 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-16 06:39:52 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Malwarebytes
2008-04-16 06:39:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 06:39:42 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-16 06:39:13 0 d-------- C:\Program Files\Common Files\Download Manager
2008-04-14 06:39:04 0 d-------- C:\Program Files\Microsoft Silverlight
2008-04-12 08:47:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Apricorn
2008-04-12 08:41:40 400560 --a------ C:\WINDOWS\system32\drivers\timntr.sys <Not Verified; Apricorn; Apricorn EZ Gig II>
2008-04-12 08:41:40 39376 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys <Not Verified; Apricorn; Apricorn EZ Gig II>
2008-04-12 08:41:34 120688 --a------ C:\WINDOWS\system32\drivers\snapman.sys <Not Verified; Apricorn; Apricorn Snapshot API>
2008-04-12 08:40:55 0 d-------- C:\Program Files\Common Files\Apricorn
2008-04-08 22:54:33 262144 --a------ C:\Documents and Settings\Justin Roden\ntuser.dat
2008-04-07 19:55:50 4 --a------ C:\WINDOWS\system32\0B69EB
2008-03-27 20:34:14 0 d-------- C:\Program Files\uTorrent
2008-03-27 20:34:13 0 d-------- C:\Documents and Settings\Justin Roden\Application Data\uTorrent


-- Find3M Report ---------------------------------------------------------------

2008-04-19 17:58:51 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-04-19 09:48:32 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\AVG7
2008-04-19 07:25:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-17 06:29:16 0 d-------- C:\Program Files\Common Files
2008-04-08 05:36:59 0 d-------- C:\Program Files\Kodak
2008-04-07 15:24:33 29346 --a------ C:\logfile
2008-03-15 17:12:03 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Image Zone Express
2008-03-09 17:34:39 0 d-------- C:\Program Files\LimeWire
2008-03-02 23:31:38 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Adobe
2008-03-02 23:26:11 0 d-------- C:\Program Files\Common Files\CNC
2008-03-02 22:47:54 0 d-------- C:\Program Files\Java
2008-03-02 18:44:19 0 d-------- C:\Program Files\iTunes
2008-02-26 11:03:34 0 d-------- C:\Program Files\DNA
2008-02-23 13:35:18 0 d-------- C:\Program Files\Common Files\PACE Anti-Piracy
2008-02-19 22:33:00 0 --a------ C:\WINDOWS\ORUN32.EXE
2008-02-19 22:32:39 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"webscan"="C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" []
"@"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/01/2008 12:13 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/04/2008 03:18 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [12/15/2005 12:18 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/14/2008 09:30 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" []
"EZGigMonitor.exe"="F:\Apricorn\EZ Gig II\EZGigMonitor.exe" [10/09/2007 01:20 PM]
"AcronisTimounterMonitor"="F:\Apricorn\EZ Gig II\TimounterMonitor.exe" [10/09/2007 01:33 PM]
"Apricorn Scheduler Service"="C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe" [10/09/2007 01:24 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [09/15/2006 01:27 PM]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"SUPERAntiSpyware"="F:\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]

C:\Documents and Settings\Paul Roden\Start Menu\Programs\Startup\
DESKTOP.INI [8/10/2004 2:04:12 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [11/2/2007 9:51:53 PM]
DESKTOP.INI [8/10/2004 2:04:12 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [10/22/2004 2:34:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [12/15/2005 11:40:44 AM]
SMART-ER.lnk - F:\Apricorn\SMART-ER\SMART-ER.exe [6/4/2007 10:20:18 AM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 F:\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 09/27/2007 06:44 AM 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,




-- End of Deckard's System Scanner: finished at 2008-04-19 19:25:14 ------------

There was no second, extra.txt file generated by Dekard's System Scanner.

Best Regards,

Trainer12
Training Manager
North America
  • 0

#4
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
in this post we will remove one piece of malware i can see before we continue.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://goggle.com/
O15 - Trusted Zone: http://maytag.custhelp.com

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


could you post a new hijackthis log in reply.

could you also let me know if the machine is able to use internet explore yet? or is the machine itself able to get online yet?

andrewuk
  • 0

#5
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
.....moved from a new post in the malware forum here

Andrewuk,

Yes, I can get on the Internet. My son can't get on, but my daughter, wife and I can get on.

Best regards,

Trainer12

DSS Hijack Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:12 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\InCD\InCD\InCDsrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\WINDOWS\Web\aolservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
F:\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
F:\Apricorn\EZ Gig II\EZGigMonitor.exe
F:\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
F:\Apricorn\SMART-ER\SMART-ER.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
F:\Documents and Settings\Paul Roden\My Documents\PC's\HiJack This Scans\HiJacker Software\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EZGigMonitor.exe] F:\Apricorn\EZ Gig II\EZGigMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] F:\Apricorn\EZ Gig II\TimounterMonitor.exe
O4 - HKLM\..\Run: [Apricorn Scheduler Service] "C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMART-ER.lnk = F:\Apricorn\SMART-ER\SMART-ER.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1201974964171
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://notes-srv1.la...e.edu/dwa7W.cab
O20 - Winlogon Notify: !SASWinLogon - F:\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apricorn Scheduler Service (AcrSch2Svc) - Apricorn - C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Services (AOL-SERVICE-v1) - Unknown owner - C:\WINDOWS\Web\aolservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - F:\InCD\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SMART-ER Service (SMART-ERService) - Apricorn - F:\Apricorn\SMART-ER\SMART-ER Service.exe

--
End of file - 10393 bytes

Malwarebyte Log:

Malwarebytes' Anti-Malware 1.11
Database version: 658

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 105705
Time elapsed: 53 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

My wife, my daughter and I, can get on the computer and the Internet with no problem. It is my son that is having a hard time finding out about weather whether to go to fund raisers.
  • 0

#6
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ok, in this post we will scan four files that i do not recognise and also do an online scan to see what else is lurking on your machine. please post your replies to this topic only.

the kaspersky scan will likely take close to 2 hours.


====STEP 1====
Jotti File Submission:

Please go to Jotti's malware scan
Copy and paste the following file path into the "File to upload & scan"box on the top of the page:
F:\Apricorn\EZ Gig II\EZGigMonitor.exe

Click on the submit button

Please also do the same with the following two files:
F:\Apricorn\SMART-ER\SMART-ER.exe
C:\WINDOWS\Web\aolservice.exe


Please post the results of the scan in your next reply.

If Jotti is busy, try the same atVirustotal


====STEP 2====
You will need Internet Explore to run this.

Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

In your next reply could i see:
1. the three jotti scan logs
2. the kaspersky scan log

andrewuk

Edited by andrewuk, 19 April 2008 - 07:18 PM.

  • 0

#7
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Dear Andrewuk:

Here is the Jotti Log pasted below. It foiund 5 things in AOL.exe. I couldn't get the Kasperksy program to run. I sent them a message. I disabled the Grisoft AVS and the SuperAntivirus. Uninstalled and tried again. It keeps going back to this screen shot screen below the Jotti Logs.

Thanks,

Trainer12

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1



File to upload & scan:



Service
Service load: 0% 100%

File: EZGigMonitor.exe
Status: OK
MD5: 3f2a3d0fcaf06350e554b541959498d4
Packers detected: -
Bit9 reports: Not analyzed yet (more info)

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1


File to upload & scan:



Service
Service load: 0% 100%

File: SMART-ER.exe
Status: OK
MD5: b90909154051bb0a83d9a25966f37b39
Packers detected: -
Bit9 reports: Not analyzed yet (more info)

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1


File to upload & scan:



Service
Service load: 0% 100%

File: aolservice.exe
Status: INFECTED/MALWARE
MD5: 9ed64ba9e729699e6b6331954627f957
Packers detected: PELOCK
Bit9 reports: File not found

Scanner results
Scan taken on 20 Apr 2008 03:35:54 (GMT)
A-Squared Found nothing
AntiVir Found HEUR/Crypted
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Backdoor.Win32.SdBot.aad
Fortinet Found nothing
Ikarus Found Backdoor.Win32.Rbot.cgu
Kaspersky Anti-Virus Found Backdoor.Win32.SdBot.aad
NOD32 Found nothing
Norman Virus Control Found W32/Hupigon.gen76
Panda Antivirus Found nothing
Sophos Antivirus Found Sus/UnkPacker (probable variant)
VirusBuster Found nothing
VBA32 Found nothing

Screen Shot of the Kaspensky after clicking on Scan Settings, it goes back to this. It is attached as a file.

Attached Files


  • 0

#8
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
it appears that one of those files was bad, which we will remove now. we will also attempt a different online scan.

the scans will likely take 2 hours, quite possibly much longer. so just let them run.


====STEP 1====
Please download the OTMoveIt2 by OldTimer and Save it to your desktop.

Do NOT run it yet


====STEP 2====
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O23 - Service: AOL Services (AOL-SERVICE-v1) - Unknown owner - C:\WINDOWS\Web\aolservice.exe

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


====STEP 3====
Delete an NT Service

  • Open HiJackThis
  • Click on the "Config..." button on the bottom right
  • Click on the tab "Misc Tools"
  • click on "delete an NT service"
  • Copy and paste this in: AOL-SERVICE-v1
  • Click "ok", then reboot


====STEP 4====
Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\Web\aolservice.exe
    Purity
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


====STEP 5====
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


====STEP 6====
there is a chance that the bad file we just removed was blocking the kaspersky scan so could you try the kaspersky scan again, it that does not work then try this:

Please go HERE to run Panda's TotalScan
  • Select the bubble for Full scan
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • Then the scan will begin
  • When the scan completes, click the Save button on the right of Scan details
  • Save it to a convenient location. Post the contents of the TotalScan report


In your next reply could i see:
1. the OTMoveIT log
2. the kaspersky log or the Totalscan log
3. a new hijackthis log

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#9
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Andrewuk,

I can't delete the aolservice.exe. Here are the screen shots of my attempts to remove it with Hijack this and Administrator in Windows XP. I downloaded the other software but have not run them yet and they are on my desktop.

Thanks,

Trainer12

HijackThis

The service 'AOL service v1' is enabled and or running. Disable it first using HijackThis (from the scan results) or the services.msc window.

I tried that twice and I tried killing it from the services.msc window twice. No Luck.

What next?

Thanks,

Trainer12
  • 0

#10
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ok, try this and then do STEP 2, STEP 4, STEP 5 and STEP 6.

Please copy (Ctrl C) and paste (Ctrl V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat. Please save it on your desktop.

@echo off
sc stop AOL Services
sc delete AOL Services
exit

Double click FixServices.bat. A window will open and close. This is normal.

andrewuk
  • 0

Advertisements


#11
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Andrewuk,

Total Scan Report:

;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-04-20 13:27:20
PROTECTIONS: 1
MALWARE: 40
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
StopSign Antivirus FREE TRIAL diagnostic vers1.0.0.1 No Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.casalemedia.com/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.atdmt.com/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.fastclick.net/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.tribalfusion.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.tribalfusion.com/]
00149064 Cookie/Maxserving TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.maxserving.com/]
00149064 Cookie/Maxserving TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.maxserving.com/]
00159564 Cookie/WUpd TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.revenue.net/]
00167430 Cookie/myaffiliateprogram TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.www.myaffiliateprogram.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Barbara Joseph\Desktop\FirefoxPortable\Data\profile\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.com.com/]
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.yadro.ru/]
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.yadro.ru/]
00167735 Cookie/Netster TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][lb1.netster.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.statcounter.com/]
00168048 Cookie/Overture TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.perf.overture.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.apmebf.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.apmebf.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.apmebf.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.burstnet.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.burstnet.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168077 Cookie/Versiontracker TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.versiontracker.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.bs.serving-sys.com/]
00168097 Cookie/BurstBeacon TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][www.burstbeacon.com/]
00168101 Cookie/Falkag TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.as-us.falkag.net/]
00168109 Cookie/Adtech TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.adtech.de/]
00168109 Cookie/Adtech TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.adtech.de/]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/49303385]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/60960915]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/45397005]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/60960915]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/17019767]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/17019767]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/687358]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/49303385]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][server.iad.liveperson.net/hc/687358]
00168114 Cookie/onestat.com TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][stat.onestat.com/]
00168114 Cookie/onestat.com TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][stat.onestat.com/]
00170535 Cookie/GoClick TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][c.goclick.com/]
00170535 Cookie/GoClick TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][c.goclick.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.realmedia.com/]
00171718 Cookie/Enhance TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][c.enhance.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.questionmarket.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Justin Roden\Desktop\FirefoxPortable\Data\profile\cookies.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.zedo.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.adrevolver.com/]
00187950 Cookie/bravenetA TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.bravenet.com/]
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\Paul Roden\Application Data\Mozilla\Firefox\Profiles\nhj805w1.default\cookies.txt[.adultfriendfinder.com/]
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\Paul Roden\Application Data\Mozilla\Firefox\Profiles\nhj805w1.default\cookies.txt[.adultfriendfinder.com/]
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\Paul Roden\Application Data\Mozilla\Firefox\Profiles\nhj805w1.default\cookies.txt[.adultfriendfinder.com/]
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\Paul Roden\Application Data\Mozilla\Firefox\Profiles\nhj805w1.default\cookies.txt[.adultfriendfinder.com/]
00194327 Cookie/Go TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.go.com/]
00194327 Cookie/Go TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.go.com/]
00199984 Cookie/Searchportal TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][searchportal.information.com/]
00262020 Cookie/Atwola TrackingCookie No 0 No No C:\Program Files\support.com\backup\co\cookies.txt\100253_5d91a117c_[cookies.txt][.atwola.com/]
00366244 Application/NirCmd.A HackTools No 0 No No F:\Documents and Settings\Paul Roden\My Documents\My Downloads\Flash_Disinfector.exe[nircmd.exe]
01129933 Adware/ActiveSearch Adware No 0 No No C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe[MediaBar.dll]
01170158 Adware/ActiveSearch Adware No 0 Yes No C:\Documents and Settings\Christine Roden\Desktop\BearShareV6.exe
01176994 Bck/VB.XB Virus/Trojan No 0 No No F:\Documents and Settings\Paul Roden\My Documents\My Downloads\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe]
01299541 Application/ImeshMediaBar HackTools No 0 Yes No C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe
;===============================================================================
=================================================================================
===================
SUSPECTS
Location
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================

OTMoveIt2 by Old Time Log File:

C:\WINDOWS\Web\aolservice.exe moved successfully.
< Purity >

HiJackThis Log file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:43 PM, on 4/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\InCD\InCD\InCDsrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
F:\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
F:\Apricorn\EZ Gig II\EZGigMonitor.exe
F:\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
F:\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
F:\Documents and Settings\Paul Roden\My Documents\PC's\HiJack This Scans\HiJacker Software\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EZGigMonitor.exe] F:\Apricorn\EZ Gig II\EZGigMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] F:\Apricorn\EZ Gig II\TimounterMonitor.exe
O4 - HKLM\..\Run: [Apricorn Scheduler Service] "C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMART-ER.lnk = F:\Apricorn\SMART-ER\SMART-ER.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://www.nanoscan.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan....s/ascstubie.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1201974964171
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://notes-srv1.la...e.edu/dwa7W.cab
O20 - Winlogon Notify: !SASWinLogon - F:\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apricorn Scheduler Service (AcrSch2Svc) - Apricorn - C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - F:\InCD\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SMART-ER Service (SMART-ERService) - Apricorn - F:\Apricorn\SMART-ER\SMART-ER Service.exe

--
End of file - 10512 bytes


OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04202008_111526

OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04202008_135116
  • 0

#12
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
the scan picked up a nunber of cookies and fix tools, but it also picked up some infected files which we will remove now.

====STEP 1====
Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe[MediaBar.dll]
    C:\Documents and Settings\Christine Roden\Desktop\BearShareV6.exe
    C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe
    Purity
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

====STEP 2====
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

In your next reply could i see:
1. the OTMoveIT log
2. some idea of how your machine is running now

andrewuk
  • 0

#13
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Andrewuk,

I ran ATF again. Below is the OTMoveIT2 log.

< C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe[MediaBar.dll] >
File/Folder C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe[MediaBar.dll] not found.
C:\Documents and Settings\Christine Roden\Desktop\BearShareV6.exe moved successfully.
C:\Documents and Settings\Christine Roden\Local Settings\Temp\MediaBar.exe moved successfully.
< Purity >

OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04202008_144008

My Son's account still has the same problems. IE keeps trying to go to yahoo.com. http://runonce.msm.com/runonce2.asp is the URL that keeps poping up in the default home page listing and in the browser address window. Microsoft Word won't open. The error messag I get is:
Windows cannot acces the specific device, path or file. You may not have appropriate permission to access the item.
  • 0

#14
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ok, lets reset the hosts file and pull down another DSS scan:

====STEP 1====
Download the HostsXpert 4.2 - Hosts File Manager.
  • Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
  • Run HostsXpert 4.2 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

====STEP 2====
click on Start, click on Run
copy and paste the following in bold in the open window and then click OK
"%userprofile%\desktop\dss.exe" /config
This will open up DSS configuration
click on Check All
click Scan
DSS will now run again when finished
Please post back both logs that open in notepad
Main txt and extra txt

In your next reply could i see:
1. the 2 DSS logs

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#15
Trainer12

Trainer12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Andrewuk:

I couldn't get the HostsXpert to work. The following error message: "ERROR: Cannot create file C:\WINDOWS\System32\system32\driver\ETC\HOST"

Second, I could not open up DSS Scanner to scan with my system. Here are the logs for the programs that you requested.

eckard's System Scanner v20071014.68
Run by Paul Roden on 2008-04-21 21:50:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Paul Roden.exe) ------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:35 PM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\InCD\InCD\InCDsrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
F:\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
F:\Apricorn\EZ Gig II\EZGigMonitor.exe
F:\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
F:\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\Paul Roden\My Documents\New Folder\Documents and Settings\Paul Roden\My Documents\PC's\Malware\HostsXpert\HostsXpert\HostsXpert.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Paul Roden\My Documents\New Folder\Documents and Settings\Paul Roden\My Documents\PC's\Deckards System Scan Backup\dss.exe
F:\DOCUME~1\PAULRO~1\MYDOCU~1\PC's\HIJACK~1\HIJACK~1\PAULRO~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EZGigMonitor.exe] F:\Apricorn\EZ Gig II\EZGigMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] F:\Apricorn\EZ Gig II\TimounterMonitor.exe
O4 - HKLM\..\Run: [Apricorn Scheduler Service] "C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMART-ER.lnk = F:\Apricorn\SMART-ER\SMART-ER.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://www.nanoscan.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan....s/ascstubie.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1201974964171
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://notes-srv1.la...e.edu/dwa7W.cab
O20 - Winlogon Notify: !SASWinLogon - F:\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apricorn Scheduler Service (AcrSch2Svc) - Apricorn - C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - F:\InCD\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SMART-ER Service (SMART-ERService) - Apricorn - F:\Apricorn\SMART-ER\SMART-ER Service.exe

--
End of file - 10810 bytes

-- Files created between 2008-03-21 and 2008-04-21 -----------------------------

2008-04-20 11:29:07 0 d-------- C:\WINDOWS\LastGood
2008-04-20 00:50:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-20 00:50:45 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-19 20:33:46 0 d-------- C:\Program Files\iPod
2008-04-19 20:27:09 0 d-------- C:\Program Files\Apple Software Update
2008-04-19 15:36:51 6029312 --a------ C:\Documents and Settings\Paul Roden\ntuser.dat
2008-04-19 10:38:49 0 d-------- C:\HardDriv
2008-04-19 10:05:04 0 d--hs---- C:\found.000
2008-04-19 07:16:56 0 d-------- C:\Program Files\Symantec
2008-04-18 00:30:51 0 d-------- C:\Program Files\Panda Security
2008-04-17 06:29:54 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\SUPERAntiSpyware.com
2008-04-17 06:29:16 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-16 06:39:52 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Malwarebytes
2008-04-16 06:39:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 06:39:42 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-16 06:39:13 0 d-------- C:\Program Files\Common Files\Download Manager
2008-04-14 06:39:04 0 d-------- C:\Program Files\Microsoft Silverlight
2008-04-12 08:47:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Apricorn
2008-04-12 08:41:40 400560 --a------ C:\WINDOWS\system32\drivers\timntr.sys <Not Verified; Apricorn; Apricorn EZ Gig II>
2008-04-12 08:41:40 39376 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys <Not Verified; Apricorn; Apricorn EZ Gig II>
2008-04-12 08:41:34 120688 --a------ C:\WINDOWS\system32\drivers\snapman.sys <Not Verified; Apricorn; Apricorn Snapshot API>
2008-04-12 08:40:55 0 d-------- C:\Program Files\Common Files\Apricorn
2008-04-08 22:54:33 262144 --a------ C:\Documents and Settings\Justin Roden\ntuser.dat
2008-04-07 19:55:50 4 --a------ C:\WINDOWS\system32\0B69EB
2008-03-27 20:34:14 0 d-------- C:\Program Files\uTorrent
2008-03-27 20:34:13 0 d-------- C:\Documents and Settings\Justin Roden\Application Data\uTorrent


-- Find3M Report ---------------------------------------------------------------

2008-04-21 18:13:26 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-04-21 08:00:17 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\AVG7
2008-04-19 20:32:07 0 d-------- C:\Program Files\QuickTime
2008-04-19 07:25:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-17 06:29:16 0 d-------- C:\Program Files\Common Files
2008-04-08 05:36:59 0 d-------- C:\Program Files\Kodak
2008-04-07 15:24:33 29346 --a------ C:\logfile
2008-03-15 17:12:03 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Image Zone Express
2008-03-09 17:34:39 0 d-------- C:\Program Files\LimeWire
2008-03-02 23:31:38 0 d-------- C:\Documents and Settings\Paul Roden\Application Data\Adobe
2008-03-02 23:26:11 0 d-------- C:\Program Files\Common Files\CNC
2008-03-02 22:47:54 0 d-------- C:\Program Files\Java
2008-02-26 11:03:34 0 d-------- C:\Program Files\DNA
2008-02-23 13:35:18 0 d-------- C:\Program Files\Common Files\PACE Anti-Piracy
2008-02-19 22:33:00 0 --a------ C:\WINDOWS\ORUN32.EXE
2008-02-19 22:32:39 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"webscan"="C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" []
"@"="" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [12/15/2005 12:18 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/14/2008 09:30 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" []
"EZGigMonitor.exe"="F:\Apricorn\EZ Gig II\EZGigMonitor.exe" [10/09/2007 01:20 PM]
"AcronisTimounterMonitor"="F:\Apricorn\EZ Gig II\TimounterMonitor.exe" [10/09/2007 01:33 PM]
"Apricorn Scheduler Service"="C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe" [10/09/2007 01:24 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="F:\iTunesHelper.exe" [03/30/2008 10:36 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [09/15/2006 01:27 PM]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"SUPERAntiSpyware"="F:\SUPERAntiSpyware\SUPERAntiSpyware.exe" [04/20/2008 11:09 AM]

C:\Documents and Settings\Paul Roden\Start Menu\Programs\Startup\
DESKTOP.INI [8/10/2004 2:04:12 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [11/2/2007 9:51:53 PM]
DESKTOP.INI [8/10/2004 2:04:12 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [10/22/2004 2:34:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [12/15/2005 11:40:44 AM]
SMART-ER.lnk - F:\Apricorn\SMART-ER\SMART-ER.exe [6/4/2007 10:20:18 AM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\SUPERAntiSpyware\SASWINLO.DLL 04/20/2008 11:09 AM 294912 F:\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 09/27/2007 06:44 AM 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

*Newly Created Service* - SASDIFSV



-- End of Deckard's System Scanner: finished at 2008-04-21 21:51:16 ------------
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP