Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Complicated/multiple Infections - Hijack log + Malware log [RESOLVED]


  • This topic is locked This topic is locked

#16
JustinIsMe

JustinIsMe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Kaspersky log attached.

About the emails, have to look over all of them before I delete. Some of them contain important information.





Eset Online Scanner

# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3282 (20080719)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=edc82d1921b98c4380893bed6a559daa
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-07-19 09:45:41
# local_time=2008-07-19 02:45:41 (-0800, Pacific Daylight Time)
# country="Canada"
# osver=5.1.2600 NT Service Pack 2
# scanned=509591
# found=65
# scan_time=3314
C:\tio8x6.cmd Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\xfoolavp.com Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\4fvlkvo.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\4keteh.dll Win32/Rootkit.Vanti.NBG trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\54j.dll Win32/Rootkit.Vanti.NBM trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\5a9av.dll Win32/Rootkit.Vanti.NBG trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\5kitr.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\7s9c.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\9i.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\a745yz.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\aajc.dll Win32/PSW.OnLineGames.NNO trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\ae.dll Win32/Rootkit.Vanti.NBG trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\cz8.dll Win32/Rootkit.Vanti.NBG trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\dtwg.dll Win32/PSW.OnLineGames.NOP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\e7sf4.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\f.dll Win32/PSW.OnLineGames.NOP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\fqlq.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\gydiv.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\lb2t87v.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\lr4x.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\nsk4ir5b.dll Win32/PSW.OnLineGames.NOP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\ogcscda.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\pelqe.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\qyf28.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\r7vk4.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\rvofi5.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\sta13.exe Win32/Obfuscated.A1 trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\sta1ED.exe Win32/Obfuscated.A1 trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\sta3F.exe probably a variant of Win32/Obfuscated trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\uqtw.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\uz7re.dll Win32/Rootkit.Vanti.NAI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\vupin8b.dll Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\x88wsyh.dll a variant of Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\Deckard\System Scanner\20080715182336\backup\DOCUME~1\ATHOME~1\LOCALS~1\Temp\yjyuu.dll Win32/PSW.Agent.NAW trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.47382 Win32/PSW.OnLineGames.NMP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.77322 Win32/PSW.OnLineGames.NMP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\16\2485e150-317c9660 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\16\2485e150-317c9660 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\4\6e96fd04-7df5f2b5 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\4\6e96fd04-7df5f2b5 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\55\20b605b7-5d939390 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\55\20b605b7-5d939390 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\57\538bb179-47897327 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\At Home\Application Data\Sun\Java\Deployment\cache\6.0\57\538bb179-47897327 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\25\435b9f19-793d9c70 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\25\435b9f19-793d9c70 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\48\748d6430-7a3cc4d0 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\48\748d6430-7a3cc4d0 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\57\538bb179-3ccbafd4 Java/TrojanDownloader.OpenStream.NAB trojan (deleted) 00000000000000000000000000000000
C:\Documents and Settings\Ken\Application Data\Sun\Java\Deployment\cache\6.0\57\538bb179-3ccbafd4 »ZIP »OP.class Java/TrojanDownloader.OpenStream.NAB trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\ffojc.com Win32/PSW.OnLineGames.NMY trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\nby.bat a variant of Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\Documents and Settings\ATHOME~1\APPLIC~1\extranurb\astztgfm.exe Win32/Obfuscated.A1 trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\Documents and Settings\ATHOME~1\APPLIC~1\extranurb\wtzmhanb.exe Win32/Obfuscated.A1 trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\Documents and Settings\ATHOME~1\APPLIC~1\extranurb\xjtrcmhb.exe Win32/Obfuscated.A1 trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07152008_183511\WINDOWS\system32\ckvo1.dll Win32/PSW.OnLineGames.NMP trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\autorun.inf Win32/PSW.OnLineGames.NMY trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\awda2.exe Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\f.exe Win32/PSW.OnLineGames.MUU trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\h.cmd Win32/Pacex.Gen virus (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\Documents and Settings\At Home\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.65620 Win32/PSW.OnLineGames.NLS trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\Documents and Settings\At Home\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.70097 Win32/PSW.OnLineGames.NMY trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\Documents and Settings\At Home\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.99202 Win32/PSW.OnLineGames.MUU trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\Documents and Settings\Ken\Application Data\extranurb\kglcwcft.exe a variant of Win32/Obfuscated.EN trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07192008_134750\Documents and Settings\Ken\Application Data\extranurb\zwgkmzwd.exe probably a variant of Win32/Inject trojan (unable to clean - deleted) 00000000000000000000000000000000

Attached Files


  • 0

Advertisements


#17
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Looks good.. Post me a fresh DSS log before I can set you free.. :)
  • 0

#18
JustinIsMe

JustinIsMe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Thank you for all your help fenz. You are the best


Deckard's System Scanner v20071014.68
Run by At Home on 2008-07-19 14:57:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as At Home.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:57:52 PM, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\At Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ATHOME~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....ink/?linkid=677
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-4215398-1976366640-3380966323-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Ken')
O4 - HKUS\S-1-5-21-4215398-1976366640-3380966323-1006\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Ken')
O4 - HKUS\S-1-5-21-4215398-1976366640-3380966323-1006\..\Run: [Steam] (User 'Ken')
O4 - HKUS\S-1-5-21-4215398-1976366640-3380966323-1006\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Ken')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra 'Tools' menuitem: Launch Copernic 2001 - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra button: Copernic - {2A465936-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra button: Translate - {99EFB53C-C965-43CF-9F45-52242D134187} - file://C:\Program Files\Copernic 2001 Pro\Translate.htm
O9 - Extra 'Tools' menuitem: &Translate Using Gist-In-Time - {99EFB53C-C965-43CF-9F45-52242D134187} - file://C:\Program Files\Copernic 2001 Pro\Translate.htm
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: RaptisoftGameLoader - http://www.miniclip....tgameloader.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zon...kr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/a...ic_new/nxpm.cab
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.easports....ommon/ieell.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mlslink.mlxch...ectComboBox.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://citymap.nanaimo.ca/mgaxctrl.cab
O16 - DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7} (OneCCCtl Class) - https://as00.estara....081765OneCC.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mlslink.mlxch...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mlslink.mlxch...ol/IRCSharc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {ABAB45AD-4D69-4C01-A4A4-DD105F1EAE61} (mgToolbarPub.Toolbar) - http://citymap.city....eX/Toolbars.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.trickster...sterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.trickster...utComponent.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zon...er.cab56986.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - http://webmap.abbots...ements/Acgm.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe

--
End of file - 12570 bytes

-- Files created between 2008-06-19 and 2008-07-19 -----------------------------

2008-07-19 13:49:10 0 d-------- C:\Program Files\EsetOnlineScanner
2008-07-18 19:07:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-18 19:07:13 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-18 19:07:10 0 d-------- C:\WINDOWS\LastGood
2008-07-14 20:54:29 0 d-------- C:\Program Files\Avira
2008-07-14 20:54:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-13 00:18:34 0 d-------- C:\Program Files\Trend Micro
2008-07-12 22:23:25 0 d-------- C:\Program Files\Panda Security
2008-07-12 21:31:44 0 d-------- C:\Documents and Settings\At Home\Application Data\Malwarebytes
2008-07-12 21:31:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-12 21:31:40 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-12 21:31:12 0 d-------- C:\Program Files\Common Files\Download Manager


-- Find3M Report ---------------------------------------------------------------

2008-07-13 16:03:44 0 d-------- C:\Program Files\DivX
2008-07-12 23:14:50 0 d-------- C:\Program Files\MSN Messenger
2008-07-12 21:31:12 0 d-------- C:\Program Files\Common Files
2008-07-12 20:11:13 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-07 13:43:32 0 d-------- C:\Program Files\Lx_cats
2008-06-23 20:26:12 0 d-------- C:\Program Files\Steam
2008-06-16 20:55:40 0 d-------- C:\Documents and Settings\At Home\Application Data\LimeWire
2008-06-14 10:18:50 0 d-------- C:\Program Files\Apple Software Update
2008-06-14 10:15:20 0 d-------- C:\Program Files\iTunes
2008-06-14 10:15:03 0 d-------- C:\Program Files\iPod
2008-06-14 10:13:23 0 d-------- C:\Program Files\QuickTime
2008-06-10 17:07:20 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-10 17:03:26 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-06-10 17:03:26 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-06-10 17:03:20 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-06-10 17:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-10 17:03:20 815104 --a------ C:\WINDOWS\system32\divx_xx0a.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-10 17:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-10 17:03:18 683520 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-07 08:40:11 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-05-27 22:09:10 0 d-------- C:\Program Files\Lexmark Toolbar
2008-05-27 22:04:01 0 d-------- C:\Program Files\Lexmark 1300 Series
2008-05-22 15:18:54 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 11:16 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/04/2008 05:17 PM]
"lxdcmon.exe"="C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" []
"lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [30/04/2007 01:19 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [27/05/2008 10:50 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/06/2008 11:13 AM]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [17/07/2008 07:42 PM]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [11/08/2005 04:30 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [13/10/2004 09:24 AM]
"Steam"="" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [26/07/2007 07:07 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [18/10/2006 09:05 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 01:00 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [09/09/2005 12:14:16 PM]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [18/04/2006 11:49:28 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe [04/11/2004 7:28:24 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13/02/2001 1:01:04 AM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/07/2008 08:11 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 12/07/2008 08:10 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,




-- End of Deckard's System Scanner: finished at 2008-07-19 14:58:16 ------------
  • 0

#19
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
All right... Your log looks clean to my eyes.. Just a few things..

1. Uninstall your AVG-Antispyware.. It's no longer supported by Grisoft and you already have Malwarebytes' Anti-Malware, which I preferred over AVG personally..

2. Your Avira Antivirus is outdated.. Please update its virus definitions.. Its critical for you :)


Now for some cleanup..
  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.





NEXT


Please Install/Update Sun Java

Updating Java:
  • Go to Start --> Control Panel --> Add or Remove Programs.
  • Search in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )
  • It should have next icon next to it: Posted Image
  • Select it and click Remove. This will uninstall the previous (outdated) version of Java.
  • Then Download and install the newest version from here: Java Runtime Environment (JRE) 6 Update 7



You have Avira Antivir as your antivirus and Malwarebytes' as your antispyware

However, I haven't seen any third-party firewall in your logs.. Do you have any? If you don't, please install ONLY ONE of these free and excellent firewall below:
After you install the third party firewall, please disable your Windows firewall. Please go to My Computer >> Control Panel >> Windows Firewall and choose Off (not recommended) option. Then please click Apply and Ok.



Lastly, to keep your operating system up to date please visit the link below monthly

To learn more about how to protect yourself while on the internet read this excellent article by Tony Klein: So how did I get infected in the first place?

Please also read an excellent article by miekiemoes :Help! My computer is slow!

And another excellent article by CastleCops Malware Prevention: Prevent Re-infection

Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :)



Have a safe and happy computing day!


Regards
fenzodahl512

Edited by fenzodahl512, 19 July 2008 - 04:08 PM.
Edited instruction.. sigh..

  • 0

#20
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP