Unsolved

This post is more than 5 years old

57 Posts

1717

July 15th, 2007 17:00

browser pop ups, malware and spyware warning boxes, changed wallpaper - Please advise

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:02 PM, on 7/15/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gomyron.com/NjU2NA==/2/3560/homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {295BA105-3506-4D25-B0DD-54346320BDC5} - (no file)
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AntiSpywareBot] C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe -boot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [stratas] lockx.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Judy\Application Data\hgv?e.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm072
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/246f02f3420b2fa5c301/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174846445118
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O20 - Winlogon Notify: vtutr - C:\WINDOWS\System32\vtutr.dll (file missing)
O21 - SSODL: msole - {2480EEF6-4245-4FBF-B3AA-B65F39E59650} - C:\WINDOWS\msole.dll
O21 - SSODL: msdde - {B6EBC2F0-52F6-45AF-A61D-5FBE3FDBC53E} - C:\WINDOWS\msdde.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
--
End of file - 12075 bytes

4 Apprentice

 • 

20.5K Posts

July 15th, 2007 18:00

You have quite a collection of malware there. Has someone been doing file sharing on that computer?

It will take us several days and several tools to fix this. in addition, you are missing Windows' XP SP2, so that only adds to your vulnerability. DO NOT try to update to SP2 now!! You computer needs to be very, very clean in order to do that without problems.

First, please download Combofix from here: http://download.bleepingcomputer.com/sUBs/combofix.exe
Or
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
** Take note that the links are case sensitive

Save ComboFix to the desktop.

1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with other requested logs.

Note:
Do not mouseclick Combofix's window while it is running. That may cause your system to stall/hang.
Do not proceed with the rest of the fix if you fail to run ComboFix.


Next, Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click Smitfraudfix.exe
Select option #1 - Search by typing 1 and press " Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";
it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

http://www.beyondlogic.org/consulting/proc...processutil.htm

57 Posts

July 15th, 2007 20:00

SmitFraudFix v2.204
Scan done at 16:53:29.70, Sun 07/15/2007
Run from C:\Documents and Settings\Judy\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\CSCRIPT.EXE
»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Judy

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Judy\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Judy\FAVORI~1

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"=" file:///C:\\WINDOWS\\privacy_danger\\index.htm"
"SubscribedURL"=""
"FriendlyName"="Privacy Protection"
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Rustock
 
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Broadcom 440x 10/100 Integrated Controller
DNS Server Search Order: 68.87.73.242
DNS Server Search Order: 68.87.71.226
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9BD3C85E-A50D-4982-8ABD-B5A9035B1EA8}: DhcpNameServer=68.87.73.242 68.87.71.226
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9BD3C85E-A50D-4982-8ABD-B5A9035B1EA8}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9BD3C85E-A50D-4982-8ABD-B5A9035B1EA8}: DhcpNameServer=68.87.73.242 68.87.71.226
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9BD3C85E-A50D-4982-8ABD-B5A9035B1EA8}: DhcpNameServer=68.87.73.242 68.87.71.226
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.73.242 68.87.71.226
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=68.87.73.242 68.87.71.226
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=68.87.73.242 68.87.71.226

»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

»»»»»»»»»»»»»»»»»»»»»»»» End
 

57 Posts

July 15th, 2007 20:00

Yes, my nephews have been hard at work building their collection of malware and most likely use filie sharing.
 
Thank you for the heads up on the effort involved.  I understand the time commitment and am most thankful to have your guidance.
 
SP2 and related updates are on the list once we get a clean machine.
 
Second post coming with the SmitfraudFix report.  Ran into the 20000 message body character limit.  I'll also post the "ComboFix-quarantined-files.txt" file just in case you want it.  
 
**************************
"ComboFix.txt" follows:
 
 
"Judy" - 2007-07-15 16:23:02 - ComboFix 07-07-13.8 - Service Pack 1  NTFS 

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

C:\DOCUME~1\ALLUSE~1\Desktop.\AntiSpywareBot.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs.\AntiSpywareBot
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs.\AntiSpywareBot\AntiSpywareBot on the Web.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs.\AntiSpywareBot\AntiSpywareBot.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs.\AntiSpywareBot\Uninstall AntiSpywareBot.lnk
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\DataBase.ref
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_10_19_34_39.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_10_19_34_54.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_11_20_03_38.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_11_20_04_10.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_08_39_52.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_08_40_12.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_19_00_05.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_19_00_15.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_13_11_07_04.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_13_11_07_12.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_10_49_37.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_10_49_53.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_13_56_05.log
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\CustomScan.stg
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\IgnoreList.stg
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\ScanInfo.stg
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\ScanResults.stg
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\SelectedFolders.stg
C:\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\Settings.stg
C:\DOCUME~1\Judy\Desktop.\Error Cleaner.url
C:\DOCUME~1\Judy\Desktop.\Privacy Protector.url
C:\DOCUME~1\Judy\Desktop.\Spyware&Malware Protection.url
C:\DOCUME~1\Judy\FAVORI~1.\Error Cleaner.url
C:\DOCUME~1\Judy\FAVORI~1.\Privacy Protector.url
C:\DOCUME~1\Judy\FAVORI~1.\Spyware&Malware Protection.url
C:\Program Files\AntiSpywareBot
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.url
C:\Program Files\AntiSpywareBot\Launcher.exe
C:\Program Files\AntiSpywareBot\unins000.dat
C:\Program Files\AntiSpywareBot\unins000.exe
C:\Program Files\NewMediaCodec
C:\Program Files\NewMediaCodec\install.ico
C:\Program Files\NewMediaCodec\NewMediaCodec.ocx
C:\Program Files\NewMediaCodec\Uninstall.exe
C:\Program Files\Ultimate Cleaner
C:\Program Files\Ultimate Defender
C:\WINDOWS\dat.txt
C:\WINDOWS\main_uninstaller.exe
C:\WINDOWS\msdde.dll
C:\WINDOWS\msole.dll
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\Tasks\AntiSpywareBot Scheduled Scan.job

(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

-------\msdirectx

(((((((((((((((((((((((((   Files Created from 2007-06-15 to 2007-07-15  )))))))))))))))))))))))))))))))

2007-07-15 16:21 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-15 14:28   d-------- C:\Program Files\Trend Micro
2007-07-15 11:15   d-------- C:\WINDOWS\pss
2007-07-11 20:05   d-------- C:\DOCUME~1\Judy\.limewire
2007-07-08 10:14   d-------- C:\DOCUME~1\Ray\APPLIC~1\Apple Computer
2007-07-06 07:57   d-------- C:\DOCUME~1\Ray\APPLIC~1\Google
2007-07-05 17:40   d-------- C:\Program Files\Spyware Doctor
2007-07-05 17:40   d-------- C:\DOCUME~1\Judy\APPLIC~1\PC Tools
2007-07-05 17:29 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-06-24 10:32 71,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys
2007-06-24 10:32 37,480 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys
2007-06-24 10:32 34,184 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys
2007-06-24 10:32 32,008 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys
2007-06-24 10:32 170,408 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys
2007-06-24 10:32 109,608 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys
2007-06-24 10:30   d-------- C:\Program Files\McAfee
2007-06-24 10:30   d-------- C:\Program Files\Common Files\McAfee
2007-06-23 21:12 981,504 --a------ C:\WINDOWS\SYSTEM32\wmnetmgr.dll
2007-06-23 21:12 98,304 --a------ C:\WINDOWS\SYSTEM32\wmpshell.dll
2007-06-23 21:12 82,432 --a------ C:\WINDOWS\SYSTEM32\drmstor.dll
2007-06-23 21:12 816,264 --a------ C:\WINDOWS\SYSTEM32\wmvdmod.dll
2007-06-23 21:12 81,408 --a------ C:\WINDOWS\SYSTEM32\logagent.exe
2007-06-23 21:12 760,968 --a------ C:\WINDOWS\SYSTEM32\wmsdmod.dll
2007-06-23 21:12 7,680 --a------ C:\WINDOWS\SYSTEM32\asferror.dll
2007-06-23 21:12 678,912 --a------ C:\WINDOWS\SYSTEM32\drmv2clt.dll
2007-06-23 21:12 670,208 --a------ C:\WINDOWS\SYSTEM32\wmadmoe.dll
2007-06-23 21:12 6,656 --a------ C:\WINDOWS\SYSTEM32\laprxy.dll
2007-06-23 21:12 410,248 --a------ C:\WINDOWS\SYSTEM32\wmadmod.dll
2007-06-23 21:12 358,912 --a------ C:\WINDOWS\SYSTEM32\msscp.dll
2007-06-23 21:12 301,712 --a------ C:\WINDOWS\SYSTEM32\drmclien.dll
2007-06-23 21:12 27,136 --a------ C:\WINDOWS\SYSTEM32\wmdmlog.dll
2007-06-23 21:12 253,952 --a------ C:\WINDOWS\SYSTEM32\msnetobj.dll
2007-06-23 21:12 245,760 --a------ C:\WINDOWS\SYSTEM32\mswmdm.dll
2007-06-23 21:12 241,664 --a------ C:\WINDOWS\SYSTEM32\qasf.dll
2007-06-23 21:12 241,664 --a------ C:\WINDOWS\SYSTEM32\mpg4dmod.dll
2007-06-23 21:12 232,960 --a------ C:\WINDOWS\SYSTEM32\blackbox.dll
2007-06-23 21:12 23,552 --a------ C:\WINDOWS\SYSTEM32\wmdmps.dll
2007-06-23 21:12 218,112 --a------ C:\WINDOWS\SYSTEM32\wmasf.dll
2007-06-23 21:12 201,728 --a------ C:\WINDOWS\SYSTEM32\mspmsp.dll
2007-06-23 21:12 20,480 --a------ C:\WINDOWS\SYSTEM32\wmpui.dll
2007-06-23 21:12 20,480 --a------ C:\WINDOWS\SYSTEM32\wmpcore.dll
2007-06-23 21:12 20,480 --a------ C:\WINDOWS\SYSTEM32\wmpcd.dll
2007-06-23 21:12 2,940,928 --a------ C:\WINDOWS\SYSTEM32\wmploc.dll
2007-06-23 21:12 159,232 --a------ C:\WINDOWS\SYSTEM32\CEWMDM.dll

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 16:01:10 -------- d-----w C:\Program Files\Google
2007-06-24 14:37:07 -------- d-----w C:\Program Files\McAfee.com
2007-06-22 16:05:29 -------- d-----w C:\Program Files\LimeWire
2007-06-10 19:37:28 -------- d-----w C:\Program Files\America Online 9.0
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 02:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 02:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2005-02-17 22:52:12 47,704 ----a-w C:\DOCUME~1\Judy\APPLIC~1\GDIPFONTCACHEV1.DAT

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
 
 
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
2004-09-29 13:02 292947 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 02:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5345A7A1-805A-4923-B505-86B2FEBA3FE0}]
   C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
2003-08-06 03:04 106548 --a------ C:\WINDOWS\system32\dla\tfswshx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
2005-08-02 14:41 524288 --a------ C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
2006-12-22 16:02 67136 --a------ c:\program files\mcafee\virusscan\scriptcl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
2006-04-17 13:32 323904 --a------ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 23:55 2403392 -ra------ c:\program files\google\googletoolbar3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 22:12]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 03:01]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 21:47]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-13 02:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"HostManager"="C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe" [2005-08-02 15:33]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2004-07-19 08:51]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 07:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-06-16 14:38]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 09:18]
"Uniblue Registry Booster2"="C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe" []
"stratas"="lockx.exe" []
"Sonic RecordNow!"="" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" []
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{2480EEF6-4245-4FBF-B3AA-B65F39E59650}"="C:\WINDOWS\msole.dll" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutr]
C:\WINDOWS\System32\vtutr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc

Contents of the 'Scheduled Tasks' folder
2007-07-12 01:09:00  C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2004-01-20 01:44:44  C:\WINDOWS\tasks\ISP signup reminder 1.job
2007-06-24 14:32:10  C:\WINDOWS\tasks\McDefragTask.job
2007-07-01 05:00:01  C:\WINDOWS\tasks\McQcTask.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 16:37:57
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-15 16:44:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-15 16:44
 --- E O F ---
******************************
 

57 Posts

July 15th, 2007 20:00

Folder PATH listing
Volume serial number is 71FAE346 2853:F217
C:\QOOBOX
\---Quarantine
    +---C
    |   +---DOCUME~1
    |   |   +---ALLUSE~1
    |   |   |   +---Desktop
    |   |   |   |       AntiSpywareBot.lnk.vir
    |   |   |   |      
    |   |   |   \---STARTM~1
    |   |   |       \---Programs
    |   |   |           \---AntiSpywareBot
    |   |   |                   AntiSpywareBot on the Web.lnk.vir
    |   |   |                   AntiSpywareBot.lnk.vir
    |   |   |                   Uninstall AntiSpywareBot.lnk.vir
    |   |   |                  
    |   |   \---Judy
    |   |       +---APPLIC~1
    |   |       |   \---AntiSpywareBot
    |   |       |       |   DataBase.ref.vir
    |   |       |       |  
    |   |       |       +---Log
    |   |       |       |       log_2007_07_10_19_34_39.log.vir
    |   |       |       |       log_2007_07_10_19_34_54.log.vir
    |   |       |       |       log_2007_07_11_20_03_38.log.vir
    |   |       |       |       log_2007_07_11_20_04_10.log.vir
    |   |       |       |       log_2007_07_12_08_39_52.log.vir
    |   |       |       |       log_2007_07_12_08_40_12.log.vir
    |   |       |       |       log_2007_07_12_19_00_05.log.vir
    |   |       |       |       log_2007_07_12_19_00_15.log.vir
    |   |       |       |       log_2007_07_13_11_07_04.log.vir
    |   |       |       |       log_2007_07_13_11_07_12.log.vir
    |   |       |       |       log_2007_07_15_10_49_37.log.vir
    |   |       |       |       log_2007_07_15_10_49_53.log.vir
    |   |       |       |       log_2007_07_15_13_56_05.log.vir
    |   |       |       |      
    |   |       |       \---Settings
    |   |       |               CustomScan.stg.vir
    |   |       |               IgnoreList.stg.vir
    |   |       |               ScanInfo.stg.vir
    |   |       |               ScanResults.stg.vir
    |   |       |               SelectedFolders.stg.vir
    |   |       |               Settings.stg.vir
    |   |       |              
    |   |       +---Desktop
    |   |       |       Error Cleaner.url.vir
    |   |       |       Privacy Protector.url.vir
    |   |       |       Spyware&Malware Protection.url.vir
    |   |       |      
    |   |       \---FAVORI~1
    |   |               Error Cleaner.url.vir
    |   |               Privacy Protector.url.vir
    |   |               Spyware&Malware Protection.url.vir
    |   |              
    |   +---Program Files
    |   |   +---AntiSpywareBot
    |   |   |       AntiSpywareBot.exe.vir
    |   |   |       AntiSpywareBot.url.vir
    |   |   |       Launcher.exe.vir
    |   |   |       unins000.dat.vir
    |   |   |       unins000.exe.vir
    |   |   |      
    |   |   \---NewMediaCodec
    |   |           install.ico.vir
    |   |           NewMediaCodec.ocx.vir
    |   |           Uninstall.exe.vir
    |   |          
    |   \---WINDOWS
    |       |   dat.txt.vir
    |       |   main_uninstaller.exe.vir
    |       |   msdde.dll.vir
    |       |   msole.dll.vir
    |       |   rs.txt.vir
    |       |  
    |       +---privacy_danger
    |       |   |   index.htm.vir
    |       |   |  
    |       |   \---images
    |       |           capt.gif.vir
    |       |           danger.jpg.vir
    |       |           down.gif.vir
    |       |           spacer.gif.vir
    |       |          
    |       +---SYSTEM32
    |       |   \---DRIVERS
    |       |           FAD.sys.vir
    |       |          
    |       \---Tasks
    |               AntiSpywareBot Scheduled Scan.job.vir
    |              
    \---Registry_backups
            services_msdirectx.reg.cf
           
[/code]

57 Posts

July 15th, 2007 20:00


2003-01-30 14:52      12073    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\FAD.sys.vir
2007-05-18 04:39      23870    --a------    C:\Qoobox\Quarantine\C\WINDOWS\privacy_danger\images\capt.gif.vir
2007-05-18 04:39      47318    --a------    C:\Qoobox\Quarantine\C\WINDOWS\privacy_danger\images\danger.jpg.vir
2007-05-18 04:40      14916    --a------    C:\Qoobox\Quarantine\C\WINDOWS\privacy_danger\images\down.gif.vir
2007-05-18 04:44      43    --a------    C:\Qoobox\Quarantine\C\WINDOWS\privacy_danger\images\spacer.gif.vir
2007-06-11 14:27      13084144    --a------    C:\Qoobox\Quarantine\C\Program Files\AntiSpywareBot\AntiSpywareBot.exe.vir
2007-06-11 14:27      562672    --a------    C:\Qoobox\Quarantine\C\Program Files\AntiSpywareBot\Launcher.exe.vir
2007-06-18 20:39      1127    --a------    C:\Qoobox\Quarantine\C\WINDOWS\privacy_danger\index.htm.vir
2007-07-03 13:22      29184    --a------    C:\Qoobox\Quarantine\C\WINDOWS\main_uninstaller.exe.vir
2007-07-03 13:22      52224    --a------    C:\Qoobox\Quarantine\C\WINDOWS\msole.dll.vir
2007-07-03 13:22      72192    --a------    C:\Qoobox\Quarantine\C\WINDOWS\msdde.dll.vir
2007-07-04 07:34      4286    --a------    C:\Qoobox\Quarantine\C\Program Files\NewMediaCodec\install.ico.vir
2007-07-05 00:19      143872    --a------    C:\Qoobox\Quarantine\C\Program Files\NewMediaCodec\NewMediaCodec.ocx.vir
2007-07-05 00:19      37033    --a------    C:\Qoobox\Quarantine\C\Program Files\NewMediaCodec\Uninstall.exe.vir
2007-07-05 00:21      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\FAVORI~1\Error Cleaner.url.vir
2007-07-05 00:21      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\FAVORI~1\Privacy Protector.url.vir
2007-07-05 00:21      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\FAVORI~1\Spyware&Malware Protection.url.vir
2007-07-09 08:26      3048117    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\DataBase.ref.vir
2007-07-10 19:34      0    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\CustomScan.stg.vir
2007-07-10 19:34      0    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\IgnoreList.stg.vir
2007-07-10 19:34      0    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\ScanInfo.stg.vir
2007-07-10 19:34      0    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\SelectedFolders.stg.vir
2007-07-10 19:34      0    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\Settings.stg.vir
2007-07-10 19:34      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_10_19_34_39.log.vir
2007-07-10 19:34      1415    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\STARTM~1\Programs\AntiSpywareBot\AntiSpywareBot on the Web.lnk.vir
2007-07-10 19:34      5282    --a------    C:\Qoobox\Quarantine\C\Program Files\AntiSpywareBot\unins000.dat.vir
2007-07-10 19:34      55    --a------    C:\Qoobox\Quarantine\C\Program Files\AntiSpywareBot\AntiSpywareBot.url.vir
2007-07-10 19:34      736    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\STARTM~1\Programs\AntiSpywareBot\Uninstall AntiSpywareBot.lnk.vir
2007-07-10 19:34      748377    --a------    C:\Qoobox\Quarantine\C\Program Files\AntiSpywareBot\unins000.exe.vir
2007-07-10 19:34      766    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\STARTM~1\Programs\AntiSpywareBot\AntiSpywareBot.lnk.vir
2007-07-10 19:34      798    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\Desktop\AntiSpywareBot.lnk.vir
2007-07-10 19:44      2255    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Settings\ScanResults.stg.vir
2007-07-10 19:44      386735    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_10_19_34_54.log.vir
2007-07-11 20:04      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_11_20_03_38.log.vir
2007-07-11 20:04      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_11_20_04_10.log.vir
2007-07-12 08:42      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_08_39_52.log.vir
2007-07-12 08:43      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_08_40_12.log.vir
2007-07-12 19:00      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_19_00_05.log.vir
2007-07-12 19:00      46    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_12_19_00_15.log.vir
2007-07-13 11:07      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_13_11_07_04.log.vir
2007-07-13 11:07      46    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_13_11_07_12.log.vir
2007-07-13 11:26      18250    --a------    C:\Qoobox\Quarantine\C\WINDOWS\rs.txt.vir
2007-07-13 13:12      1523    --a------    C:\Qoobox\Quarantine\C\WINDOWS\dat.txt.vir
2007-07-15 10:49      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\Desktop\Error Cleaner.url.vir
2007-07-15 10:49      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\Desktop\Privacy Protector.url.vir
2007-07-15 10:49      226    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\Desktop\Spyware&Malware Protection.url.vir
2007-07-15 10:49      46    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_10_49_53.log.vir
2007-07-15 10:51      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_10_49_37.log.vir
2007-07-15 13:57      518    --a------    C:\Qoobox\Quarantine\C\WINDOWS\Tasks\AntiSpywareBot Scheduled Scan.job.vir
2007-07-15 13:58      123    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\Judy\APPLIC~1\AntiSpywareBot\Log\log_2007_07_15_13_56_05.log.vir
2007-07-15 16:30      2342    --a------    C:\Qoobox\Quarantine\Registry_backups\services_msdirectx.reg.cf

 

4 Apprentice

 • 

20.5K Posts

July 16th, 2007 13:00

File sharing of copyrighted material is illegal, and you could be held liable, so it is not something to be taken lightly. Moreover, a file sharing program is not technically malware by itself, but it can install malware because it opens the door for any number of
worms, adware, and spyware infections when you use their network. The courts have decided that current P2P networks are primarily used to trade pirated software and media.
I suggest that you go to Add/Remove Programs and uninstall Limewire and IMESH along with iMeshBar.

Then remove all their folders including :
C:\Program Files\ iMeshBar
C:\Program Files\ LimeWire\

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Save that to your desktop, so you can copy and paste the Scan Log results in your next reply.


  • Next, please run a scan with HijackThis and save the log to your desktop so you can post it in your next reply.
    Go back to the main screen for HijackThis and click on the "Open the Misc Tools section" button.
    Click on the "Open Uninstall Manager" button.
    Click the "Save List" button.
    After you click the "Save List" button, you will be asked where to save the file. Save it to the desktop along with the other logs. The list should open in notepad. Copy and paste that list here.

    Thus, you will have three logs to post:
    1. The report from Super AntiSpyware
    2. Your fresh Hijackthis log
    3. The uninstall list

    Let me know at that point if you are still having any symptoms of malware. Thanks.

57 Posts

July 16th, 2007 18:00

Adobe Acrobat Reader 3.02
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
Adobe Shockwave Player
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Explorer
AOL Instant Messenger
AOL Toolbar 2.0
Apple Software Update
Broadcom Management Programs
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
Dell Support 5.0.0 (766)
Disney's Magic Artist
Documents To Go
DS21Patch
FIFA 2000
Google Toolbar for Internet Explorer
Guild Wars
HijackThis 2.0.2
iMeshBar
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics Driver
Internet Explorer Default Page
iPod for Windows 2005-10-12
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
LimeWire 4.10.5
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft Age of Empires Gold
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Interactive Training
Microsoft Office XP Media Content
Microsoft Office XP Standard for Students and Teachers
Modem Event Monitor
Modem Helper
Modem On Hold
MPIO Manager 2
My Web Search (Popular Screensavers)
Palm Desktop
PhotoParade Player
Pong
QuickTime
RealOne Player
Rhapsody Player Engine
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 8 (KB911565)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896426)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Shockwave
Snood for Windows version 3.52-W
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Starsiege TRIBES 1.8
SUPERAntiSpyware Free Edition
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Hotfix - KB896688
Windows XP Hotfix - KB896727
Windows XP Hotfix - KB905915
Windows XP Hotfix - KB911567
Windows XP Hotfix - KB918439
Windows XP Hotfix - KB918899
Windows XP Hotfix - KB925486
WordPerfect Office 11
Yahoo! Companion
ZoneAlarm
 

57 Posts

July 16th, 2007 18:00

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:46 PM, on 7/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gomyron.com/NjU2NA==/2/3560/homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [stratas] lockx.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm072
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/246f02f3420b2fa5c301/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174846445118
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: vtutr - C:\WINDOWS\System32\vtutr.dll (file missing)
O21 - SSODL: msole - {2480EEF6-4245-4FBF-B3AA-B65F39E59650} - C:\WINDOWS\msole.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
--
End of file - 10988 bytes

57 Posts

July 16th, 2007 18:00

Will add theP2P issue to my list. 
 
The machine is still having issues:
- wallpaper is blank white
- browser popups continue for pcturbopro and drivecleaner
- noticed that ZoneAlarm is not starting up, started it manually this time
 
but we'll see about all that stuff once you've examined the logs below.  I imagine they are not clean yet. 
 
As an FYI I got a message during the SUPERAntiSpyware scan about virtual memory minimum being to low and I pressed okay.
 
Ran into 20000 message body character limit again so posting each of the three logs in individual posts.  The SUPERAntiSpyware log is below.
 
*****************************************
SUPERantiSpyware log:
 
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 07/16/2007 at 02:29 PM
Application Version : 3.9.1008
Core Rules Database Version : 3259
Trace Rules Database Version: 1270
Scan type       : Complete Scan
Total Scan Time : 02:05:32
Memory items scanned      : 501
Memory threats detected   : 0
Registry items scanned    : 5623
Registry threats detected : 5
File items scanned        : 89947
File threats detected     : 114
Adware.MyWay
 HKLM\Software\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
 HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
 HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
 HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}\InprocServer32
 C:\PROGRAM FILES\IMESHBAR\BAR\1.BIN\IMESHBAR.DLL
Adware.MyWebSearch
 HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Adware.Tracking Cookie
 C:\Documents and Settings\Judy\Cookies\judy@mediaplex[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@242[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@stats.privacyprotector[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@winantispyware[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@winantivirus[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@stats.drivecleaner[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@server.iad.liveperson[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@2o7[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@go.winantivirus[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@amaena[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@242[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@adserving.cpxinteractive[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@www.winantispyware[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@stats1.reliablestats[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@www.winantivirus[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@cpvfeed[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@go.drivecleaner[3].txt
 C:\Documents and Settings\Judy\Cookies\judy@go.winantispyware[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@84815040[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@random[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@onlinesecurity-50-50-swr[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@statcounter[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@242[3].txt
 C:\Documents and Settings\Judy\Cookies\judy@ad.yieldmanager[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@drivecleaner[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@clickbank[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@advertising[2].txt
 C:\Documents and Settings\Judy\Cookies\judy@go.drivecleaner[1].txt
 C:\Documents and Settings\Judy\Cookies\judy@stats1.reliablestats[2].txt
 C:\Documents and Settings\LocalService\Cookies\judy@doubleclick[1].txt
 C:\Documents and Settings\LocalService\Cookies\judy@mywebsearch[1].txt
 C:\Documents and Settings\LocalService\Cookies\judy@statse.webtrendslive[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@2o7[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@ad.admarketplace[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@ad.yieldmanager[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@adknowledge[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@adopt.specificclick[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@adrevolver[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@adrevolver[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@ads.gameshownetwork[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@ads.pointroll[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@advertising[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@as-us.falkag[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@as.casalemedia[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@atdmt[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@ath.belnk[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@atwola[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@belnk[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@c5.zedo[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@casalemedia[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@counter3.sextracker[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@counter4.sextracker[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@counter6.sextracker[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@counter8.sextracker[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@dist.belnk[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@doubleclick[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@drivecleaner[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@e-2dj6wjloqmd5wcp.stats.esomniture[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@edge.ru4[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@fastclick[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@go.drivecleaner[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@login.tracking101[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@mediaplex[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@mywebsearch[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@network.realmedia[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@paycounter[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@questionmarket[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@realmedia[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@revsci[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@serving-sys[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@sextracker[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@targetnet[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@trafficmp[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@tribalfusion[2].txt
 C:\Documents and Settings\Ray\Cookies\ray@valueclick[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@winantivirus[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@www.burstnet[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@www.windowsmedia[1].txt
 C:\Documents and Settings\Ray\Cookies\ray@zedo[2].txt
Trojan.Spyware Stormer
 C:\Program Files\Spyware Stormer
Trace.Known Threat Sources
 C:\Documents and Settings\Judy\Local Settings\Temporary Internet Files\Content.IE5\U9GNYXEH\spacer[1].gif
 C:\Documents and Settings\Judy\Local Settings\Temporary Internet Files\Content.IE5\PFBBT5GY\index[1].php
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\img2[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\logo[1].jpg
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\bg_main[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\dvd[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\logo[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\list[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\img3[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\img4[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\bttn[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\pointer[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\detector[1].htm
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\window[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\1[1]
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\logo[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\top_bg[1].jpg
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\bg[1].jpg
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\4[2]
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\defender[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\cuts3[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\3[1]
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\bg[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\bttn[2].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\box[1].jpg
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\txt[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\hd_bg[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\DFZFLPKE\line[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\cuts1[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\cd[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\0DU3GLQ3\list[1].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\EP5AVYH0\logo[2].gif
 C:\Documents and Settings\Ray\Local Settings\Temporary Internet Files\Content.IE5\4JHNEU7L\bttn[1].gif
****************************************************************

4 Apprentice

 • 

20.5K Posts

July 17th, 2007 03:00

You have Limewire installed.
It is not technically malware by itself, but it can install malware because it opens the door for any number of
worms, adware, and spyware infections when you use their network. The courts have decided that current P2P networks are primarily used to trade pirated software and media.
P2P software itself has now been found illegal in some cases. I suggest that you remove Limewire. To remove it, use the uninstaller if it is there:
Open the LimeWire folder.
Double click on the Uninstall LimeWire 18c icon.
If you do not have an uninstaller, use Add/Remove Programs.

You are running MyWebSearch (or MyBar). This is not technically malware, but it may bring malware with it. I recommend that you remove it.

Remove My Search Bar and My WebSearch Email Plug-in using Add/Remove Programs.
Delete the folders here if you removed these programs:
C:\Program Files\ MyWebSearch
C:\Program Files\ LimeWire

Please launch Hijackthis and place a checkmark next to these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL (file missing)
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - HKCU\..\Run: [stratas] lockx.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm072
09 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/246f02f3420b2fa5c301/netzip/RdxIE601.cab
O20 - Winlogon Notify: vtutr - C:\WINDOWS\System32\vtutr.dll (file missing)
O21 - SSODL: msole - {2480EEF6-4245-4FBF-B3AA-B65F39E59650} - C:\WINDOWS\msole.dll (file missing)
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm


Fix this if you removed Limewire:
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe

The following are not necessarily spyware/malware, but they use resources and may not be needed on Startup. Fixing them here will not prevent you from opening them manually as needed.

O4 - HKLM\..\Run: [TkBellExe] \"C:\Program Files\Common Files\Real\Update_OB\realsched.exe\" -osboot
( RealPlayer scheduler.Unnecessary)

O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
( AOL system tray icon. Not necessary.)

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
(D Microsoft Office startup assistant. Unnecessary)

Close all windows except HijackThis and click "Fix Checked".
Close HijackThis.

Reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key.
Use the arrow keys to highlight Safe Mode and press the Enter key.

Configure to show all files/folders:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Uncheck: Hide protected operating system files
Click on Apply.
Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
Be sure the first three boxes are selected:
Search System folders
Search Hidden Files and folders
Search SubFolders

Please delete the following file:
C:\WINDOWS\system32\ lockx.exe --file

Reboot normally.

Rehide files:
Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Check: Hide protected operating system files
Click on Apply.

Run Disk Cleanup in each user's profile:
Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
Please make sure the following are checked:
-- Downloaded Program Files
-- Temporary Internet Files
-- Recycle Bin
-- Temporary Files
Click "OK" and Disk Cleanup will delete those files for you.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.

  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

Official JAVA Installation Instructions if needed.

AFter that, please post a fresh log. Thanks.

57 Posts

July 17th, 2007 21:00

Before diving in, a quick note.  Thank you again for your time.  Your efforts and service are very much appreciated.  
 
Status of steps taken:
 
1. Removed LimeWire via its uninstall.
 
2. Removal of MyWebSearch and iMeshBar errored out with "module not found" in Add/Remove Programs, but I was able to delete their directories and contents.  However they still show in Add/Remove Programs.
 
3. Performed HijackThis fixes.  A few notes:
Noticed an entry in 16 for "dl.filekicker.com" that looked suspicious.
I think we want rid of uniBlue and I will put that on my list to clean up later.
The 04 entry for LimeWire was not there.
I checked the box for an 04 Global Startup for MyWebSearch.  Hope that was kosher.
 
4. "lockx.exe" is not on the system, so not deleted.
 
5 .Machine status:
wallpaper back to normal
no more browser popups
no more malware or spyware boxes popping up
Had to go into ZoneAlarm and recheck the box to start ZA at startup and it is now starting up okay.
 
6. Downloaded new Java install and deleted old versions but did not install new Java.  Got warning about SP2 being needed to be supported and thought I would do the install later after we get a a clean machine and after I get the Windows updates all done.  Please advise if that is not okay.
 
7.  Disk Cleanup run for each user.
 
Fresh HijackThis log follows:
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:31:26 PM, on 7/17/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1124836799\ee\AOLServiceHost.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124836799\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174846445118
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8845 bytes
 
 
 

4 Apprentice

 • 

20.5K Posts

July 17th, 2007 23:00

That's great news! :)

"Got warning about SP2 being needed to be supported and thought I would do the install later after we get a a clean machine and after I get the Windows updates all done. Please advise if that is not okay."
Okay, we're almost done, so do that as soon as you get SP2 or you will be vunerable.


"However they still show in Add/Remove Programs."

We can fix that as long as you have deleted all components.
Using the HijackThis Uninstall Manager you can remove these entries from your uninstall list.

To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen.
To delete an entry simply click on the entry you would like to remove and then click on the Delete this entry button

As far as this one:
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
It is legitimate, but if you do not want it, fix it with HijackThis. If you ever change your mind, not only does HJT keep backups, but if you go to the site again, you will be asked to install that again.

Your System Restore may still have some infection. It cannot get out UNLESS you have to do a System Restore. I suggest flushing System Restore now (If everything is running well) so you have a clean Restore Point.
After that, go get SP2. If all seems to be well again, after a day or two of use, flush SR again. That will give you a good Restore Point with SP2.
If everything is running well....
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

We need to delete some tools that you used. You can also keep the free version of Super AntiSpyware to use as an on-demand scanner (recommended).
You will still be able to manually update it.
Delete ComboFix, making sure you delete the quarantine folder here if it still exists: C:\QooBox.

Please delete SmitfraudFix (and its log) as well

Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

You may have already taken some of these steps:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Adjust your security settings for ActiveX:
Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

3. Download and install the following free programs:
a. SpywareBlaster:
http://www.javacoolsoftware.com/spywareblaster.html
Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
b. SpywareGuard:
http://www.javacoolsoftware.com/spywareguard.html
Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
Periodically check for updates in both programs.

4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads
Sunbelt Kerio has a free version: http://www.kerio.com/kpf_download.html

5. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

6. Install spyware detection and removal programs:
You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.

a. Ad-aware: http://www.lavasoft.de/software/adaware/

b. SpyBot S&D: http://safer-networking.org/en/news/2005-05-31.html

I would check for updates in SpyBot once a week or so.
Check for updates in Ad-aware frequently.

7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List.
Here is the link:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 8.1.0.
It would be best to remove prior versions before updating to a new version.
If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html

10. Make sure you are using the most updated version of Java.
The current version is Java Runtime Environment (JRE) 6u1

You can go here to download the latest version of Java Runtime Environment (JRE) 6.
Scroll down to where it says " Java Runtime Environment (JRE) 6u2 allows end-users to run Java applications".

Click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.

Remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
Official JAVA Installation Instructions if needed.
Reboot.

11. Practice Safe Surfing with with TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

The following color codes are used by TrendProtect to indicate the safety of each site.

Red for Warning
Yellow for Use Caution
Green for Safe
Grey for Unknown


12. Here are some helpful articles:
"So how did I get infected in the first place?"
by TonyKlein
http://computercops.biz/postlite7736-.html

"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

13. This is an excellent resource for users of all levels. General computer maintenance as well as internet security is covered.
Rootkits for Dummies
(Paperback)
by Larry Stevenson (Author), Nancy Altholz (Author)


Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!

Message Edited by Bugbatter on 07-17-2007 08:20 PM

57 Posts

July 18th, 2007 00:00

Amazing what you can accomplish carefully following expert guidance.  Less than 72 hours and months worth of carnage is repaired. 
 
I'll take out the tools and files per your instructions, use HijackThis to take out the Add/Remove entries, and flush system restore after verifying each proven stability point along the way.  Now on to getting the base machine up to snuff with SP2, java, and a more robust set of protective software.
 
Thank you for the excellent "standard list" of preventive measures.
 
Thanks again for your assistance.  Good to go.  Take care and enjoy!

4 Apprentice

 • 

20.5K Posts

July 18th, 2007 09:00

You are most welcome. I'm glad we could help. :)
No Events found!

Top