Unsolved
This post is more than 5 years old
8 Posts
0
1971
September 30th, 2007 19:00
Help Review HiJack This Log
I have been chasing this around and around...please help me get this popup pain!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:54:55 PM, on 9/30/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\drivers\CDAC11BA.EXE
D:\WINNT\system32\CTsvcCDA.EXE
D:\WINNT\System32\svchost.exe
D:\PROGRA~1\Iomega\System32\AppServices.exe
D:\WINNT\system32\mgabg.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\tardisnt.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
D:\WINNT\System32\ZipToA.exe
D:\Program Files\Iomega\AutoDisk\ADService.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
D:\WINNT\Explorer.EXE
D:\program files\iomega\DriveIcons\ImgIcon.exe
D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
D:\WINNT\system32\PDesk\PDesk.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
N:\Program files\Creative\MediaSource\Detector\CTDetect.exe
F:\Program Files\Linksys\logviewer2\LogViewer.exe
F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
D:\Program Files\WINZIP\WZQKPICK.EXE
D:\Program Files\Trend Micro\HijackThis\HJT.exe
F:\Netscape\Netscape 8\Netscape Browser\netscape.exe
E:\EUDORA\Eudora.exe
D:\WINNT\system32\taskmgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://204.145.206.77/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.10.1.10:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = kochcons.com; 204.145.206.2;
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {51999E1D-8BED-4D86-9A50-C0D93CC06C9E} - D:\WINNT\system32\rqrpq.dll
O2 - BHO: BndDrive2 BHO Class - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - D:\Program Files\ISM\BndDrive4.dll (file missing)
O2 - BHO: (no name) - {9E65EA92-5E6A-44E2-942D-8D6A745E0FCB} - D:\Program Files\Intuit\hopebemuz4444.dll
O2 - BHO: (no name) - {C3AD77B9-162D-4B3D-8CD8-53888D52280B} - D:\Program Files\Intuit\hopebemuz83122.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MP_STATUS_MONITOR] f:\canon\multipass\monitr32.exe I
O4 - HKLM\..\Run: [MPTBox] f:\canon\multipass\MPTBox.exe
O4 - HKLM\..\Run: [Iomega Startup Options] d:\program files\iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] d:\program files\iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ADUserMon] D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Deskup] d:\program files\iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Picasa Media Detector] N:\Program files\Picasa\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\AcrobatReader\AdobeReader 8.x\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{A1-1E-EF-F7-ZN}] N:\Temp\thinksnet.exe CHD003
O4 - HKCU\..\Run: [DW4] "D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Creative Detector] "N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [updateMgr] "f:\Program Files\AcrobatReader\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ISMModule4] "D:\Program Files\ISM\ISMModule4.exe"
O4 - HKCU\..\Run: [WinAble] D:\Program Files\WinAble\winable.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: TA_Start.lnk = N:\Temp\thinksnet.exe
O4 - Global Startup: LogViewer.lnk = F:\Program Files\Linksys\logviewer2\LogViewer.exe
O4 - Global Startup: Microsoft Office.lnk = N:\Program files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Tardis.exe v 1.6.lnk = F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WINZIP\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm020YYUS
O12 - Plugin for .htm: F:\Netscape\Netscape 8\PLUGINS\npTrident.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/compaq.v2/vet_install_popup.pl?1&4&04.00.08.43-hp&http://h71016.www7.hp.com/html/interactive/xw8200/model.html?jumpid=in_r2910_3d/WKS/xw8200|3DCENTRAL|viewpoint
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/219c020c799b4e9cdf17/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175341505902
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5289C2F-5C34-4B3F-B767-36083C5C0287}: NameServer = 24.160.227.25,24.160.227.32,24.160.227.33
O23 - Service: C-DillaCdaC11BA - Macrovision - D:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\d2drb2No\command.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: CWShredder Service - Trend Micro Incorporated - D:\Program Files\CoolWebShredder\cwshredder.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: hpdj - Unknown owner - F:\Temp\hpdj.exe (file missing)
O23 - Service: Iomega App Services - Iomega Corporation - D:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: IomegaAccess - Iomega Corporation - D:\WINNT\System32\IomegaAccess.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINNT\system32\mgabg.exe
O23 - Service: MPService - Unknown owner - f:\canon\multipass\mpservic.exe (file missing)
O23 - Service: Tardis time service (Tardis) - Unknown owner - D:\WINNT\system32\tardisnt.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
O23 - Service: ZipToA - Iomega Corporation - D:\WINNT\System32\ZipToA.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - D:\Program Files\Iomega\AutoDisk\ADService.exe
--
End of file - 8826 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:54:55 PM, on 9/30/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\drivers\CDAC11BA.EXE
D:\WINNT\system32\CTsvcCDA.EXE
D:\WINNT\System32\svchost.exe
D:\PROGRA~1\Iomega\System32\AppServices.exe
D:\WINNT\system32\mgabg.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\tardisnt.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
D:\WINNT\System32\ZipToA.exe
D:\Program Files\Iomega\AutoDisk\ADService.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
D:\WINNT\Explorer.EXE
D:\program files\iomega\DriveIcons\ImgIcon.exe
D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
D:\WINNT\system32\PDesk\PDesk.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
N:\Program files\Creative\MediaSource\Detector\CTDetect.exe
F:\Program Files\Linksys\logviewer2\LogViewer.exe
F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
D:\Program Files\WINZIP\WZQKPICK.EXE
D:\Program Files\Trend Micro\HijackThis\HJT.exe
F:\Netscape\Netscape 8\Netscape Browser\netscape.exe
E:\EUDORA\Eudora.exe
D:\WINNT\system32\taskmgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://204.145.206.77/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.10.1.10:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = kochcons.com; 204.145.206.2;
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {51999E1D-8BED-4D86-9A50-C0D93CC06C9E} - D:\WINNT\system32\rqrpq.dll
O2 - BHO: BndDrive2 BHO Class - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - D:\Program Files\ISM\BndDrive4.dll (file missing)
O2 - BHO: (no name) - {9E65EA92-5E6A-44E2-942D-8D6A745E0FCB} - D:\Program Files\Intuit\hopebemuz4444.dll
O2 - BHO: (no name) - {C3AD77B9-162D-4B3D-8CD8-53888D52280B} - D:\Program Files\Intuit\hopebemuz83122.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MP_STATUS_MONITOR] f:\canon\multipass\monitr32.exe I
O4 - HKLM\..\Run: [MPTBox] f:\canon\multipass\MPTBox.exe
O4 - HKLM\..\Run: [Iomega Startup Options] d:\program files\iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] d:\program files\iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ADUserMon] D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Deskup] d:\program files\iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Picasa Media Detector] N:\Program files\Picasa\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\AcrobatReader\AdobeReader 8.x\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{A1-1E-EF-F7-ZN}] N:\Temp\thinksnet.exe CHD003
O4 - HKCU\..\Run: [DW4] "D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Creative Detector] "N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [updateMgr] "f:\Program Files\AcrobatReader\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ISMModule4] "D:\Program Files\ISM\ISMModule4.exe"
O4 - HKCU\..\Run: [WinAble] D:\Program Files\WinAble\winable.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: TA_Start.lnk = N:\Temp\thinksnet.exe
O4 - Global Startup: LogViewer.lnk = F:\Program Files\Linksys\logviewer2\LogViewer.exe
O4 - Global Startup: Microsoft Office.lnk = N:\Program files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Tardis.exe v 1.6.lnk = F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WINZIP\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm020YYUS
O12 - Plugin for .htm: F:\Netscape\Netscape 8\PLUGINS\npTrident.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/compaq.v2/vet_install_popup.pl?1&4&04.00.08.43-hp&http://h71016.www7.hp.com/html/interactive/xw8200/model.html?jumpid=in_r2910_3d/WKS/xw8200|3DCENTRAL|viewpoint
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/219c020c799b4e9cdf17/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175341505902
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5289C2F-5C34-4B3F-B767-36083C5C0287}: NameServer = 24.160.227.25,24.160.227.32,24.160.227.33
O23 - Service: C-DillaCdaC11BA - Macrovision - D:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\d2drb2No\command.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: CWShredder Service - Trend Micro Incorporated - D:\Program Files\CoolWebShredder\cwshredder.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: hpdj - Unknown owner - F:\Temp\hpdj.exe (file missing)
O23 - Service: Iomega App Services - Iomega Corporation - D:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: IomegaAccess - Iomega Corporation - D:\WINNT\System32\IomegaAccess.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINNT\system32\mgabg.exe
O23 - Service: MPService - Unknown owner - f:\canon\multipass\mpservic.exe (file missing)
O23 - Service: Tardis time service (Tardis) - Unknown owner - D:\WINNT\system32\tardisnt.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
O23 - Service: ZipToA - Iomega Corporation - D:\WINNT\System32\ZipToA.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - D:\Program Files\Iomega\AutoDisk\ADService.exe
--
End of file - 8826 bytes
No Events found!


bamajim
10.4K Posts
0
October 1st, 2007 13:00
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
MRU Graduate
"The world is what you make of it"
wgkoch
8 Posts
0
October 1st, 2007 15:00
This seems to have had some successes, but I have not run IE yet.
What is/are the next steps, if any?
Here is the log file from combofix you requested.
ComboFix 07-10.1.2 - wgkoch 10/01/2007 11:15:08.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.89 [GMT -5:00]
Running from: D:\Documents and Settings\wgkoch\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\wgkoch\Start Menu\Programs\Startup\ta_start.lnk
D:\Program Files\FunWebProducts
D:\Program Files\inetget2
D:\Program Files\inetget2\wininstall.exe
D:\Program Files\Intuit\hopebemuz4444.dll
D:\Program Files\Intuit\hopebemuz83122.dll
D:\Program Files\MyWebSearch
D:\Program Files\MyWebSearch\bar\History\search2
D:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
D:\Program Files\MyWebSearch\bar\Settings\setting2.htm
D:\Program Files\MyWebSearch\bar\Settings\settings.dat
D:\Program Files\quick links
D:\Program Files\quick links\Uninst.log
D:\WINNT\b122.exe
D:\WINNT\cookies.ini
D:\WINNT\Downloaded Program Files\Temp
D:\WINNT\retadpu1000106.exe
D:\WINNT\system32\A1
D:\WINNT\system32\bnsjutfv.dll
D:\WINNT\system32\bqosxvuj.dll
D:\WINNT\system32\config\SAM.SAV
D:\WINNT\system32\f02WtR
D:\WINNT\system32\f02WtR\f02WtR1065.exe
D:\WINNT\system32\ftjhqxyb.exe
D:\WINNT\system32\H2
D:\WINNT\system32\hggheee.dll
D:\WINNT\system32\hjvtaawe.exe
D:\WINNT\system32\juvxsoqb.ini
D:\WINNT\system32\kfoidqap.exe
D:\WINNT\system32\msnav32.ax
D:\WINNT\system32\Q2
D:\WINNT\system32\Q2\mon33dll.exe
D:\WINNT\system32\qprqr.ini
D:\WINNT\system32\rqrpq.dll
D:\WINNT\system32\sydbjduy.exe
D:\WINNT\system32\tmhehatk.exe
D:\WINNT\system32\uqtddwdk.exe
D:\WINNT\system32\vhvwotwp.exe
D:\WINNT\system32\xbevuxta.exe
D:\WINNT\system32\xcajnlgl.exe
D:\WINNT\system32\xsojctjf.exe
D:\WINNT\TTC-4444.exe
D:\WINNT\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\cmdService
((((((((((((((((((((((((( Files Created from 2007-09-01 to 2007-10-01 )))))))))))))))))))))))))))))))
.
2007-10-01 11:13 51,200 --a------ D:\WINNT\NirCmd.exe
2007-09-27 17:34 d-------- D:\Program Files\Trend Micro
2007-09-27 16:37 d-------- D:\VundoFix Backups
2007-09-18 16:19 d--hs---- D:\WINNT\d2drb2No
2007-09-18 16:19 d-------- D:\Documents and Settings\Default User\Application Data\NetMon
2007-09-18 16:18 d-a------ D:\WINNT\system32\GRB3
2007-09-18 16:18 d-a------ D:\WINNT\system32\DLL2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
99-12-07 07:00 32528 --a--c--- D:\WINNT\inf\wbfirdma.sys
07-10-01 11:16 --------- d-a------ D:\Program Files\Intuit
07-10-01 07:07 --------- d-------- D:\Documents and Settings\wgkoch\Application Data\Lavasoft
07-08-05 14:18 --------- d-------- D:\Documents and Settings\wgkoch\Application Data\OfficeUpdate12
07-07-30 19:19 92504 --a------ D:\WINNT\system32\cdm.dll
07-07-30 19:19 549720 --a------ D:\WINNT\system32\wuapi.dll
07-07-30 19:19 53080 --a------ D:\WINNT\system32\wuauclt.exe
07-07-30 19:19 43352 --a------ D:\WINNT\system32\wups2.dll
07-07-30 19:19 325976 --a------ D:\WINNT\system32\wucltui.dll
07-07-30 19:19 271224 --a------ D:\WINNT\system32\mucltui.dll
07-07-30 19:19 207736 --a------ D:\WINNT\system32\muweb.dll
07-07-30 19:19 203096 --a------ D:\WINNT\system32\wuweb.dll
07-07-30 19:19 1712984 --a------ D:\WINNT\system32\wuaueng.dll
07-07-30 19:18 33624 --a------ D:\WINNT\system32\wups.dll
04-02-20 11:07 271 ---h-c--- D:\Program Files\desktop.ini
04-02-20 11:07 21952 ---h-c--- D:\Program Files\folder.htt
2005-07-29 21:24:26 472 --sha-r D:\WINNT\d2drb2No\xZxOvZhC.vbs
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B27CC68-110C-46a9-80D3-F3107DE6EB98}]
D:\Program Files\ISM\BndDrive4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 13:05 D:\WINNT\system32\mobsync.exe]
"MP_STATUS_MONITOR"="f:\canon\multipass\monitr32.exe" []
"MPTBox"="f:\canon\multipass\MPTBox.exe" []
"Iomega Startup Options"="d:\program files\iomega\Common\ImgStart.exe" [01-01-17 16:33 ]
"Iomega Drive Icons"="d:\program files\iomega\DriveIcons\ImgIcon.exe" [01-11-20 11:08 ]
"ADUserMon"="D:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [02-01-24 16:11 ]
"Deskup"="d:\program files\iomega\DriveIcons\deskup.exe" [01-10-01 10:08 ]
"Matrox Powerdesk"="D:\WINNT\system32\PDesk\PDesk.exe" [04-09-14 11:13 ]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06-02-21 12:53 ]
"Picasa Media Detector"="N:\Program files\Picasa\Picasa2\PicasaMediaDetector.exe" [06-09-08 19:49 ]
"Adobe Reader Speed Launcher"="F:\Program Files\AcrobatReader\AdobeReader 8.x\Reader\Reader_sl.exe" [07-05-11 03:06 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [06-04-19 09:30 ]
"Creative Detector"="N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" [04-12-02 19:23 ]
"updateMgr"="f:\Program Files\AcrobatReader\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
LogViewer.lnk - F:\Program Files\Linksys\logviewer2\LogViewer.exe [2003-02-03 12:10:48]
Microsoft Office.lnk - N:\Program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
Tardis.exe v 1.6.lnk - F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe [2006-06-17 06:29:08]
WinZip Quick Pick.lnk - D:\Program Files\WINZIP\WZQKPICK.EXE [2002-03-08 21:26:45]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
LogViewer.lnk - F:\Program Files\Linksys\logviewer2\LogViewer.exe [2003-02-03 12:10:48]
Microsoft Office.lnk - N:\Program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
Tardis.exe v 1.6.lnk - F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe [2006-06-17 06:29:08]
WinZip Quick Pick.lnk - D:\Program Files\WINZIP\WZQKPICK.EXE [2002-03-08 21:26:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= E:\EUDORA\EuShlExt.dll [06-08-17 15:57 86016]
R0 hotcore2;hotcore2;D:\WINNT\system32\drivers\hotcore2.sys
R0 iomdisk;Iomega Devices Disk Filter Services;D:\WINNT\system32\DRIVERS\iomdisk.sys
R1 UdfReadr;UdfReadr;D:\WINNT\system32\drivers\UdfReadr.sys
R2 _IOMEGA_ACTIVE_DISK_SERVICE_;Iomega Active Disk;"D:\Program Files\Iomega\AutoDisk\ADService.exe"
R2 ATNT40K;ActiveTouch NT Appsharing Driver;D:\WINNT\system32\DRIVERS\ATNT40K.SYS
R2 cis1284;cis1284;\??\D:\WINNT\System32\drivers\cis1284.sys
R2 Tardis;Tardis time service;D:\WINNT\system32\tardisnt.exe
R3 azt2320;Aztech 2320 Audio Driver (WDM);D:\WINNT\system32\drivers\aztw2320.sys
R3 G200;G200;D:\WINNT\system32\DRIVERS\g200mini.sys
R3 NtApm;NT Apm/Legacy Interface Driver;D:\WINNT\system32\DRIVERS\NtApm.sys
S1 sglfb;sglfb;D:\WINNT\system32\drivers\sglfb.sys
S3 mga64;mga64;D:\WINNT\system32\DRIVERS\mga64m.sys
S3 NDISHOOK;NDISHOOK Protocol Driver;\??\D:\Linksys\printserver\NDISHOOK.SYS
S3 vdev;VPN-1 SecureClient Virtual Ethernet Adapter;D:\WINNT\system32\DRIVERS\vdev.sys
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-01 11:22:19
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Creative Detector = "N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" /R?v??0??????w????m???????????????????l???m?????????Q?????l????'?wm????z?w?O???????????????????????????{?w????m??????????????????w????m????????????z?w???????????w?z?w????m???????????????????????-~?w
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-01 11:24:17 - machine was rebooted
D:\ComboFix-quarantined-files.txt ... 07-10-01 11:23
.
--- E O F ---
bamajim
10.4K Posts
0
October 1st, 2007 16:00
You are most welcome
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
D:\Program Files\ISM\BndDrive4.dll
Folder::
D:\Program Files\ISM
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B27CC68-110C-46a9-80D3-F3107DE6EB98}]
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
MRU Graduate
"The world is what you make of it"
wgkoch
8 Posts
0
October 1st, 2007 17:00
ComboFix 07-10.1.2 - wgkoch 10/01/2007 13:06:22.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.51 [GMT -5:00]
Running from: D:\Documents and Settings\wgkoch\Desktop\ComboFix.exe
Command switches used :: D:\Documents and Settings\wgkoch\Desktop\CFScript.txt
FILE::
D:\Program Files\ISM\BndDrive4.dll
.
((((((((((((((((((((((((( Files Created from 2007-09-01 to 2007-10-01 )))))))))))))))))))))))))))))))
.
2007-10-01 13:06 16,384 --a----t- D:\WINNT\system32\Perflib_Perfdata_358.dat
2007-10-01 12:21 d-------- D:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-01 12:19 d-------- D:\Program Files\Common Files\Wise Installation Wizard
2007-10-01 11:13 51,200 --a------ D:\WINNT\NirCmd.exe
2007-09-27 17:34 d-------- D:\Program Files\Trend Micro
2007-09-27 16:37 d-------- D:\VundoFix Backups
2007-09-18 16:19 d--hs---- D:\WINNT\d2drb2No
2007-09-18 16:19 d-------- D:\Documents and Settings\Default User\Application Data\NetMon
2007-09-18 16:18 d-a------ D:\WINNT\system32\GRB3
2007-09-18 16:18 d-a------ D:\WINNT\system32\DLL2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
12/07/99 07:00a 32528 --a--c--- D:\WINNT\inf\wbfirdma.sys
10/01/07 11:16a --------- d-a------ D:\Program Files\Intuit
10/01/07 07:07a --------- d-------- D:\Documents and Settings\wgkoch\Application Data\Lavasoft
08/07/07 01:57p 8064 --a------ D:\WINNT\system32\drivers\AWRTRD.sys
08/07/07 01:56p 9344 --a------ D:\WINNT\system32\drivers\NSDriver.sys
08/05/07 02:18p --------- d-------- D:\Documents and Settings\wgkoch\Application Data\OfficeUpdate12
02/20/04 11:07a 271 ---h-c--- D:\Program Files\desktop.ini
02/20/04 11:07a 21952 ---h-c--- D:\Program Files\folder.htt
2005-07-29 21:24:26 472 --sha-r D:\WINNT\d2drb2No\xZxOvZhC.vbs
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 01:05p D:\WINNT\system32\mobsync.exe]
"MP_STATUS_MONITOR"="f:\canon\multipass\monitr32.exe" []
"MPTBox"="f:\canon\multipass\MPTBox.exe" []
"Iomega Startup Options"="d:\program files\iomega\Common\ImgStart.exe" [01/17/01 04:33p]
"Iomega Drive Icons"="d:\program files\iomega\DriveIcons\ImgIcon.exe" [11/20/01 11:08a]
"ADUserMon"="D:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [01/24/02 04:11p]
"Deskup"="d:\program files\iomega\DriveIcons\deskup.exe" [10/01/01 10:08a]
"Matrox Powerdesk"="D:\WINNT\system32\PDesk\PDesk.exe" [09/14/04 11:13a]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/21/06 12:53p]
"Picasa Media Detector"="N:\Program files\Picasa\Picasa2\PicasaMediaDetector.exe" [09/08/06 07:49p]
"Adobe Reader Speed Launcher"="F:\Program Files\AcrobatReader\AdobeReader 8.x\Reader\Reader_sl.exe" [05/11/07 03:06a]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [04/19/06 09:30a]
"Creative Detector"="N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" [12/02/04 07:23p]
"updateMgr"="f:\Program Files\AcrobatReader\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
LogViewer.lnk - F:\Program Files\Linksys\logviewer2\LogViewer.exe [2003-02-03 12:10:48]
Microsoft Office.lnk - N:\Program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
Tardis.exe v 1.6.lnk - F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe [2006-06-17 06:29:08]
WinZip Quick Pick.lnk - D:\Program Files\WINZIP\WZQKPICK.EXE [2002-03-08 21:26:45]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
LogViewer.lnk - F:\Program Files\Linksys\logviewer2\LogViewer.exe [2003-02-03 12:10:48]
Microsoft Office.lnk - N:\Program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
Tardis.exe v 1.6.lnk - F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe [2006-06-17 06:29:08]
WinZip Quick Pick.lnk - D:\Program Files\WINZIP\WZQKPICK.EXE [2002-03-08 21:26:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= E:\EUDORA\EuShlExt.dll [08/17/06 03:57p 86016]
R0 hotcore2;hotcore2;D:\WINNT\system32\drivers\hotcore2.sys
R0 iomdisk;Iomega Devices Disk Filter Services;D:\WINNT\system32\DRIVERS\iomdisk.sys
R1 UdfReadr;UdfReadr;D:\WINNT\system32\drivers\UdfReadr.sys
R2 _IOMEGA_ACTIVE_DISK_SERVICE_;Iomega Active Disk;"D:\Program Files\Iomega\AutoDisk\ADService.exe"
R2 ATNT40K;ActiveTouch NT Appsharing Driver;D:\WINNT\system32\DRIVERS\ATNT40K.SYS
R2 cis1284;cis1284;\??\D:\WINNT\System32\drivers\cis1284.sys
R2 Tardis;Tardis time service;D:\WINNT\system32\tardisnt.exe
R3 azt2320;Aztech 2320 Audio Driver (WDM);D:\WINNT\system32\drivers\aztw2320.sys
R3 G200;G200;D:\WINNT\system32\DRIVERS\g200mini.sys
R3 NtApm;NT Apm/Legacy Interface Driver;D:\WINNT\system32\DRIVERS\NtApm.sys
S1 sglfb;sglfb;D:\WINNT\system32\drivers\sglfb.sys
S3 mga64;mga64;D:\WINNT\system32\DRIVERS\mga64m.sys
S3 NDISHOOK;NDISHOOK Protocol Driver;\??\D:\Linksys\printserver\NDISHOOK.SYS
S3 vdev;VPN-1 SecureClient Virtual Ethernet Adapter;D:\WINNT\system32\DRIVERS\vdev.sys
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-01 13:08:33
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Creative Detector = "N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" /R?v??0??????w????m???????????????????l???m?????????Q?????l????'?wm????z?w?O???????????????????????????{?w????m??????????????????w????m????????????z?w???????????w?z?w????m???????????????????????-~?w
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 10/01/2007 13:09:52
D:\ComboFix-quarantined-files.txt ... 10/01/07 01:09p
D:\ComboFix2.txt ... 10/01/07 11:24a
.
--- E O F ---
bamajim
10.4K Posts
0
October 1st, 2007 21:00
MRU Graduate
"The world is what you make of it"
Message Edited by bamajim on 10-01-2007 05:09 PM
wgkoch
8 Posts
0
October 2nd, 2007 10:00
My PC seems to be cured! Your competent help is what made this come to a conclusion!
THANK YOU for your attention and willingness to share your knowledge! It is most appreciated.
Your instructions were concise and clear.
This infection was the worst I have ever encountered with the malware able to sense
and avoid the removal actions by shutting down itself and even killing processes (lsass) to keep from getting removed.
Do you have any final instructions to clean up, delete files left over from the Combofix and/or
help me prevent future infections from these awful guys?
wgkoch
Here is the last HIJackThis log you requested:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:09 PM, on 10/1/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
F:\Program Files\Ad-Aware 2007\aawservice.exe
D:\WINNT\System32\drivers\CDAC11BA.EXE
D:\WINNT\system32\CTsvcCDA.EXE
D:\WINNT\System32\svchost.exe
D:\PROGRA~1\Iomega\System32\AppServices.exe
D:\WINNT\system32\mgabg.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\tardisnt.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
D:\WINNT\System32\ZipToA.exe
D:\Program Files\Iomega\AutoDisk\ADService.exe
D:\WINNT\System32\svchost.exe
D:\program files\iomega\DriveIcons\ImgIcon.exe
D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
D:\WINNT\system32\PDesk\PDesk.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
N:\Program files\Creative\MediaSource\Detector\CTDetect.exe
F:\Program Files\Linksys\logviewer2\LogViewer.exe
F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
D:\Program Files\WINZIP\WZQKPICK.EXE
D:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
D:\WINNT\explorer.exe
E:\EUDORA\Eudora.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://204.145.206.77/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.10.1.10:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = kochcons.com; 204.145.206.2;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MP_STATUS_MONITOR] f:\canon\multipass\monitr32.exe I
O4 - HKLM\..\Run: [MPTBox] f:\canon\multipass\MPTBox.exe
O4 - HKLM\..\Run: [Iomega Startup Options] d:\program files\iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] d:\program files\iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ADUserMon] D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Deskup] d:\program files\iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Picasa Media Detector] N:\Program files\Picasa\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\AcrobatReader\AdobeReader 8.x\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [DW4] "D:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Creative Detector] "N:\Program files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [updateMgr] "f:\Program Files\AcrobatReader\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: LogViewer.lnk = F:\Program Files\Linksys\logviewer2\LogViewer.exe
O4 - Global Startup: Microsoft Office.lnk = N:\Program files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Tardis.exe v 1.6.lnk = F:\Program Files\Tardis\T2Kv1.6\Tardis 2000\Tardis.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WINZIP\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm020YYUS
O12 - Plugin for .htm: F:\Netscape\Netscape 8\PLUGINS\npTrident.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/compaq.v2/vet_install_popup.pl?1&4&04.00.08.43-hp&http://h71016.www7.hp.com/html/interactive/xw8200/model.html?jumpid=in_r2910_3d/WKS/xw8200|3DCENTRAL|viewpoint
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/219c020c799b4e9cdf17/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175341505902
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5289C2F-5C34-4B3F-B767-36083C5C0287}: NameServer = 24.160.227.25,24.160.227.32,24.160.227.33
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - F:\Program Files\Ad-Aware 2007\aawservice.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - D:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: CWShredder Service - Trend Micro Incorporated - D:\Program Files\CoolWebShredder\cwshredder.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: hpdj - Unknown owner - F:\Temp\hpdj.exe (file missing)
O23 - Service: Iomega App Services - Iomega Corporation - D:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: IomegaAccess - Iomega Corporation - D:\WINNT\System32\IomegaAccess.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINNT\system32\mgabg.exe
O23 - Service: MPService - Unknown owner - f:\canon\multipass\mpservic.exe (file missing)
O23 - Service: Tardis time service (Tardis) - Unknown owner - D:\WINNT\system32\tardisnt.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
O23 - Service: ZipToA - Iomega Corporation - D:\WINNT\System32\ZipToA.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - D:\Program Files\Iomega\AutoDisk\ADService.exe
--
End of file - 8077 bytes
bamajim
10.4K Posts
0
October 2nd, 2007 11:00
You are most welcome
You may now remove/delete/uninstall the tools we used to clean your PC
Now that your log is clean
There are some final notes:
Make sure your Java is up to date date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
Updating Java:
Java Runtime Environment (JRE) 6.u2.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the " Download" button to the right.
Check the box that says: " Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u2-windowsi586-p.exe to install the newest version.
Make your Internet Explorer more secure
This can be done by following these simple instructions:
Click Security tab
Click once on the Internet icon so it becomes highlighted.
Click Custom Level.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click OK.
If it prompts you to save the settings, press Yes.
Next press Apply and then OK to exit the Internet Properties page
Update your Anti Virus Software
Use and maintain a Firewall There is a list HERE
All of which are free
Install IE SPYAD for protection against innocent looking websites that are not innocent
Visit Microsoft's Windows Update Site Frequently for critical updates
Backup your Important Documents and Files on a regular basis
You may want to read this article" So how did I get infected in the first place" by Tony Klein
surf safe
MRU Graduate
"The world is what you make of it"