Unsolved

This post is more than 5 years old

910

November 7th, 2007 13:00

Security Toolbar 7.1 problem, vundo infection

Hi,
 
I have an Athlon 64 processor 3700+, 2.21 Ghz, 1.75 Gb ram running XP Media Center Edition v2002, Service Pack 2.
 
I have somehow managed to pick up the 'Security Toolbar 7.1' virus and would much appreciate any help you can offer.  I have tried AVG which was already running on my system, ,SUPERAntispyware along with AdAware, these all seem to find trojans but when I re-connect to the internet the false warnings reappear.
 
Many thanks,  John
 
Here is the copy of the Hijack This log.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:26:17, on 07/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS.0\eHome\ehRecvr.exe
C:\WINDOWS.0\eHome\ehSched.exe
C:\WINDOWS.0\System32\GEARSec.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS.0\system32\PSIService.exe
C:\WINDOWS.0\system32\svchost.exe
F:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS.0\system32\dllhost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\MACE.exe
C:\WINDOWS.0\eHome\ehmsas.exe
F:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS.0\vsnpstd3.exe
C:\WINDOWS.0\SOUNDMAN.EXE
C:\WINDOWS.0\CNYHKey.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
F:\Jill\NOKIAD~1\PCSUIT~1\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS.0\system32\rundll32.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS.0\system32\ctfmon.exe
F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\camtool\VideoMonitor\CamTool.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\PROGRA~1\Webshots\Webshots.scr
F:\Program Files\DigiGuide TV Guide\digiguide.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\mace.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS.0\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ATIMACE] C:\Program Files\ATI Technologies\ATI.ACE\MACE.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "F:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS.0\vsnpstd3.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\Jill\NOKIAD~1\PCSUIT~1\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RestartNeroSetup] "C:\DOCUME~1\JOHN~1.TAR\LOCALS~1\Temp\Nero Web\SetupXu.exe" MODE="update"  STARTMODE="2"  USERSEL="3"  FAMILYNAME="Nero 7"  RUNSETUPXU="1"  UPGRADE="1"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [9c921f32] rundll32.exe "C:\WINDOWS.0\system32\ohtfpklh.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Windows Registry Repair Pro] F:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: DigiGuide TV Guide.lnk = F:\Program Files\DigiGuide TV Guide\Client.exe
O4 - Startup: Webshots.lnk = F:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: camtool.lnk = C:\Program Files\camtool\VideoMonitor\CamTool.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.blueyonder.co.uk
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117fd.bay117.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - AppInit_DLLs: C:\WINDOWS.0\system32\__c0036BC9.dat
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS.0\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS.0\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS.0\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS.0\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS.0\system32\PSIService.exe
O23 - Service: V2i Protector - PowerQuest Corporation - F:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
--
End of file - 10821 bytes

10.4K Posts

November 8th, 2007 00:00


John Batcheldor

Please download Combofix and save to your desktop:
  • Note: It is important that it is saved directly to your desktop
    Close any open browsers.
    Double click on combofix.exe and follow the prompts.
    When it's finished it will produce a log.
    Post the contents of the C:\ComboFix.txt into your next reply.
    Note: Do not mouseclick combofix's window whilst it's running.
    That may cause the program to freeze/hang.
















Microsoft MVP Windows-Security



"The world is what you make of it"





November 8th, 2007 13:00

Hi, Thanks for your help,I have managed to lose the security toolbar with either avg or SUPERAntispyware but still getting occasional pop-ups. Here is the log from Combofix:-
 
ComboFix 07-11-08.1 - John 2007-11-08 14:55:05.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.519 [GMT 0:00]
Running from: C:\Documents and Settings\John.TARGA\Desktop\ComboFix.exe
 * Created a new restore point
.
 Unable to gain System Privileges
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS.0\Application Data.\salesmonitor
C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\John.TARGA\iexplorer.exe
C:\Documents and Settings\Sammie-x\iexplorer.exe
C:\Program Files\Common Files\{3C921~1
C:\Program Files\Common Files\{3C921~1\Uninst.exe
C:\Program Files\Common Files\{9C921~1
C:\svchost.exe
C:\WINDOWS.0\cookies.ini
C:\WINDOWS.0\system32\apkvjbzw.dllbox
C:\WINDOWS.0\system32\ddeeg.bak1
C:\WINDOWS.0\system32\ddeeg.bak2
C:\WINDOWS.0\system32\ddeeg.ini
C:\WINDOWS.0\system32\ddeeg.ini2
C:\WINDOWS.0\system32\ddeeg.tmp
C:\WINDOWS.0\system32\drivers\sfsync02.sys
C:\WINDOWS.0\system32\geedd.dll
C:\WINDOWS.0\system32\gehcwhor.dllbox
C:\WINDOWS.0\system32\gvgtsdji.dllbox
C:\WINDOWS.0\system32\iymrbdct.dllbox
C:\WINDOWS.0\system32\pac.txt
C:\WINDOWS.0\system32\shvaectb.dllbox
C:\z.exe
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_SFSYNC02
-------\DomainService
-------\sfsync02

(((((((((((((((((((((((((   Files Created from 2007-10-08 to 2007-11-08  )))))))))))))))))))))))))))))))
.
2007-11-08 14:52 51,200 --a------ C:\WINDOWS.0\NirCmd.exe
2007-11-08 11:31 86,080 --a------ C:\WINDOWS.0\system32\efhuwrbm.dll
2007-11-08 11:25 80,448 --a------ C:\WINDOWS.0\system32\hkfvvfcd.dll
2007-11-07 00:16   d-------- C:\Program Files\Trend Micro
2007-11-06 14:40 340,032 --a------ C:\WINDOWS.0\system32\mcgtojps.dll
2007-11-05 20:41 24,064 --a------ C:\WINDOWS.0\system32\msxml3a.dll
2007-11-05 17:05 83,008 --a------ C:\WINDOWS.0\system32\fwbkrqmj.dll
2007-11-05 15:25 83,008 --a------ C:\WINDOWS.0\system32\ljthpfob.dll
2007-11-05 15:19 85,568 --a------ C:\WINDOWS.0\system32\awgsyfcp.dll
2007-11-05 14:18 85,568 --a------ C:\WINDOWS.0\system32\fvsdhtwm.dll
2007-11-05 14:15 83,008 --a------ C:\WINDOWS.0\system32\tbfqhgca.dll
2007-11-05 11:59 85,568 --a------ C:\WINDOWS.0\system32\jqlrlmsc.dll
2007-11-05 11:59 83,008 --a------ C:\WINDOWS.0\system32\qbpobjsm.dll
2007-11-04 20:32 340,032 --a------ C:\WINDOWS.0\system32\vhstohfc.dll
2007-11-04 17:10   d-------- C:\Documents and Settings\John.TARGA\Application Data\SUPERAntiSpyware.com
2007-11-04 17:10   d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SUPERAntiSpyware.com
2007-11-03 23:56 786 --a------ C:\3124.bat
2007-11-03 23:45   d-------- C:\Documents and Settings\John.TARGA\Application Data\AdwareAlert
2007-11-03 23:38 32,768 --a------ C:\Documents and Settings\John.TARGA\pdf.exe
2007-11-03 23:38 786 --a------ C:\7296.bat
2007-11-03 17:32 4,122 --a------ C:\WINDOWS.0\system32\tmp.reg
2007-11-03 16:34   d-------- C:\Program Files\Common Files\Download Manager
2007-11-03 16:34 1,152 --a------ C:\WINDOWS.0\system32\windrv.sys
2007-11-03 10:34 340,032 --a------ C:\WINDOWS.0\system32\stwrcqfe.dll
2007-11-02 14:36   d-------- C:\Program Files\---SKRAP---
2007-11-02 14:32   d-------- C:\Documents and Settings\John.TARGA\Application Data\Canon
2007-11-01 21:10 82 --a------ C:\n.bat
2007-11-01 21:09 0 --a------ C:\z.dat
2007-11-01 17:01   d-------- C:\WINDOWS.0\system32\Mz14r
2007-11-01 16:29 147,456 --a------ C:\WINDOWS.0\system32\vbzip10.dll
2007-11-01 16:25   d-------- C:\WINDOWS.0\system32\Mz18r
2007-11-01 16:25   d-------- C:\Temp\mZOr
2007-11-01 16:24   d-a------ C:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP
2007-10-13 15:45   d-------- C:\Program Files\iTunes
2007-10-13 15:45   d-------- C:\Program Files\iPod
2007-10-13 15:44   d-------- C:\Program Files\Common Files\Apple
2007-10-13 15:39   d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Apple
2007-10-11 00:14 175,104 --a------ C:\emailstripper.exe
2007-10-10 15:56 40,733 --a------ C:\WINDOWS.0\system32\rightonadz-uninst.exe
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 15:02 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Kontiki
2007-11-08 11:20 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\AVG7
2007-11-07 17:12 --------- d-----w C:\Documents and Settings\Sammie-x\Application Data\AVG7
2007-11-05 14:17 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\uTorrent
2007-11-04 17:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-03 23:42 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\LimeWire
2007-11-02 22:15 --------- d-----w C:\Documents and Settings\Sammie-x\Application Data\LimeWire
2007-11-02 14:41 --------- d-----w C:\Program Files\---SKRAP---
2007-10-29 23:55 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg7
2007-10-24 16:48 --------- d-----w C:\Program Files\MySpace
2007-10-18 00:49 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-14 22:10 --------- d-----w C:\Program Files\Java
2007-10-13 15:45 --------- d-----w C:\Program Files\QuickTime
2007-10-13 15:39 --------- d-----w C:\Program Files\Apple Software Update
2007-10-10 14:27 94,776 ----a-w C:\Documents and Settings\John.TARGA\Application Data\GDIPFONTCACHEV1.DAT
2007-10-03 20:46 --------- d-----w C:\Program Files\Kontiki
2007-10-03 20:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Channel4
2007-09-24 18:02 --------- d-----w C:\Program Files\DOE
2007-09-24 16:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-24 16:24 --------- d-----w C:\Program Files\Idigicon Ltd
2007-06-29 21:39 93,992 ----a-w C:\Documents and Settings\Sammie-x\Application Data\GDIPFONTCACHEV1.DAT
2006-11-16 01:45 1,658 ----a-w C:\Documents and Settings\John.TARGA\Application Data\wklnhst.dat
2006-11-01 13:05 382 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb1942.dat
2006-11-01 13:00 20,480 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb4827.dat
2006-11-01 13:00 151 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb2391.dat
2006-10-31 14:30 49 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb41.dat
2006-10-31 14:13 9,216 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb8467.dat
2006-10-31 14:13 0 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb6334.dat
2006-10-31 14:13 0 ----a-w C:\Documents and Settings\John.TARGA\Application Data\internaldb5436.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d08ae7be-29e6-422d-9eb0-b68f14f96538}]
2007-11-08 11:25 80448 --a------ C:\WINDOWS.0\system32\hkfvvfcd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS.0\ehome\ehtray.exe" [2005-08-05 21:56]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43]
"ATIMACE"="C:\Program Files\ATI Technologies\ATI.ACE\MACE.exe" [2006-01-04 21:28]
"VirtualCloneDrive"="F:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 13:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"snpstd3"="C:\WINDOWS.0\vsnpstd3.exe" [2005-01-14 11:00]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 13:07 C:\WINDOWS.0\soundman.exe]
"ledpointer"="CNYHKey.exe" [2004-03-02 20:24 C:\WINDOWS.0\CNYHKey.exe]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-06-07 12:07]
"PCSuiteTrayApplication"="F:\Jill\NOKIAD~1\PCSUIT~1\NOKIAP~1\TRAYAP~1.EXE" [2004-05-21 10:41]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 12:00 C:\WINDOWS.0\system32\bthprops.cpl]
"AVG7_CC"="F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-24 08:46]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 10:23]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"9c921f32"="C:\WINDOWS.0\system32\efhuwrbm.dll" [2007-11-08 11:31]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS.0\system32\ctfmon.exe" [2004-08-10 12:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"Windows Registry Repair Pro"="F:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe" []
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 10:23]
"SUPERAntiSpyware"="F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
C:\Documents and Settings\John.TARGA\Start Menu\Programs\Startup\
DigiGuide TV Guide.lnk - F:\Program Files\DigiGuide TV Guide\Client.exe [2006-09-26 00:18:33]
Webshots.lnk - F:\Program Files\Webshots\Launcher.exe [2006-09-25 19:14:07]
C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
camtool.lnk - C:\Program Files\camtool\VideoMonitor\CamTool.exe [2006-09-26 16:37:17]
hp psc 1000 series.lnk - G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18]
hpoddt01.exe.lnk - G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS.0\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS.0\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\apkvjbzw]
apkvjbzw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gehcwhor]
gehcwhor.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gvgtsdji]
gvgtsdji.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iymrbdct]
iymrbdct.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\shvaectb]
shvaectb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnkif]
ssqnkif.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqppmj]
ssqppmj.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS.0\system32\geedd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
mHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

R0 PQV2i;PQV2i;C:\WINDOWS.0\system32\drivers\PQV2i.sys
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS.0\system32\drivers\hcw88aud.sys
R1 PQIMount;PQIMount;C:\WINDOWS.0\system32\drivers\PQIMount.sys
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS.0\system32\drivers\hcw88bda.sys
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS.0\system32\drivers\hcw88tse.sys
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS.0\system32\drivers\hcw88tun.sys
R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS.0\system32\drivers\hcw88vid.sys
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS.0\system32\drivers\HCW88BAR.sys
R3 IMT0521;Inmax USB IMT-0521 Smartcard Reader;C:\WINDOWS.0\system32\Drivers\IMT0521.sys
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS.0\system32\DRIVERS\zd1211Bu.sys
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS.0\system32\Drivers\BRGSp50.sys
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;C:\WINDOWS.0\system32\DRIVERS\SCR33X2K.sys
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS.0\system32\Drivers\usb2vcom.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a2a5479-a1d3-11da-8241-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c91297b-9c7c-11da-b3ef-806d6172696f}]
\Shell\AutoRun\command - E:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{434e4efa-776e-11db-afff-806d6172696f}]
\Shell\AutoRun\command - E:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a56568f9-4c83-11db-898c-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6f93641-9fb8-11da-8475-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4148dd3-a477-11da-a4eb-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d434c141-9dcb-11da-a54b-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A4CDB6E-36BC-3AD6-0808-000201020300}]
C:\WINDOWS.0\system32\pentntkl.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-04 03:00:00 C:\WINDOWS.0\Tasks\AdwareAlert Scheduled Scan.job"
"2007-11-05 16:24:09 C:\WINDOWS.0\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-08 11:20:04 C:\WINDOWS.0\Tasks\User_Feed_Synchronization-{C54D0EF1-08FE-47B9-9FB5-A9C9F5C3E052}.job"
- C:\WINDOWS.0\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-08 15:02:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-08 15:04:55 - machine was rebooted
.
 --- E O F ---

10.4K Posts

November 8th, 2007 14:00

John Batcheldor

You may not notice much change untill we are close to the end.

1. Open NotePad (not wordpad). Copy and paste the following into Notepad

File::
C:\WINDOWS.0\system32\efhuwrbm.dll
C:\WINDOWS.0\system32\hkfvvfcd.dll
C:\WINDOWS.0\system32\mcgtojps.dll
C:\WINDOWS.0\system32\msxml3a.dll
C:\WINDOWS.0\system32\fwbkrqmj.dll
C:\WINDOWS.0\system32\ljthpfob.dll
C:\WINDOWS.0\system32\awgsyfcp.dll
C:\WINDOWS.0\system32\fvsdhtwm.dll
C:\WINDOWS.0\system32\tbfqhgca.dll
C:\WINDOWS.0\system32\jqlrlmsc.dll
C:\WINDOWS.0\system32\qbpobjsm.dll
C:\WINDOWS.0\system32\vhstohfc.dll
C:\WINDOWS.0\system32\stwrcqfe.dll
C:\WINDOWS.0\system32\Mz14r
C:\WINDOWS.0\system32\vbzip10.dll
C:\WINDOWS.0\system32\rightonadz-uninst.exe
C:\Documents and Settings\John.TARGA\Application Data\internaldb1942.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb4827.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb2391.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb41.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb8467.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb6334.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb5436.dat
C:\WINDOWS.0\system32\pentntkl.exe

Folder::
C:\WINDOWS.0\system32\Mz18r
C:\Temp\mZOr

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d08ae7be-29e6-422d-9eb0-b68f14f96538}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SNM"=-
"9c921f32"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Registry Repair Pro"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\apkvjbzw]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gehcwhor]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gvgtsdji]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iymrbdct]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\shvaectb]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnkif]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqppmj]
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A4CDB6E-36BC-3AD6-0808-000201020300}]

Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply



Microsoft MVP Windows-Security



"The world is what you make of it"

November 8th, 2007 23:00

HI,
Hopefully I have done this ok,
 
ComboFix 07-11-08.1 - John 2007-11-09  1:47:25.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1236 [GMT 0:00]
Running from: C:\Documents and Settings\John.TARGA\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John.TARGA\Desktop\CFScript.txt
 * Created a new restore point
FILE
C:\Documents and Settings\John.TARGA\Application Data\internaldb1942.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb2391.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb41.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb4827.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb5436.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb6334.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb8467.dat
C:\WINDOWS.0\system32\awgsyfcp.dll
C:\WINDOWS.0\system32\efhuwrbm.dll
C:\WINDOWS.0\system32\fvsdhtwm.dll
C:\WINDOWS.0\system32\fwbkrqmj.dll
C:\WINDOWS.0\system32\hkfvvfcd.dll
C:\WINDOWS.0\system32\jqlrlmsc.dll
C:\WINDOWS.0\system32\ljthpfob.dll
C:\WINDOWS.0\system32\mcgtojps.dll
C:\WINDOWS.0\system32\msxml3a.dll
C:\WINDOWS.0\system32\Mz14r
C:\WINDOWS.0\system32\pentntkl.exe
C:\WINDOWS.0\system32\qbpobjsm.dll
C:\WINDOWS.0\system32\rightonadz-uninst.exe
C:\WINDOWS.0\system32\stwrcqfe.dll
C:\WINDOWS.0\system32\tbfqhgca.dll
C:\WINDOWS.0\system32\vbzip10.dll
C:\WINDOWS.0\system32\vhstohfc.dll
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\John.TARGA\Application Data\internaldb1942.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb2391.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb41.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb4827.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb5436.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb6334.dat
C:\Documents and Settings\John.TARGA\Application Data\internaldb8467.dat
C:\Temp\mZOr
C:\WINDOWS.0\cookies.ini
C:\WINDOWS.0\system32\awgsyfcp.dll
C:\WINDOWS.0\system32\efhuwrbm.dll
C:\WINDOWS.0\system32\fvsdhtwm.dll
C:\WINDOWS.0\system32\fwbkrqmj.dll
C:\WINDOWS.0\system32\hkfvvfcd.dll
C:\WINDOWS.0\system32\jqlrlmsc.dll
C:\WINDOWS.0\system32\ljthpfob.dll
C:\WINDOWS.0\system32\mcgtojps.dll
C:\WINDOWS.0\system32\msxml3a.dll
C:\WINDOWS.0\system32\Mz18r
C:\WINDOWS.0\system32\qbpobjsm.dll
C:\WINDOWS.0\system32\rightonadz-uninst.exe
C:\WINDOWS.0\system32\stwrcqfe.dll
C:\WINDOWS.0\system32\tbfqhgca.dll
C:\WINDOWS.0\system32\vbzip10.dll
C:\WINDOWS.0\system32\vhstohfc.dll
.
(((((((((((((((((((((((((   Files Created from 2007-10-09 to 2007-11-09  )))))))))))))))))))))))))))))))
.
2007-11-08 14:52 51,200 --a------ C:\WINDOWS.0\NirCmd.exe
2007-11-07 00:16   d-------- C:\Program Files\Trend Micro
2007-11-04 17:10   d-------- C:\Documents and Settings\John.TARGA\Application Data\SUPERAntiSpyware.com
2007-11-04 17:10   d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SUPERAntiSpyware.com
2007-11-03 23:56 786 --a------ C:\3124.bat
2007-11-03 23:45   d-------- C:\Documents and Settings\John.TARGA\Application Data\AdwareAlert
2007-11-03 23:38 32,768 --a------ C:\Documents and Settings\John.TARGA\pdf.exe
2007-11-03 23:38 786 --a------ C:\7296.bat
2007-11-03 17:32 4,122 --a------ C:\WINDOWS.0\system32\tmp.reg
2007-11-03 16:34   d-------- C:\Program Files\Common Files\Download Manager
2007-11-03 16:34 1,152 --a------ C:\WINDOWS.0\system32\windrv.sys
2007-11-02 14:36   d-------- C:\Program Files\---SKRAP---
2007-11-02 14:32   d-------- C:\Documents and Settings\John.TARGA\Application Data\Canon
2007-11-01 21:10 82 --a------ C:\n.bat
2007-11-01 21:09 0 --a------ C:\z.dat
2007-11-01 17:01   d-------- C:\WINDOWS.0\system32\Mz14r
2007-11-01 16:24   d-a------ C:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP
2007-10-13 15:45   d-------- C:\Program Files\iTunes
2007-10-13 15:45   d-------- C:\Program Files\iPod
2007-10-13 15:44   d-------- C:\Program Files\Common Files\Apple
2007-10-13 15:39   d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Apple
2007-10-11 00:14 175,104 --a------ C:\emailstripper.exe
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 01:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Kontiki
2007-11-08 16:03 --------- d-----w C:\Documents and Settings\Sammie-x\Application Data\AVG7
2007-11-08 11:20 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\AVG7
2007-11-05 14:17 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\uTorrent
2007-11-04 17:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-03 23:42 --------- d-----w C:\Documents and Settings\John.TARGA\Application Data\LimeWire
2007-11-02 22:15 --------- d-----w C:\Documents and Settings\Sammie-x\Application Data\LimeWire
2007-11-02 14:41 --------- d-----w C:\Program Files\---SKRAP---
2007-10-29 23:55 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg7
2007-10-24 16:48 --------- d-----w C:\Program Files\MySpace
2007-10-18 00:49 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-14 22:10 --------- d-----w C:\Program Files\Java
2007-10-13 15:45 --------- d-----w C:\Program Files\QuickTime
2007-10-13 15:39 --------- d-----w C:\Program Files\Apple Software Update
2007-10-10 14:27 94,776 ----a-w C:\Documents and Settings\John.TARGA\Application Data\GDIPFONTCACHEV1.DAT
2007-10-03 20:46 --------- d-----w C:\Program Files\Kontiki
2007-10-03 20:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Channel4
2007-09-24 18:02 --------- d-----w C:\Program Files\DOE
2007-09-24 16:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-24 16:24 --------- d-----w C:\Program Files\Idigicon Ltd
2007-06-29 21:39 93,992 ----a-w C:\Documents and Settings\Sammie-x\Application Data\GDIPFONTCACHEV1.DAT
2006-11-16 01:45 1,658 ----a-w C:\Documents and Settings\John.TARGA\Application Data\wklnhst.dat
.
(((((((((((((((((((((((((((((   snapshot@2007-11-08_15.03.32.68   )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-09 01:51:27 16,384 ----atw C:\WINDOWS.0\Temp\Perflib_Perfdata_624.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS.0\ehome\ehtray.exe" [2005-08-05 21:56]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43]
"ATIMACE"="C:\Program Files\ATI Technologies\ATI.ACE\MACE.exe" [2006-01-04 21:28]
"VirtualCloneDrive"="F:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 13:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"snpstd3"="C:\WINDOWS.0\vsnpstd3.exe" [2005-01-14 11:00]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 13:07 C:\WINDOWS.0\soundman.exe]
"ledpointer"="CNYHKey.exe" [2004-03-02 20:24 C:\WINDOWS.0\CNYHKey.exe]
"DataLayer"="C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE" [2004-06-07 12:07]
"PCSuiteTrayApplication"="F:\Jill\NOKIAD~1\PCSUIT~1\NOKIAP~1\TRAYAP~1.EXE" [2004-05-21 10:41]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 12:00 C:\WINDOWS.0\system32\bthprops.cpl]
"AVG7_CC"="F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-24 08:46]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 10:23]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS.0\system32\ctfmon.exe" [2004-08-10 12:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 10:23]
"SUPERAntiSpyware"="F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
C:\Documents and Settings\John.TARGA\Start Menu\Programs\Startup\
DigiGuide TV Guide.lnk - F:\Program Files\DigiGuide TV Guide\Client.exe [2006-09-26 00:18:33]
Webshots.lnk - F:\Program Files\Webshots\Launcher.exe [2006-09-25 19:14:07]
C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
camtool.lnk - C:\Program Files\camtool\VideoMonitor\CamTool.exe [2006-09-26 16:37:17]
hp psc 1000 series.lnk - G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18]
hpoddt01.exe.lnk - G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS.0\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS.0\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
mHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

R0 PQV2i;PQV2i;C:\WINDOWS.0\system32\drivers\PQV2i.sys
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS.0\system32\drivers\hcw88aud.sys
R1 PQIMount;PQIMount;C:\WINDOWS.0\system32\drivers\PQIMount.sys
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS.0\system32\drivers\hcw88bda.sys
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS.0\system32\drivers\hcw88tse.sys
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS.0\system32\drivers\hcw88tun.sys
R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS.0\system32\drivers\hcw88vid.sys
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS.0\system32\drivers\HCW88BAR.sys
R3 IMT0521;Inmax USB IMT-0521 Smartcard Reader;C:\WINDOWS.0\system32\Drivers\IMT0521.sys
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS.0\system32\DRIVERS\zd1211Bu.sys
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS.0\system32\Drivers\BRGSp50.sys
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;C:\WINDOWS.0\system32\DRIVERS\SCR33X2K.sys
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS.0\system32\Drivers\usb2vcom.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a2a5479-a1d3-11da-8241-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c91297b-9c7c-11da-b3ef-806d6172696f}]
\Shell\AutoRun\command - E:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{434e4efa-776e-11db-afff-806d6172696f}]
\Shell\AutoRun\command - E:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a56568f9-4c83-11db-898c-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6f93641-9fb8-11da-8475-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4148dd3-a477-11da-a4eb-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d434c141-9dcb-11da-a54b-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-04 03:00:00 C:\WINDOWS.0\Tasks\AdwareAlert Scheduled Scan.job"
"2007-11-05 16:24:09 C:\WINDOWS.0\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-08 11:20:04 C:\WINDOWS.0\Tasks\User_Feed_Synchronization-{C54D0EF1-08FE-47B9-9FB5-A9C9F5C3E052}.job"
- C:\WINDOWS.0\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-09 01:51:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-09  1:54:53 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-08 15:04
.
 --- E O F ---

10.4K Posts

November 9th, 2007 11:00

John Batcheldor

Yes you did it right. That got quite a bit of it. But we still have a little work to do.

Run an online virus scan called Kaspersky from HERE.
  • 1. Click on " Kaspersky Online Scanner"
    2. A new smaller window will pop up. Press on " Accept". After reading the contents.
    3. Now Kaspersky will update the anti-virus database. Let it run.
    4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
    5. Then click on " My Computer". And the scan will start.
    6. When the scan is complete Select "Save error report as"
    Then in the file name just type in kaspersky
    Under "save as type" select text .txt
    Save it to your Desktop.








Copy and post the results of the Kaspersky Online scan

==========

Note: For IE7 uers. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

















Microsoft MVP Windows-Security



"The world is what you make of it"




No Events found!

Top