Unsolved

This post is more than 5 years old

32 Posts

1213

March 17th, 2008 23:00

Spyware/virus trouble

i just started having major problems with my computer. It has become nearly unusable. I have tried housecall but could not get through the whole scan because of the other popups and internet being interrupted. I have tried ad-aware which helped but did not solve all the problems. I am still getting internet explorer pop ups even though i use mozilla and when i use mozilla and click on a link i am often brought to a different page trying to sell me something, if i click the back button and then try the link again it works correctly. Also i am getting a yellow triangle with an exclamation point in it which is saying that i have spyware or internet attacks and to click to solve th eproblem but it is just spyware or something along those line and finally the background of my computer also gets changed immediatly after i try to change it back. It is a blue screen that says to click the link to remove spyware. Here is my Hijackthis results thanks for taking the time to help.

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:50 PM, on 3/17/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\drivers\ctfmon.exe
C:\WINDOWS\Fonts\svchost.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: E-Zsoft VideoDownloaderToolBar - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - D:\YouTubeDownloader\VDTB.dll (file missing)
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\Run: [BMe3190abf] Rundll32.exe "C:\WINDOWS\System32\gwnicuqs.dll",s
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\mvgq-Nmcfgp,gzg (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B10E0F6-CCAA-4E7C-86E9-FEF3E54B0366}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A8C367F-1054-414E-A37C-1329F58433BD}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS2\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS3\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

4 Apprentice

 • 

20.5K Posts

March 17th, 2008 23:00



I don't have good news for you.
Your system is very infected.
The problem with these infections is that they cause a lot of damage. Even if we can clean the malware off your system, I cannot guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognize and logs won't show.
After cleaning the malware, you can still get errors afterwards because of the damage.
We can try to clean this up and do what we can, but keep in mind that we may not be able to solve ALL problems this malware already caused.

My main concern is that along with multiple infections, you have a keylogger on there which is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or possibly other useful information that could be used to compromise the system or be used in a social engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user. Keylog programs are commonly included in rootkits and RATs (remote administration trojans).

I suggest that you backup important files and reinstall everything from scratch. There are so many changes that could have been done if we find that backdoor Trojan was used.

Here are some informative links to use to help you make a decision:

Danger: Remote Access Trojans

Consumers � Identity Theft

When should I re-format? How should I reinstall?

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Rootkits: The Obscure Hacker Attack

Help: I Got Hacked. Now What Do I Do?

Help: I Got Hacked. Now What Do I Do? Part II

Microsoft Says Recovery from Malware Becoming Impossible

However, if you do not have the resources to reformat your computer and reinstall your operating system and programs and would like me to attempt to clean it, I will be happy to do so.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post.

32 Posts

March 18th, 2008 00:00

Okay all those things you mentioned are taken car of and this has not been posted on another forum.

4 Apprentice

 • 

20.5K Posts

March 18th, 2008 00:00

Okay, we'll try, but it will take a while.


While I am reviewing your log and writing up the first steps, you can help me by doing the following:

* Have you have posted this issue on another forum? If so, please provide a link to the topic.

* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.

* If this computer belongs to someone else, do you have authority to apply the fixes we will use?

* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.

** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

I look forward to your reply so we can begin.

32 Posts

March 18th, 2008 00:00

Thanks for getting back to me so soon.  I thought that this was definitly a bad situation because i have never seen a computer act this way and i consider myself to be somewhat knowledgable about computers but in this situation i find myself lost.  I would really like to attempt to try and fix these problems rather than start from scratch.  I feel that it would be worth the try because worst case scenario if it doesnt work i could still wipe out the system.  I just have soo much stuff on my computer i wouldnt even know where to begin a back up. So if you could give me some advice on where i should start to try and fix the problems or what i should do i would really appreciate it.  Thanks again

4 Apprentice

 • 

20.5K Posts

March 18th, 2008 02:00

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://download.bleepingcomputer.com/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads post the text that will open (report.txt). Close that for now.

  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (UNcheck all others.):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".

  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.


Please post that report in your next reply here along with your log from FixWareout and a fresh Hijackthis log.

32 Posts

March 18th, 2008 06:00

Here is the SUPERAntiSpyware Scan Log:

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/18/2008 at 02:01 AM

Application Version : 4.0.1154

Core Rules Database Version : 3421
Trace Rules Database Version: 1413

Scan type       : Complete Scan
Total Scan Time : 01:50:21

Memory items scanned      : 322
Memory threats detected   : 4
Registry items scanned    : 6112
Registry threats detected : 54
File items scanned        : 137835
File threats detected     : 289

Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\SSTTS.DLL
    C:\WINDOWS\SYSTEM32\SSTTS.DLL

Rogue.Unclassified/Loader
    C:\WINDOWS\SYSTEM32\MGMRWMRV.EXE
    C:\WINDOWS\SYSTEM32\MGMRWMRV.EXE
    C:\WINDOWS\TEMP\4D70.TMP

Adware.Vundo-Variant/Small-A
    C:\WINDOWS\SYSTEM32\HWOIMOPT.DLL
    C:\WINDOWS\SYSTEM32\HWOIMOPT.DLL
    HKLM\Software\Classes\CLSID\{a3b28907-fe4d-4ea3-8ccd-1fb26597bbfd}
    HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}
    HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}\InprocServer32
    HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\PKSPXWTA.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3b28907-fe4d-4ea3-8ccd-1fb26597bbfd}
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100055.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100056.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101734.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101735.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101748.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101760.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102913.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102933.DLL
    C:\WINDOWS\SYSTEM32\GITFBYEA.DLL
    C:\WINDOWS\SYSTEM32\GOLBTJBL.DLL

Trojan.Downloader-Gen/Svchost-Fake
    C:\WINDOWS\FONTS\SVCHOST.EXE
    C:\WINDOWS\FONTS\SVCHOST.EXE
    [Host Process] C:\WINDOWS\FONTS\SVCHOST.EXE

Trojan.Downloader-Gen/MROFIN
    [runner1] C:\WINDOWS\MROFINU1188.EXE
    C:\WINDOWS\MROFINU1188.EXE
    C:\WINDOWS\MROFINU1000106.EXE
    C:\WINDOWS\MROFINU1188.EXE.TMP
    C:\WINDOWS\MROFINU572.EXE.TMP

Adware.Vundo Variant
    HKLM\Software\Classes\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
    HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
    HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}\InprocServer32
    HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}\InprocServer32#ThreadingModel
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0101673.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101690.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101913.DLL

Transponder Variant BHO
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}

Unclassified.Unknown Origin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}
    C:\PROGRAM FILES\MSN\LUSI89104.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102925.EXE

Adware.2020Search
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}

Adware.180solutions/SurfAssistant
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}

Adware.Second Thought
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}
    C:\WINDOWS\BOKJA.EXE
    C:\WINDOWS\STCLOADER.EXE

Adware.Tracking Cookie
    C:\Documents and Settings\Mikee\Cookies\mikee@burstnet[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@nextag[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ad.outerinfoads[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@secure.systemerrorfixer[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@clicks.emarketmakers[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.traffic1000[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@surveys.spotsitemedia[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ehg-dig.hitbox[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.burstnet[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@mediaplex[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@media.hotels[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@gcode[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@trafficmp[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.as4x.tmcs.ticketmaster[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@angleinteractive.directtrack[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@stat.dealtime[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@288_[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@login.tracking101[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.burstbeacon[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@cdn.atwola[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@advertising[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@clckm[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@eas.apm.emediate[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@enhance[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@tagiq.clickforensics[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.realtechnetwork[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@eyewonder[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@server.cpmstar[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@paypopup[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@casalemedia[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@qnsr[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@indextools[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@clickaudit[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@traffic-tracker[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@atlas.entrepreneur[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.as4x.tmcs[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@apmebf[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adnetserver[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@cgi-bin[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@kjr72.bestrevenue[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@anad.tacoda[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@2o7[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@a[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@tribalfusion[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@zedo[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@serviceswitching[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@html[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@sale.bestsellerantivirus[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@questionmarket[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@w[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.advertyz[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adlegend[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@partners.trafficneeds[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.pointroll[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@gomyhit[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@tacoda[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@dealtime[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@fastclick[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@tradedoubler[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@indiads[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adopt.specificclick[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ad.yieldmanager[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@atdmt[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adultadworld[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@media.adrevolver[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@axxessads.valuead[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@belnk[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.monster[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@xxxbookies[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@interclick[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adrevolver[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adecn[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@partner2profit[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@revsci[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@specificclick[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.popunderserver[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ad[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@67.15.239[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@silo.thefind[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@288_[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@anat.tacoda[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@bluestreak[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.adgoto[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@avsystemcare[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@systemerrorfixer[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adbrite[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@consumergain[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@247realmedia[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ad.admarketplace[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ad1.clickhype[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adbrite[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adknowledge[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adopt.euroclick[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.addynamix[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ads.singingfool[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adserver[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adserver[3].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@adultfriendfinder[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@affiliace.directtrack[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@as-us.falkag[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@as1.falkag[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@atdmt[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ath.belnk[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@atwola[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@azjmp[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@burstnet[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@classifiedventures1.112.2o7[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@clickbank[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@counter.hitslink[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@da-tracking[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@data3.perf.overture[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@directtrack[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@doubleclick[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@edge.ru4[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ehg-bestbuy.hitbox[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@ehg-foxsports.hitbox[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@findwhat[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@hitbox[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@icc.intellisrv[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@klik.klikadvertising[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@maxserving[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@media6degrees[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@mediatraffic[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@msnportal.112.2o7[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@perf.overture[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@realmedia[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@server.cpmstar[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@service.tremormedia[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@serving-sys[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@smileycentral[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@specificclick[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@statcounter[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@stopzilla[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@tremor.adbureau[2].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.burstbeacon[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.popunderserver[1].txt
    C:\Documents and Settings\Mikee\Cookies\mikee@www.stopzilla[2].txt

32 Posts

March 18th, 2008 06:00

This is the rest of the SUPERAntiSpyware Scan Log it all didn't fit on the last post

 

Trojan.Unclassified/ZAM ENYATEL
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\InprocServer32
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\InprocServer32#ThreadingModel
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\ProgID
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\Programmable
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\TypeLib
    HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\VersionIndependentProgID

Adware.180solutions/ZangoSearch
    C:\Program Files\Zango\zango.exe
    C:\Program Files\Zango

Trojan.NetMon/DNSChange
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc
    C:\Program Files\Network Monitor
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102926.EXE

Trojan.cmdService
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
    HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc

Trojan.Unknown Origin
    HKLM\Software\xpre
    HKLM\Software\xpre#execount
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101716.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103003.VBS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103005.VBS

Adware.TrustInCash
    HKCR\Se_spoof.SpoofBHO
    HKCR\Se_spoof.SpoofBHO\CLSID
    HKCR\Se_spoof.SpoofBHO\CurVer
    HKCR\Se_spoof.SpoofBHO.1
    HKCR\Se_spoof.SpoofBHO.1\CLSID

Adware.180solutions/Seekmo
    C:\Program Files\Seekmo\seekmohook.dll
    C:\Program Files\Seekmo

Adware.ClickSpring/Outer Info Network
    C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt
    C:\Program Files\Outerinfo\FF\components
    C:\Program Files\Outerinfo\FF\install.rdf
    C:\Program Files\Outerinfo\FF
    C:\Program Files\Outerinfo\Terms.rtf
    C:\Program Files\Outerinfo

Adware.Web Buying
    HKU\.DEFAULT\Software\WebBuying
    HKU\S-1-5-21-73586283-1637723038-839522115-1003\Software\WebBuying
    HKU\S-1-5-18\Software\WebBuying

Trojan.Downloader-Gen/RetAd
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257 ]

RootKit.TnCore/Trace
    C:\WINDOWS\system32\drivers\core.cache.dsk

Browser Hijacker.Favorites
    C:\DOCUMENTS AND SETTINGS\MIKEE\FAVORITES\ONLINE SECURITY TEST.URL

Adware.ClickSpring
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\!UPDATE.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0101674.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101689.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101756.EXE

Trojan.Downloader-CommandDesktop
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\CMDINST.EXE

Rogue.LocusSoftware-Installer
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\WINVSNET.EXE

Trojan.Downloader-Gen/XRun-A
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\XPRE.EXE

Trojan.Downloader-Gen/XRun
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\XRUN.EXE

Adware.Yazzle-Installer
    C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\YAZZSNET.EXE

Adware.Rabio Search Enhancer
    C:\PROGRAM FILES\RABCO\RABCOSE.EXE
    C:\PROGRAM FILES\RABCO\X_RABCOSE.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102928.DLL
    C:\WINDOWS\SYSTEM32\D4\THUDLL5502.EXE

Adware.WebBuying Assistant
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP783\A0098962.DLL

Adware.WebBuying Assistant-Installer
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP785\A0098988.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP785\A0099031.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100445.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0100647.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103011.EXE

Adware.NoDNS
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101724.EXE

Trojan.URLChanger-Gen
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102927.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102929.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102934.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102935.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102936.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102937.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102938.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102939.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102940.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102941.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102942.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102943.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102944.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102945.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102946.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102947.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102948.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102949.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102950.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102951.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102952.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102953.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102954.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102955.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102956.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102957.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102958.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102959.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102960.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102961.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102962.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102963.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102964.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102965.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102966.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102967.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102968.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102969.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102970.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102971.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102972.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102973.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102974.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102975.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102976.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102977.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102978.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102979.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102980.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102981.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102982.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102983.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102984.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102985.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102986.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102987.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102988.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102989.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102990.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102991.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102992.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102993.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102994.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102995.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102996.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102997.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102998.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102999.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103000.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103001.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103002.DLL

Trojan.Downloader-Bot
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102930.DLL

Adware.Adservs
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103006.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP791\A0106090.DLL

Trojan.MSSHED32
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103008.EXE

Adware.ContextuAd/Kontex
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP791\A0106088.DLL

Trojan.FakeDrop-180AX
    C:\WINDOWS\180AX.EXE
    C:\WINDOWS\FLEOK\180AX.EXE

Trojan.FakeDrop-2020Search
    C:\WINDOWS\2020SEARCH.DLL
    C:\WINDOWS\2020SEARCH2.DLL

Trojan.FakeDrop-BJam
    C:\WINDOWS\BJAM.DLL

Trojan.FakeDrop-CDSM32
    C:\WINDOWS\CDSM32.DLL

Torjan.SecondThoughtInstaller
    C:\WINDOWS\INSTALLER\ID53.EXE

Trojan.FakeDrop-MSPPHE
    C:\WINDOWS\MSPPHE.DLL

Adware.Vundo Variant/Rel
    C:\WINDOWS\SYSTEM32\STTSS.INI2

Adware.Unknown Origin
    E:\FROM C DRIVE\DOCUMENTS\MIKE\MY DOCUMENTS MIKE\SCHOOL\AZESEARCH.BMP

Adware.ZToolbar
    E:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103012.DLL

Trace.Known Threat Sources
    C:\Documents and Settings\Mikee\Local Settings\Temporary Internet Files\Content.IE5\0HUIOK0H\17PHolmes[1].cmt

32 Posts

March 18th, 2008 06:00

Here is the FixWareout report:

 

 Username "Mikee" - 03/17/2008 23:53:55 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdqav.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.115.30 85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{6B10E0F6-CCAA-4E7C-86E9-FEF3E54B0366}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8A8C367F-1054-414E-A37C-1329F58433BD}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8A8C367F-1054-414E-A37C-1329F58433BD}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}
"DhcpNameServer"="85.255.115.30,85.255.112.182"
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
 
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\Temp\kdqav.ren 83456 08/29/2002

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Host Process"="C:\\WINDOWS\\Fonts\\svchost.exe"
"!AVG Anti-Spyware"="\"D:\\Program Files\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ntuser"="C:\\WINDOWS\\system32\\drivers\\ctfmon.exe"
"autoload"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\mvgq-Nmcfgp,gzg"
"e02a3923"="rundll32.exe \"C:\\WINDOWS\\System32\\hwoimopt.dll\",b"
"BMe3190abf"="Rundll32.exe \"C:\\WINDOWS\\System32\\gwnicuqs.dll\",s"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ntuser"="C:\\WINDOWS\\system32\\drivers\\ctfmon.exe"
"autoload"="C:\\Documents and Settings\\Mikee\\Local Settings\\Application Data\\mvgq-Nmcfgp,gzg"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~

32 Posts

March 18th, 2008 06:00

And this is the most recent HijackThis log hope this stuff helps

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:57 AM, on 3/18/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\ctfmon.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\Rundll32.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\Run: [BMe3190abf] Rundll32.exe "C:\WINDOWS\System32\gwnicuqs.dll",s
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\mvgq-Nmcfgp,gzg (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 5411 bytes
 

4 Apprentice

 • 

20.5K Posts

March 18th, 2008 11:00

That definitely helped, but we have more to do.

We will have to disable AVG Anti-Spyware's Guard so it does not interfere with the rest of our fixes.
Open AVG Anti-Spyware. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right-click on AVG AS in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.msc
Press "OK".
In Services, click the "Extended tab" and scroll down the list to find AVG Anti-Spyware Guard.
When you find the guard service, double-click on it.
In the Properties Window > General Tab that opens, click the "Stop" button.
From the drop-down menu next to "Startup Type", click on "Manual".
Now click "Apply", then "OK" and close the Services window. When we have verified that your computer is as clean as we can get it, you can enable AVG AS again, but not until then. As a side note, I must say that it is interesting that Super AntiSpyware was able to handle what AVG AS did not.

Please print these instructions and refer to them for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.










4 Apprentice

 • 

20.5K Posts

March 19th, 2008 02:00

So far, so good. We are making progress, but it will soon be midnight at my house. Please disconnect that computer from the internet for the night, I will reply within 10-12 hours after I write some script.

32 Posts

March 19th, 2008 02:00

Newest HiJackThis Scan log:

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:08:19 PM, on 3/18/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: E-Zsoft VideoDownloaderToolBar - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - D:\YouTubeDownloader\VDTB.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: SpoofBHO Class - {F631AAE2-4C20-11DC-8929-D3F855D89593} - C:\WINDOWS\se_spoof.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 5008 bytes
 

32 Posts

March 19th, 2008 02:00

2nd half of Combo Fix log:

 

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4322A444-92F8-4C3E-BD4C-013BA51E2871}]
            D:\YouTubeDownloader\VDTB.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F631AAE2-4C20-11DC-8929-D3F855D89593}]
            C:\WINDOWS\se_spoof.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
"SVCHOST.EXE"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"e02a3923"="C:\WINDOWS\System32\hwoimopt.dll" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"WndMsg"="C:\Program Files\Auto Keylogger\klkernel.exe" [2003-12-09 08:53 202627]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - E:\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"= NTSpool.exe
"Windows Security Tool"= WinSecure.exe

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Mikee^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Mikee\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Mikee^Start Menu^Programs^Startup^RABCO - Auto Update.lnk]
path=C:\Documents and Settings\Mikee\Start Menu\Programs\Startup\RABCO - Auto Update.lnk
backup=C:\WINDOWS\pss\RABCO - Auto Update.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-12-23 17:05 143360 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ESPN BottomLine]
C:\Program Files\ESPN\BottomLine\bline.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hffsrv]
--a------ 2006-01-25 21:11 82432 c:\windows\hffext\hffsrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2005-05-11 23:12 49152 C:\Program Files\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-12-20 20:54 278528 E:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunes_updater]
C:\WINDOWS\System32\iTunes_updater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-12-05 21:55 54832 D:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 14:44 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2005-06-08 15:24 458752 C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 15:14 217088 C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2005-07-19 17:32 221184 C:\WINDOWS\System32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
E:\Napster\napster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 14:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-02-02 14:06 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2006-11-23 14:10 56928 D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1000106.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS KHooker]
C:\WINDOWS\System32\khooker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
--a------ 2002-04-25 23:06 32768 C:\WINDOWS\sisUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-03-02 22:08 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2004-11-22 07:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.8\webbuying.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WndMsg]
--a------ 2003-12-09 08:53 202627 C:\Program Files\Auto Keylogger\klkernel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouTubeDownloader_upgrade]
D:\YouTubeDownloader\YouTubeDownloader.exe

R1 FDCENT;FDCENT;C:\WINDOWS\System32\drivers\FDCENT.SYS [2005-06-02 21:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]

*Newly Created Service* - ALG
*Newly Created Service* - IPNAT

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 14:46:31
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Adaware\aawservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-03-18 14:51:05 - machine was rebooted [Mikee]
ComboFix-quarantined-files.txt  2008-03-18 19:50:54
 

32 Posts

March 19th, 2008 02:00

Here is the first half of the ComboFix log:

 

ComboFix 08-03-17.1 - Mikee 2008-03-18 14:27:31.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.1.1252.1.1033.18.124 [GMT -5:00]
Running from: D:\downloads\ComboFix.exe
 * Created a new restore point
.
TimeOut - Windir.dat

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\RABCO
C:\Program Files\RABCO\ExecutionDll.dll
C:\Program Files\RABCO\RABCO.dll.intermediate.manifest
C:\Program Files\RABCO\RABCOse.info
C:\Program Files\RABCO\RABCOse.original
C:\Program Files\RABCO\Setup.log
C:\Program Files\RABCO\un_RABCOSetup_16230.exe
C:\Program Files\RABCO\un_RABCOSetup_16230.txt
C:\Program Files\RABCO\X_RABCOse.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\BMe3190abf.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\Downloaded Program Files\xpreload.ocx
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\mssvr.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\d4
C:\WINDOWS\system32\dkevtavc.dll
C:\WINDOWS\system32\dpjjmbfy.dll
C:\WINDOWS\system32\drivers\ati2mtagg.sys
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\e5
C:\WINDOWS\system32\fcccyyy.dll
C:\WINDOWS\system32\g7
C:\WINDOWS\system32\gebbyyv.dll
C:\WINDOWS\system32\gwnicuqs.dll
C:\WINDOWS\system32\mljijhg.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\opnljgh.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\qgnqasvt.dll
C:\WINDOWS\system32\s3
C:\WINDOWS\System32\sstts.dll
C:\WINDOWS\system32\sttss.ini
C:\WINDOWS\system32\sttss.ini2
C:\WINDOWS\system32\tuvtqol.dll
C:\WINDOWS\system32\w8
C:\WINDOWS\system32\w8\jecolb14.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\winlogon.exe
C:\x.dat
C:\z.dat

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ATI2MTAGG
-------\Service_ati2mtagg


(((((((((((((((((((((((((   Files Created from 2008-02-18 to 2008-03-18  )))))))))))))))))))))))))))))))
.

2008-03-18 00:06 . 2008-03-18 00:06   

    d--------    C:\Documents and Settings\Mikee\Application Data\SUPERAntiSpyware.com
2008-03-18 00:06 . 2008-03-18 00:06        d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 23:53 . 2008-03-18 00:02        d--------    C:\fixwareout
2008-03-17 19:52 . 2008-03-17 19:52        d--------    C:\Program Files\180solutions
2008-03-17 19:36 . 2008-03-17 19:36        d--------    C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-17 19:35 . 2008-03-18 00:05        d--------    C:\Program Files\Common Files\Wise Installation Wizard
2008-03-17 14:30 . 2008-03-18 00:03    1,360,407    ---hs----    C:\WINDOWS\system32\tpomiowh.ini
2008-03-17 00:24 . 2008-03-17 00:24        d--------    C:\Documents and Settings\Mikee\Application Data\Grisoft
2008-03-17 00:24 . 2007-05-30 07:10    10,872    --a------    C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-17 00:23 . 2008-03-17 00:23        d--------    C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-16 14:35 . 2008-03-16 14:35        d--------    C:\Program Files\Sysmnt
2008-03-16 14:35 . 2008-03-16 14:35        d--------    C:\Program Files\stc
2008-03-16 14:35 . 2008-03-16 14:35        d--------    C:\Program Files\180searchassistant
2008-03-16 14:35 . 2008-03-16 14:35        d--------    C:\Program Files\180search assistant
2008-03-16 14:27 . 2008-03-16 14:25    102,664    --a------    C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-16 14:26 . 2008-03-17 00:23    1,366,941    ---hs----    C:\WINDOWS\system32\aeybftig.ini
2008-03-16 14:25 . 2008-03-17 20:40        d--------    C:\Documents and Settings\Mikee\.housecall6.6
2008-03-16 14:21 . 2002-03-07 01:10    92,160    --ah-----    C:\WINDOWS\system32\svrhost.exe
2008-03-16 14:20 . 2002-07-01 01:00    162,816    --ah-----    C:\WINDOWS\system32\wget.exe
2008-03-16 14:20 . 2002-12-04 01:00    125,744    --ah-----    C:\WINDOWS\system32\pslist.exe
2008-03-16 14:20 . 2002-03-07 01:10    92,160    --a------    C:\WINDOWS\system32\iupdate.exe
2008-03-16 14:19 . 2008-03-16 14:19    4    --a------    C:\WINDOWS\system32\winfrun32.bin
2008-03-16 13:56 . 2008-03-16 13:56        d--------    C:\Program Files\SafeNet Sentinel
2008-03-16 13:55 . 2008-03-16 13:55        d--------    C:\Program Files\Common Files\ArcSoft
2008-03-14 22:45 . 2008-03-16 13:55        d--------    C:\Program Files\nvcoi
2008-03-14 10:46 . 2008-03-16 14:22    1,366,743    ---hs----    C:\WINDOWS\system32\amgqnpcs.ini
2008-03-14 02:47 . 2008-03-14 02:47    23,443    ---hs----    C:\WINDOWS\system32\drivers\ctfmon.exe
2008-03-14 02:46 . 2008-03-17 20:21    10,240    --a------    C:\Documents and Settings\Mikee\file.exe
2008-03-14 01:53 . 2008-03-14 01:53    47,616    --a------    C:\WINDOWS\system32\drivers\Haspnt.sys
2008-03-14 01:53 . 2008-03-14 01:53    6,656    --a------    C:\WINDOWS\system32\haspvdd.dll
2008-03-14 01:53 . 2005-09-11 20:09    2,577    --a------    C:\WINDOWS\system32\config.hsp
2008-03-14 01:53 . 2008-03-14 01:53    383    --a------    C:\WINDOWS\system32\haspdos.sys
2008-03-14 01:52 . 2004-07-14 12:54    676,864    --a------    C:\WINDOWS\system32\drivers\hardlock.sys
2008-03-14 01:50 . 2008-03-14 01:50        d--------    C:\Program Files\Common Files\SafeNet Sentinel
2008-03-13 17:45 . 2008-03-13 17:45    147,456    --a------    C:\WINDOWS\system32\vbzip10.dll
2008-03-13 17:44 . 2008-03-13 17:44    37,888    --a------    C:\WINDOWS\system32\rar.exe
2008-03-13 17:43 . 2008-03-17 00:19        d-a------    C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-13 17:42 . 2008-03-13 17:42        d--------    C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-13 17:42 . 2008-03-13 17:42    134    --a------    C:\n.bat
2008-03-13 17:41 . 2008-03-17 19:51        d--hs----    C:\WINDOWS\TWlrZQ
2008-03-13 17:41 . 2008-03-17 00:29        d--------    C:\WINDOWS\system32\iDlo18
2008-03-13 17:41 . 2008-03-13 17:41    167,545    --a------    C:\WINDOWS\system32\drivers\core.cache(7).dsk
2008-03-13 17:41 . 2008-03-13 17:41    167,545    --a------    C:\WINDOWS\system32\drivers\core.cache(6).dsk
2008-03-13 17:41 . 2008-03-13 17:41    167,545    --a------    C:\WINDOWS\system32\drivers\core.cache(5).dsk
2008-03-13 17:41 . 2008-03-13 17:41    40,960    --a------    C:\Documents and Settings\Mikee\f.exe
2008-03-09 01:11 . 2008-03-09 01:11        d---s----    C:\WINDOWS\system32\Microsoft
2008-02-27 15:43 . 2008-02-27 15:43        d--------    C:\Program Files\ESPN

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-18 02:41    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Napster
2008-03-16 18:55    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
2008-03-14 03:42    ---------    d-----w    C:\Documents and Settings\Mikee\Application Data\AdobeUM
2008-02-17 22:42    ---------    d-----w    C:\Program Files\Common Files\DVDVideoSoft
2008-02-15 07:05    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-15 06:56    ---------    d-----w    C:\Program Files\vso
2008-02-15 06:49    ---------    d-----w    C:\Documents and Settings\Mikee\Application Data\Ahead
2008-02-14 23:42    ---------    d-----w    C:\Program Files\Common Files\Download Manager
2008-02-14 23:39    ---------    d-----w    C:\Program Files\Common Files\eSellerate
2008-02-14 06:18    ---------    d-----w    C:\Program Files\Common Files\LightScribe
2008-02-14 06:18    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\LightScribe
2007-12-11 04:42    35,152    -c--a-w    C:\Documents and Settings\Mikee\Application Data\GDIPFONTCACHEV1.DAT
2007-01-10 17:15    282,632    ----a-w    C:\WINDOWS\Fonts\Setup.exe
2005-05-12 04:36    12,288    -c--a-w    C:\WINDOWS\Fonts\RandFont.dll
2006-02-04 04:49    38    -csha-w    C:\WINDOWS\system32\retadpu_senuTi.dat
.

4 Apprentice

 • 

20.5K Posts

March 19th, 2008 14:00


You had a password stealer on there. This malware/spyware is designed to steal your private information. That includes all passwords, logins to forums and your email details & other websites and most of all your Bank, Credit card or Paypal details.
It is vital that after you have been cleaned up you change all your passwords and it is necessary to get in touch with your Bank or other financial body to inform them that your details may ( probably have ) been stolen.
It also seems to be able to steal all your emails so anything you have emailed to anybody is no longer confidential.

You will find your stolen passwords are here:
C:\Qoobox\quarantine\C\Documents and Settings\User\x.dat.vir

Right-click on each to rename them:
Rename z.dat.vir to z.txt
Rename x.dat.vir to x.txt

• Move the two files back to the location where they originated from.
• Here:
C:\x.dat
C:\z.dat

You will need to see exactly WHAT was stolen and needs to be changed.
Now that they are .txt files, you should be able to open them in Notepad. Write the passwords etc.down so you can change them ASAP.

Following that, DELETE those two .txt files.

Next, please ensure that your security programs are disabled before running this.

Open Notepad and copy/paste the following text between the lines below. Do not copy the dotted lines.
** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces. It will copy correctly to Notepad if you highlight and copy as is.

-----------------------------------------------------------------------------------

File::
C:\WINDOWS\system32\tpomiowh.ini
C:\WINDOWS\system32\drivers\tmcomm.sys
C:\WINDOWS\system32\aeybftig.ini
C:\WINDOWS\system32\svrhost.exe
C:\WINDOWS\system32\wget.exe
C:\WINDOWS\system32\pslist.exe
C:\WINDOWS\system32\iupdate.exe
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\amgqnpcs.ini
C:\WINDOWS\system32\rar.exe
C:\n.bat
C:\WINDOWS\system32\drivers\core.cache(7).dsk
C:\WINDOWS\system32\drivers\core.cache(6).dsk
C:\WINDOWS\system32\drivers\core.cache(5).dsk
C:\Documents and Settings\Mikee\f.exe
C:\WINDOWS\se_spoof.dll
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\System32\hwoimopt.dll


Folder::
C:\Program Files\stc
C:\Program Files\180solutions
C:\Program Files\180searchassistant
C:\Program Files\180search assistant
C:\Program Files\nvcoi
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\TWlrZQ
C:\WINDOWS\system32\iDlo18
C:\Program Files\Auto Keylogger


Registry::
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"UsbD" =-
"e02a3923"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"WndMsg"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"=-
"Windows Security Tool"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer]
"autohx" =-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]


DirLook::
C:\WINDOWS\system32\Microsoft



----------------------------------------------------------------------------

Save this as CFScript.txt
Photobucket

Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced here: C:\ComboFix.txt

Please submit a sample of these files:

C:\Documents and Settings\Mikee\ file.exe
C:\WINDOWS\system32\ wget.exe


to Virus Total --
http://www.virustotal.com/en/indexf.html
At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendors’ scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

When you get the report, please post back the exact results along with your ComboFix log and a fresh Hijackthis log.



Please move HijackThis to your Program Files on your C drive.
Message Edited by Bugbatter on 03-19-2008 11:37 AM
No Events found!

Top