Unsolved
This post is more than 5 years old
32 Posts
0
1213
March 17th, 2008 23:00
Spyware/virus trouble
i just started having major problems with my computer. It has become nearly unusable. I have tried housecall but could not get through the whole scan because of the other popups and internet being interrupted. I have tried ad-aware which helped but did not solve all the problems. I am still getting internet explorer pop ups even though i use mozilla and when i use mozilla and click on a link i am often brought to a different page trying to sell me something, if i click the back button and then try the link again it works correctly. Also i am getting a yellow triangle with an exclamation point in it which is saying that i have spyware or internet attacks and to click to solve th eproblem but it is just spyware or something along those line and finally the background of my computer also gets changed immediatly after i try to change it back. It is a blue screen that says to click the link to remove spyware. Here is my Hijackthis results thanks for taking the time to help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:50 PM, on 3/17/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\drivers\ctfmon.exe
C:\WINDOWS\Fonts\svchost.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: E-Zsoft VideoDownloaderToolBar - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - D:\YouTubeDownloader\VDTB.dll (file missing)
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\Run: [BMe3190abf] Rundll32.exe "C:\WINDOWS\System32\gwnicuqs.dll",s
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\mvgq-Nmcfgp,gzg (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B10E0F6-CCAA-4E7C-86E9-FEF3E54B0366}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A8C367F-1054-414E-A37C-1329F58433BD}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS2\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS3\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


Bugbatter
4 Apprentice
•
20.5K Posts
0
March 17th, 2008 23:00
I don't have good news for you.
Your system is very infected.
The problem with these infections is that they cause a lot of damage. Even if we can clean the malware off your system, I cannot guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognize and logs won't show.
After cleaning the malware, you can still get errors afterwards because of the damage.
We can try to clean this up and do what we can, but keep in mind that we may not be able to solve ALL problems this malware already caused.
My main concern is that along with multiple infections, you have a keylogger on there which is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or possibly other useful information that could be used to compromise the system or be used in a social engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user. Keylog programs are commonly included in rootkits and RATs (remote administration trojans).
I suggest that you backup important files and reinstall everything from scratch. There are so many changes that could have been done if we find that backdoor Trojan was used.
Here are some informative links to use to help you make a decision:
Danger: Remote Access Trojans
Consumers � Identity Theft
When should I re-format? How should I reinstall?
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
Rootkits: The Obscure Hacker Attack
Help: I Got Hacked. Now What Do I Do?
Help: I Got Hacked. Now What Do I Do? Part II
Microsoft Says Recovery from Malware Becoming Impossible
However, if you do not have the resources to reformat your computer and reinstall your operating system and programs and would like me to attempt to clean it, I will be happy to do so.
Should you have any questions, please feel free to ask.
Please let us know what you have decided to do in your next post.
mike3883
32 Posts
0
March 18th, 2008 00:00
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 18th, 2008 00:00
While I am reviewing your log and writing up the first steps, you can help me by doing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I look forward to your reply so we can begin.
mike3883
32 Posts
0
March 18th, 2008 00:00
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 18th, 2008 02:00
http://downloads.subratam.org/Fixwareout.exe
http://download.bleepingcomputer.com/lonny/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads post the text that will open (report.txt). Close that for now.
Please post that report in your next reply here along with your log from FixWareout and a fresh Hijackthis log.
mike3883
32 Posts
0
March 18th, 2008 06:00
Here is the SUPERAntiSpyware Scan Log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 03/18/2008 at 02:01 AM
Application Version : 4.0.1154
Core Rules Database Version : 3421
Trace Rules Database Version: 1413
Scan type : Complete Scan
Total Scan Time : 01:50:21
Memory items scanned : 322
Memory threats detected : 4
Registry items scanned : 6112
Registry threats detected : 54
File items scanned : 137835
File threats detected : 289
Adware.Vundo Variant/Resident
C:\WINDOWS\SYSTEM32\SSTTS.DLL
C:\WINDOWS\SYSTEM32\SSTTS.DLL
Rogue.Unclassified/Loader
C:\WINDOWS\SYSTEM32\MGMRWMRV.EXE
C:\WINDOWS\SYSTEM32\MGMRWMRV.EXE
C:\WINDOWS\TEMP\4D70.TMP
Adware.Vundo-Variant/Small-A
C:\WINDOWS\SYSTEM32\HWOIMOPT.DLL
C:\WINDOWS\SYSTEM32\HWOIMOPT.DLL
HKLM\Software\Classes\CLSID\{a3b28907-fe4d-4ea3-8ccd-1fb26597bbfd}
HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}
HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}\InprocServer32
HKCR\CLSID\{A3B28907-FE4D-4EA3-8CCD-1FB26597BBFD}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\PKSPXWTA.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3b28907-fe4d-4ea3-8ccd-1fb26597bbfd}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100055.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100056.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101734.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101735.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101748.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101760.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102913.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102933.DLL
C:\WINDOWS\SYSTEM32\GITFBYEA.DLL
C:\WINDOWS\SYSTEM32\GOLBTJBL.DLL
Trojan.Downloader-Gen/Svchost-Fake
C:\WINDOWS\FONTS\SVCHOST.EXE
C:\WINDOWS\FONTS\SVCHOST.EXE
[Host Process] C:\WINDOWS\FONTS\SVCHOST.EXE
Trojan.Downloader-Gen/MROFIN
[runner1] C:\WINDOWS\MROFINU1188.EXE
C:\WINDOWS\MROFINU1188.EXE
C:\WINDOWS\MROFINU1000106.EXE
C:\WINDOWS\MROFINU1188.EXE.TMP
C:\WINDOWS\MROFINU572.EXE.TMP
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}\InprocServer32
HKCR\CLSID\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CFEA5A87-D7A3-4829-9406-ADD2DC7BCBC9}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0101673.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101690.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101913.DLL
Transponder Variant BHO
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}
Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}
C:\PROGRAM FILES\MSN\LUSI89104.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102925.EXE
Adware.2020Search
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}
Adware.180solutions/SurfAssistant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}
Adware.Second Thought
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}
C:\WINDOWS\BOKJA.EXE
C:\WINDOWS\STCLOADER.EXE
Adware.Tracking Cookie
C:\Documents and Settings\Mikee\Cookies\mikee@burstnet[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@nextag[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ad.outerinfoads[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@secure.systemerrorfixer[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@clicks.emarketmakers[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.traffic1000[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@surveys.spotsitemedia[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ehg-dig.hitbox[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.burstnet[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@mediaplex[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@media.hotels[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@gcode[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@trafficmp[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.as4x.tmcs.ticketmaster[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@angleinteractive.directtrack[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@stat.dealtime[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@288_[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@login.tracking101[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.burstbeacon[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@cdn.atwola[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@advertising[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@clckm[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@eas.apm.emediate[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@enhance[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@tagiq.clickforensics[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.realtechnetwork[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@eyewonder[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@server.cpmstar[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@paypopup[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@casalemedia[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@qnsr[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@indextools[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@clickaudit[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@traffic-tracker[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@atlas.entrepreneur[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@apmebf[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adnetserver[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@cgi-bin[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@kjr72.bestrevenue[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@anad.tacoda[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@2o7[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@a[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@tribalfusion[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@zedo[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@serviceswitching[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@html[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@sale.bestsellerantivirus[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@questionmarket[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@w[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.advertyz[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adlegend[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@partners.trafficneeds[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.pointroll[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@gomyhit[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@tacoda[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@dealtime[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@fastclick[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@tradedoubler[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@indiads[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adopt.specificclick[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ad.yieldmanager[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@atdmt[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adultadworld[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@media.adrevolver[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@axxessads.valuead[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@belnk[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.monster[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@xxxbookies[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@interclick[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adrevolver[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adecn[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@partner2profit[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@revsci[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@specificclick[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.popunderserver[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ad[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@67.15.239[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@silo.thefind[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@288_[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@anat.tacoda[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@bluestreak[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.adgoto[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@avsystemcare[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@systemerrorfixer[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adbrite[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@consumergain[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@247realmedia[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ad.admarketplace[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ad1.clickhype[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adbrite[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adknowledge[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adopt.euroclick[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.addynamix[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ads.singingfool[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adserver[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adserver[3].txt
C:\Documents and Settings\Mikee\Cookies\mikee@adultfriendfinder[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@affiliace.directtrack[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@as-us.falkag[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@as1.falkag[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@atdmt[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ath.belnk[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@atwola[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@azjmp[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@burstnet[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@classifiedventures1.112.2o7[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@clickbank[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@counter.hitslink[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@da-tracking[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@data3.perf.overture[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@directtrack[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@doubleclick[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@edge.ru4[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@ehg-foxsports.hitbox[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@findwhat[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@hitbox[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@icc.intellisrv[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@klik.klikadvertising[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@maxserving[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@media6degrees[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@mediatraffic[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@msnportal.112.2o7[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@perf.overture[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@realmedia[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@server.cpmstar[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@service.tremormedia[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@serving-sys[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@smileycentral[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@specificclick[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@statcounter[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@stopzilla[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@tremor.adbureau[2].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.burstbeacon[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.popunderserver[1].txt
C:\Documents and Settings\Mikee\Cookies\mikee@www.stopzilla[2].txt
mike3883
32 Posts
0
March 18th, 2008 06:00
This is the rest of the SUPERAntiSpyware Scan Log it all didn't fit on the last post
Trojan.Unclassified/ZAM ENYATEL
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\InprocServer32
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\InprocServer32#ThreadingModel
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\ProgID
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\Programmable
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\TypeLib
HKCR\CLSID\{4C03732F-43BB-4D80-BA45-66FD05DB11DF}\VersionIndependentProgID
Adware.180solutions/ZangoSearch
C:\Program Files\Zango\zango.exe
C:\Program Files\Zango
Trojan.NetMon/DNSChange
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc
C:\Program Files\Network Monitor
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102926.EXE
Trojan.cmdService
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc
Trojan.Unknown Origin
HKLM\Software\xpre
HKLM\Software\xpre#execount
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101716.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103003.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103005.VBS
Adware.TrustInCash
HKCR\Se_spoof.SpoofBHO
HKCR\Se_spoof.SpoofBHO\CLSID
HKCR\Se_spoof.SpoofBHO\CurVer
HKCR\Se_spoof.SpoofBHO.1
HKCR\Se_spoof.SpoofBHO.1\CLSID
Adware.180solutions/Seekmo
C:\Program Files\Seekmo\seekmohook.dll
C:\Program Files\Seekmo
Adware.ClickSpring/Outer Info Network
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\Outerinfo\FF\components
C:\Program Files\Outerinfo\FF\install.rdf
C:\Program Files\Outerinfo\FF
C:\Program Files\Outerinfo\Terms.rtf
C:\Program Files\Outerinfo
Adware.Web Buying
HKU\.DEFAULT\Software\WebBuying
HKU\S-1-5-21-73586283-1637723038-839522115-1003\Software\WebBuying
HKU\S-1-5-18\Software\WebBuying
Trojan.Downloader-Gen/RetAd
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257 ]
RootKit.TnCore/Trace
C:\WINDOWS\system32\drivers\core.cache.dsk
Browser Hijacker.Favorites
C:\DOCUMENTS AND SETTINGS\MIKEE\FAVORITES\ONLINE SECURITY TEST.URL
Adware.ClickSpring
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\!UPDATE.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0101674.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101689.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101756.EXE
Trojan.Downloader-CommandDesktop
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\CMDINST.EXE
Rogue.LocusSoftware-Installer
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\WINVSNET.EXE
Trojan.Downloader-Gen/XRun-A
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\XPRE.EXE
Trojan.Downloader-Gen/XRun
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\XRUN.EXE
Adware.Yazzle-Installer
C:\DOCUMENTS AND SETTINGS\MIKEE\LOCAL SETTINGS\TEMP\YAZZSNET.EXE
Adware.Rabio Search Enhancer
C:\PROGRAM FILES\RABCO\RABCOSE.EXE
C:\PROGRAM FILES\RABCO\X_RABCOSE.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102928.DLL
C:\WINDOWS\SYSTEM32\D4\THUDLL5502.EXE
Adware.WebBuying Assistant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP783\A0098962.DLL
Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP785\A0098988.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP785\A0099031.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP787\A0100445.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP789\A0100647.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103011.EXE
Adware.NoDNS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0101724.EXE
Trojan.URLChanger-Gen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102927.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102929.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102934.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102935.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102936.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102937.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102938.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102939.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102940.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102941.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102942.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102943.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102944.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102945.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102946.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102947.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102948.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102949.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102950.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102951.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102952.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102953.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102954.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102955.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102956.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102957.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102958.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102959.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102960.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102961.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102962.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102963.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102964.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102965.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102966.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102967.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102968.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102969.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102970.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102971.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102972.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102973.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102974.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102975.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102976.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102977.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102978.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102979.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102980.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102981.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102982.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102983.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102984.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102985.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102986.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102987.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102988.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102989.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102990.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102991.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102992.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102993.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102994.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102995.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102996.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102997.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102998.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102999.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103000.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103001.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103002.DLL
Trojan.Downloader-Bot
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0102930.DLL
Adware.Adservs
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103006.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP791\A0106090.DLL
Trojan.MSSHED32
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103008.EXE
Adware.ContextuAd/Kontex
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP791\A0106088.DLL
Trojan.FakeDrop-180AX
C:\WINDOWS\180AX.EXE
C:\WINDOWS\FLEOK\180AX.EXE
Trojan.FakeDrop-2020Search
C:\WINDOWS\2020SEARCH.DLL
C:\WINDOWS\2020SEARCH2.DLL
Trojan.FakeDrop-BJam
C:\WINDOWS\BJAM.DLL
Trojan.FakeDrop-CDSM32
C:\WINDOWS\CDSM32.DLL
Torjan.SecondThoughtInstaller
C:\WINDOWS\INSTALLER\ID53.EXE
Trojan.FakeDrop-MSPPHE
C:\WINDOWS\MSPPHE.DLL
Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\STTSS.INI2
Adware.Unknown Origin
E:\FROM C DRIVE\DOCUMENTS\MIKE\MY DOCUMENTS MIKE\SCHOOL\AZESEARCH.BMP
Adware.ZToolbar
E:\SYSTEM VOLUME INFORMATION\_RESTORE{1A7DE26B-62B5-4D6A-A716-98957854FF1E}\RP790\A0103012.DLL
Trace.Known Threat Sources
C:\Documents and Settings\Mikee\Local Settings\Temporary Internet Files\Content.IE5\0HUIOK0H\17PHolmes[1].cmt
mike3883
32 Posts
0
March 18th, 2008 06:00
Here is the FixWareout report:
Username "Mikee" - 03/17/2008 23:53:55 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdqav.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.115.30 85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{6B10E0F6-CCAA-4E7C-86E9-FEF3E54B0366}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8A8C367F-1054-414E-A37C-1329F58433BD}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}
"nameserver"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8A8C367F-1054-414E-A37C-1329F58433BD}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A56663AA-08FF-4CE4-A967-BFA96FC51A0C}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BA7C6C72-122B-4D7C-BA2A-CF1889991B2A}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{EB4FB6E9-D81E-4A5C-88BB-93C06224483A}
"DhcpNameServer"="85.255.115.30,85.255.112.182" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECABEE4F-2EFC-43A8-8B64-21EFECA3B2CA}
"DhcpNameServer"="85.255.115.30,85.255.112.182"
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\Temp\kdqav.ren 83456 08/29/2002
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Host Process"="C:\\WINDOWS\\Fonts\\svchost.exe"
"!AVG Anti-Spyware"="\"D:\\Program Files\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ntuser"="C:\\WINDOWS\\system32\\drivers\\ctfmon.exe"
"autoload"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\mvgq-Nmcfgp,gzg"
"e02a3923"="rundll32.exe \"C:\\WINDOWS\\System32\\hwoimopt.dll\",b"
"BMe3190abf"="Rundll32.exe \"C:\\WINDOWS\\System32\\gwnicuqs.dll\",s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ntuser"="C:\\WINDOWS\\system32\\drivers\\ctfmon.exe"
"autoload"="C:\\Documents and Settings\\Mikee\\Local Settings\\Application Data\\mvgq-Nmcfgp,gzg"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
mike3883
32 Posts
0
March 18th, 2008 06:00
And this is the most recent HijackThis log hope this stuff helps
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:57 AM, on 3/18/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\ctfmon.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\Rundll32.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\Run: [BMe3190abf] Rundll32.exe "C:\WINDOWS\System32\gwnicuqs.dll",s
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Mikee\Local Settings\Application Data\mvgq-Nmcfgp,gzg
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\mvgq-Nmcfgp,gzg (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\ctfmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 5411 bytes
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 18th, 2008 11:00
We will have to disable AVG Anti-Spyware's Guard so it does not interfere with the rest of our fixes.
Open AVG Anti-Spyware. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right-click on AVG AS in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.msc
Press "OK".
In Services, click the "Extended tab" and scroll down the list to find AVG Anti-Spyware Guard.
When you find the guard service, double-click on it.
In the Properties Window > General Tab that opens, click the "Stop" button.
From the drop-down menu next to "Startup Type", click on "Manual".
Now click "Apply", then "OK" and close the Services window. When we have verified that your computer is as clean as we can get it, you can enable AVG AS again, but not until then. As a side note, I must say that it is interesting that Super AntiSpyware was able to handle what AVG AS did not.
Please print these instructions and refer to them for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 19th, 2008 02:00
mike3883
32 Posts
0
March 19th, 2008 02:00
Newest HiJackThis Scan log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:08:19 PM, on 3/18/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Adaware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0yahoo&bm=yh_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: E-Zsoft VideoDownloaderToolBar - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - D:\YouTubeDownloader\VDTB.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: SpoofBHO Class - {F631AAE2-4C20-11DC-8929-D3F855D89593} - C:\WINDOWS\se_spoof.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [e02a3923] rundll32.exe "C:\WINDOWS\System32\hwoimopt.dll",b
O4 - HKLM\..\RunServices: [WndMsg] C:\Program Files\Auto Keylogger\klkernel.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.182
O17 - HKLM\System\CS1\Services\Tcpip\..\{24B0A605-ED58-47DE-9E5A-7BFF441B218E}: NameServer = 85.255.115.30,85.255.112.182
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Adaware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - E:\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 5008 bytes
mike3883
32 Posts
0
March 19th, 2008 02:00
2nd half of Combo Fix log:
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4322A444-92F8-4C3E-BD4C-013BA51E2871}]
D:\YouTubeDownloader\VDTB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F631AAE2-4C20-11DC-8929-D3F855D89593}]
C:\WINDOWS\se_spoof.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
"SVCHOST.EXE"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"e02a3923"="C:\WINDOWS\System32\hwoimopt.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"WndMsg"="C:\Program Files\Auto Keylogger\klkernel.exe" [2003-12-09 08:53 202627]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - E:\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"= NTSpool.exe
"Windows Security Tool"= WinSecure.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mikee^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Mikee\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Mikee^Start Menu^Programs^Startup^RABCO - Auto Update.lnk]
path=C:\Documents and Settings\Mikee\Start Menu\Programs\Startup\RABCO - Auto Update.lnk
backup=C:\WINDOWS\pss\RABCO - Auto Update.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-12-23 17:05 143360 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ESPN BottomLine]
C:\Program Files\ESPN\BottomLine\bline.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hffsrv]
--a------ 2006-01-25 21:11 82432 c:\windows\hffext\hffsrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2005-05-11 23:12 49152 C:\Program Files\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-12-20 20:54 278528 E:\itunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunes_updater]
C:\WINDOWS\System32\iTunes_updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-12-05 21:55 54832 D:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 14:44 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2005-06-08 15:24 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 15:14 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2005-07-19 17:32 221184 C:\WINDOWS\System32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
E:\Napster\napster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 14:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-02-02 14:06 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2006-11-23 14:10 56928 D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1000106.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS KHooker]
C:\WINDOWS\System32\khooker.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
--a------ 2002-04-25 23:06 32768 C:\WINDOWS\sisUSBrg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-03-02 22:08 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2004-11-22 07:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.8\webbuying.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WndMsg]
--a------ 2003-12-09 08:53 202627 C:\Program Files\Auto Keylogger\klkernel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouTubeDownloader_upgrade]
D:\YouTubeDownloader\YouTubeDownloader.exe
R1 FDCENT;FDCENT;C:\WINDOWS\System32\drivers\FDCENT.SYS [2005-06-02 21:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 14:46:31
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Adaware\aawservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-03-18 14:51:05 - machine was rebooted [Mikee]
ComboFix-quarantined-files.txt 2008-03-18 19:50:54
mike3883
32 Posts
0
March 19th, 2008 02:00
Here is the first half of the ComboFix log:
ComboFix 08-03-17.1 - Mikee 2008-03-18 14:27:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.124 [GMT -5:00]
Running from: D:\downloads\ComboFix.exe
* Created a new restore point
.
TimeOut - Windir.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\RABCO
C:\Program Files\RABCO\ExecutionDll.dll
C:\Program Files\RABCO\RABCO.dll.intermediate.manifest
C:\Program Files\RABCO\RABCOse.info
C:\Program Files\RABCO\RABCOse.original
C:\Program Files\RABCO\Setup.log
C:\Program Files\RABCO\un_RABCOSetup_16230.exe
C:\Program Files\RABCO\un_RABCOSetup_16230.txt
C:\Program Files\RABCO\X_RABCOse.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\BMe3190abf.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\Downloaded Program Files\xpreload.ocx
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\mssvr.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\d4
C:\WINDOWS\system32\dkevtavc.dll
C:\WINDOWS\system32\dpjjmbfy.dll
C:\WINDOWS\system32\drivers\ati2mtagg.sys
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\e5
C:\WINDOWS\system32\fcccyyy.dll
C:\WINDOWS\system32\g7
C:\WINDOWS\system32\gebbyyv.dll
C:\WINDOWS\system32\gwnicuqs.dll
C:\WINDOWS\system32\mljijhg.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\opnljgh.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\qgnqasvt.dll
C:\WINDOWS\system32\s3
C:\WINDOWS\System32\sstts.dll
C:\WINDOWS\system32\sttss.ini
C:\WINDOWS\system32\sttss.ini2
C:\WINDOWS\system32\tuvtqol.dll
C:\WINDOWS\system32\w8
C:\WINDOWS\system32\w8\jecolb14.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\winlogon.exe
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATI2MTAGG
-------\Service_ati2mtagg
((((((((((((((((((((((((( Files Created from 2008-02-18 to 2008-03-18 )))))))))))))))))))))))))))))))
.
2008-03-18 00:06 . 2008-03-18 00:06
2008-03-18 00:06 . 2008-03-18 00:06
2008-03-17 23:53 . 2008-03-18 00:02
2008-03-17 19:52 . 2008-03-17 19:52
2008-03-17 19:36 . 2008-03-17 19:36
2008-03-17 19:35 . 2008-03-18 00:05
2008-03-17 14:30 . 2008-03-18 00:03 1,360,407 ---hs---- C:\WINDOWS\system32\tpomiowh.ini
2008-03-17 00:24 . 2008-03-17 00:24
2008-03-17 00:24 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-17 00:23 . 2008-03-17 00:23
2008-03-16 14:35 . 2008-03-16 14:35
2008-03-16 14:35 . 2008-03-16 14:35
2008-03-16 14:35 . 2008-03-16 14:35
2008-03-16 14:35 . 2008-03-16 14:35
2008-03-16 14:27 . 2008-03-16 14:25 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-16 14:26 . 2008-03-17 00:23 1,366,941 ---hs---- C:\WINDOWS\system32\aeybftig.ini
2008-03-16 14:25 . 2008-03-17 20:40
2008-03-16 14:21 . 2002-03-07 01:10 92,160 --ah----- C:\WINDOWS\system32\svrhost.exe
2008-03-16 14:20 . 2002-07-01 01:00 162,816 --ah----- C:\WINDOWS\system32\wget.exe
2008-03-16 14:20 . 2002-12-04 01:00 125,744 --ah----- C:\WINDOWS\system32\pslist.exe
2008-03-16 14:20 . 2002-03-07 01:10 92,160 --a------ C:\WINDOWS\system32\iupdate.exe
2008-03-16 14:19 . 2008-03-16 14:19 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-03-16 13:56 . 2008-03-16 13:56
2008-03-16 13:55 . 2008-03-16 13:55
2008-03-14 22:45 . 2008-03-16 13:55
2008-03-14 10:46 . 2008-03-16 14:22 1,366,743 ---hs---- C:\WINDOWS\system32\amgqnpcs.ini
2008-03-14 02:47 . 2008-03-14 02:47 23,443 ---hs---- C:\WINDOWS\system32\drivers\ctfmon.exe
2008-03-14 02:46 . 2008-03-17 20:21 10,240 --a------ C:\Documents and Settings\Mikee\file.exe
2008-03-14 01:53 . 2008-03-14 01:53 47,616 --a------ C:\WINDOWS\system32\drivers\Haspnt.sys
2008-03-14 01:53 . 2008-03-14 01:53 6,656 --a------ C:\WINDOWS\system32\haspvdd.dll
2008-03-14 01:53 . 2005-09-11 20:09 2,577 --a------ C:\WINDOWS\system32\config.hsp
2008-03-14 01:53 . 2008-03-14 01:53 383 --a------ C:\WINDOWS\system32\haspdos.sys
2008-03-14 01:52 . 2004-07-14 12:54 676,864 --a------ C:\WINDOWS\system32\drivers\hardlock.sys
2008-03-14 01:50 . 2008-03-14 01:50
2008-03-13 17:45 . 2008-03-13 17:45 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-03-13 17:44 . 2008-03-13 17:44 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-03-13 17:43 . 2008-03-17 00:19
2008-03-13 17:42 . 2008-03-13 17:42
2008-03-13 17:42 . 2008-03-13 17:42 134 --a------ C:\n.bat
2008-03-13 17:41 . 2008-03-17 19:51
2008-03-13 17:41 . 2008-03-17 00:29
2008-03-13 17:41 . 2008-03-13 17:41 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache(7).dsk
2008-03-13 17:41 . 2008-03-13 17:41 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache(6).dsk
2008-03-13 17:41 . 2008-03-13 17:41 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache(5).dsk
2008-03-13 17:41 . 2008-03-13 17:41 40,960 --a------ C:\Documents and Settings\Mikee\f.exe
2008-03-09 01:11 . 2008-03-09 01:11
2008-02-27 15:43 . 2008-02-27 15:43
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-18 02:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2008-03-16 18:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-14 03:42 --------- d-----w C:\Documents and Settings\Mikee\Application Data\AdobeUM
2008-02-17 22:42 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-02-15 07:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-15 06:56 --------- d-----w C:\Program Files\vso
2008-02-15 06:49 --------- d-----w C:\Documents and Settings\Mikee\Application Data\Ahead
2008-02-14 23:42 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-02-14 23:39 --------- d-----w C:\Program Files\Common Files\eSellerate
2008-02-14 06:18 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-02-14 06:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\LightScribe
2007-12-11 04:42 35,152 -c--a-w C:\Documents and Settings\Mikee\Application Data\GDIPFONTCACHEV1.DAT
2007-01-10 17:15 282,632 ----a-w C:\WINDOWS\Fonts\Setup.exe
2005-05-12 04:36 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2006-02-04 04:49 38 -csha-w C:\WINDOWS\system32\retadpu_senuTi.dat
.
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 19th, 2008 14:00
You had a password stealer on there. This malware/spyware is designed to steal your private information. That includes all passwords, logins to forums and your email details & other websites and most of all your Bank, Credit card or Paypal details.
It is vital that after you have been cleaned up you change all your passwords and it is necessary to get in touch with your Bank or other financial body to inform them that your details may ( probably have ) been stolen.
It also seems to be able to steal all your emails so anything you have emailed to anybody is no longer confidential.
You will find your stolen passwords are here:
C:\Qoobox\quarantine\C\Documents and Settings\User\x.dat.vir
Right-click on each to rename them:
Rename z.dat.vir to z.txt
Rename x.dat.vir to x.txt
• Move the two files back to the location where they originated from.
• Here:
C:\x.dat
C:\z.dat
You will need to see exactly WHAT was stolen and needs to be changed.
Now that they are .txt files, you should be able to open them in Notepad. Write the passwords etc.down so you can change them ASAP.
Following that, DELETE those two .txt files.
Next, please ensure that your security programs are disabled before running this.
Open Notepad and copy/paste the following text between the lines below. Do not copy the dotted lines.
** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces. It will copy correctly to Notepad if you highlight and copy as is.
-----------------------------------------------------------------------------------
File::
C:\WINDOWS\system32\tpomiowh.ini
C:\WINDOWS\system32\drivers\tmcomm.sys
C:\WINDOWS\system32\aeybftig.ini
C:\WINDOWS\system32\svrhost.exe
C:\WINDOWS\system32\wget.exe
C:\WINDOWS\system32\pslist.exe
C:\WINDOWS\system32\iupdate.exe
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\amgqnpcs.ini
C:\WINDOWS\system32\rar.exe
C:\n.bat
C:\WINDOWS\system32\drivers\core.cache(7).dsk
C:\WINDOWS\system32\drivers\core.cache(6).dsk
C:\WINDOWS\system32\drivers\core.cache(5).dsk
C:\Documents and Settings\Mikee\f.exe
C:\WINDOWS\se_spoof.dll
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\System32\hwoimopt.dll
Folder::
C:\Program Files\stc
C:\Program Files\180solutions
C:\Program Files\180searchassistant
C:\Program Files\180search assistant
C:\Program Files\nvcoi
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\TWlrZQ
C:\WINDOWS\system32\iDlo18
C:\Program Files\Auto Keylogger
Registry::
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"UsbD" =-
"e02a3923"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"WndMsg"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"=-
"Windows Security Tool"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer]
"autohx" =-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
DirLook::
C:\WINDOWS\system32\Microsoft
----------------------------------------------------------------------------
Save this as CFScript.txt
Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.
When finished, a log is produced here: C:\ComboFix.txt
Please submit a sample of these files:
C:\Documents and Settings\Mikee\ file.exe
C:\WINDOWS\system32\ wget.exe
to Virus Total --
http://www.virustotal.com/en/indexf.html
At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendors’ scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.
When you get the report, please post back the exact results along with your ComboFix log and a fresh Hijackthis log.
Please move HijackThis to your Program Files on your C drive.