UNSOLVED

logan_ja

updated

19 years ago

L

logan_ja

53 Posts

0

3050

July 28th, 2007 01:00

Ongoing Problems with Popups

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:06:20 PM, on 7/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\DELLSU~1\DSBrws.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.wikipedia.org/wiki/Main_Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 127.0.0.0 localhost
O1 - Hosts: 127.0.0.2 auditmypc.com
O1 - Hosts: 127.0.0.4 bulletproofsoft.net
O1 - Hosts: 127.0.0.5 camtech2000.net
O1 - Hosts: 127.0.0.6 cexx.org
O1 - Hosts: 127.0.0.7 computercops.us
O1 - Hosts: 127.0.0.8 ct7support.com
O1 - Hosts: 127.0.0.9 doxdesk.com
O1 - Hosts: 127.0.0.20 kellys-korner-xp.com
O1 - Hosts: 127.0.0.21 kephyr.com
O1 - Hosts: 127.0.0.24 lurkhere.com
O1 - Hosts: 127.0.0.25 majorgeeks.com
O1 - Hosts: 127.0.0.26 merijn.org
O1 - Hosts: 127.0.0.27 mjc1.com
O1 - Hosts: 127.0.0.28 moosoft.com
O1 - Hosts: 127.0.0.29 mvps.org
O1 - Hosts: 127.0.0.30 net-integration.net
O1 - Hosts: 127.0.0.31 noadware.net
O1 - Hosts: 127.0.0.32 no-spybot.com
O1 - Hosts: 127.0.0.33 onlinepcfix.com
O1 - Hosts: 127.0.0.34 pchell.com
O1 - Hosts: 127.0.0.35 pestpatrol.com
O1 - Hosts: 127.0.0.36 safer-networking.org
O1 - Hosts: 127.0.0.37 secure.spykiller.com
O1 - Hosts: 127.0.0.38 secureie.com
O1 - Hosts: 127.0.0.39 security.kolla.de
O1 - Hosts: 127.0.0.40 spybot.info
O1 - Hosts: 127.0.0.41 spychecker.com
O1 - Hosts: 127.0.0.42 spychecker.com
O1 - Hosts: 127.0.0.43 spycop.com
O1 - Hosts: 127.0.0.44 spyguard.com
O1 - Hosts: 127.0.0.45 spykiller.com
O1 - Hosts: 127.0.0.46 spyware.co.uk
O1 - Hosts: 127.0.0.47 spyware-cop.com
O1 - Hosts: 127.0.0.48 spywareinfo.com
O1 - Hosts: 127.0.0.49 spywarenuker.com
O1 - Hosts: 127.0.0.50 spywareremove.com
O1 - Hosts: 127.0.0.51 spywareremove.com
O1 - Hosts: 127.0.0.52 stopzillapro.com
O1 - Hosts: 127.0.0.53 sunbelt-software.com
O1 - Hosts: 127.0.0.54 thiefware.com
O1 - Hosts: 127.0.0.55 tomcoyote.org
O1 - Hosts: 127.0.0.56 unwantedlinks.com
O1 - Hosts: 127.0.0.57 webattack.com
O1 - Hosts: 127.0.0.58 wilders.org
O1 - Hosts: 127.0.0.59 www.auditmypc.com
O1 - Hosts: 127.0.0.60 www.bulletproofsoft.net
O1 - Hosts: 127.0.0.61 www.cexx.org
O1 - Hosts: 127.0.0.62 www.computercops.us
O1 - Hosts: 127.0.0.63 www.ct7support.com
O1 - Hosts: 127.0.0.64 www.doxdesk.com
O1 - Hosts: 127.0.0.65 www.eblocs.com
O1 - Hosts: 127.0.0.66 www.enigmasoftwaregroup.com
O1 - Hosts: 127.0.0.67 www.free-spyware-scan.com
O1 - Hosts: 127.0.0.68 www.free-web-browsers.com
O1 - Hosts: 127.0.0.69 www.grc.com
O1 - Hosts: 127.0.0.71 www.hackfaq.org
O1 - Hosts: 127.0.0.72 www.hazeleger.net
O1 - Hosts: 127.0.0.73 www.javacoolsoftware.com
O1 - Hosts: 127.0.0.74 www.kellys-korner-xp.com
O1 - Hosts: 127.0.0.75 www.kephyr.com
O1 - Hosts: 127.0.0.78 www.lurkhere.com
O1 - Hosts: 127.0.0.79 www.majorgeeks.com
O1 - Hosts: 127.0.0.80 www.merijn.org
O1 - Hosts: 127.0.0.81 www.mjc1.com
O1 - Hosts: 127.0.0.82 www.moosoft.com
O1 - Hosts: 127.0.0.83 www.mvps.org
O1 - Hosts: 127.0.0.84 www.net-integration.net
O1 - Hosts: 127.0.0.85 www.noadware.net
O1 - Hosts: 127.0.0.86 www.no-spybot.com
O1 - Hosts: 127.0.0.87 www.onlinepcfix.com
O1 - Hosts: 127.0.0.88 www.pchell.com
O1 - Hosts: 127.0.0.89 www.pestpatrol.com
O1 - Hosts: 127.0.0.94 www.spychecker.com
O1 - Hosts: 127.0.0.95 www.spychecker.com
O1 - Hosts: 127.0.0.96 www.spycop.com
O1 - Hosts: 127.0.0.97 www.spyguard.com
O1 - Hosts: 127.0.0.98 www.spykiller.com
O1 - Hosts: 127.0.0.99 www.spyware.co.uk
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {1038D379-1813-4C0F-8397-9672692E97CB} - (no file)
O2 - BHO: (no name) - {1C8F93F1-48BB-43C3-A166-433720FB97B5} - (no file)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {58B8FF42-D668-4BA9-8B7F-9E2B30DDF352} - C:\Program Files\ComPlus Applications\meqocano83122.dll (file missing)
O2 - BHO: (no name) - {58C41142-D0CD-41AE-AFB4-73B1545B6AB0} - C:\WINDOWS\system32\mlljh.dll (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {614E6CFA-8118-A8CD-4966-F98DB05482BC} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\TISKY009.exe SKY009
O4 - HKLM\..\Run: [{66-61-17-7C-ZN}] c:\windows\system32\msdsrego.exe SKY009
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\WINDOWS\TISKY009.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O20 - AppInit_DLLs: 57.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\rtele.html
--
End of file - 12778 bytes
 

OK. Here are best described problems I have.  Hopefully, I don't leave anything out. 
 
Dell Dimesion DIM 2400
Intel (R)  Pentium (R) 4 CPU 2.66GHz
2.66GHz, 256 MB of RAM
Microsoft Windows XP
Home Edition  Version 2002 Service Pack 2
 
#1 Problem- After startup computer had no icons on background.
#1 FIX-  People from this site helped me.  They thought the username was bad. 
So, I created a new username account and the old username was saved to a folder on the desktop. It worked great.  I had icons and could use computer fine. Later, he instructed me how to take over the old username.  I couldn't follow the same command he posted so I did not take over the old username account.
 
#2 Problem- Still had some bad pop-up problems
#2 FIX- I downloaded new Ad-Aware, Windows Defender, AVG Anti-Spyware, AVG 7.5 Virus protection. Did disk defrag, disk clean-up.  Run numerous scans from all programs and found some problems.  Did not solve #2 problem.  Still have pop-ups.
 
#3 Problem- Computer is now very slow.  After startup the computer takes very long time to load. 
Could this be from all the programs I have recently downloaded running at startup? 
 
Need all the help I can get.  Thank You, Jacob.
 
 


Message Edited by logan_ja on 07-27-2007 09:49 PM

Message Edited by logan_ja on 07-27-2007 09:50 PM
  • logan_ja

    53 Posts

    1097

    0

    Posted July 28th, 2007 19:00

    Ok, I just finished reading another post which had similarity to my problem. 
     
    Forgot to Mention -  My problem first started after I downloaded WinAntiSpyware 2007.  (which was similar to another post I just read)
     
    New Problem - I was reading the post and thought I could be a step ahead.  So I downloaded Combofix.exe.  Ran it, but it did not finish.  I had to restart manually.   I have no log to post.  And my clock is in military time.  Hopefully no damage was done.  I don't know.  Thanks, and next time I'll wait for reply before I start downloading software.  Jacob.
  • bamajim

    10376 Posts

    1097

    0

    Posted July 28th, 2007 23:00

    logan_ja

    1. Please download HostsXpert 3.7 - Hosts File Manager
    Please download HostsXpert 3.7 - Hosts File Manager
    • And Save it to your Desktop
      Rt Click Hoster.zip->>Extract all->>Extract it to your Desktop
      Open The Hoster folder->>Double Click Hoster.exe (It will look like a yeild sign with a stop light in the center)
      When the program Opens Click The " Restore Original Hosts" Button
      Close the Hoster program when complete

    2. Please download Combofix and save to your desktop:
    • Note: It is important that it is saved directly to your desktop
      Close any open browsers.
      Double click on combofix.exe and follow the prompts.
      When it's finished it will produce a log.
      Post the contents of the C:\ComboFix.txt into your next reply.
      Note: Do not mouseclick combofix's window whilst it's running.
      That may cause the program to freeze/hang.

    CastleCops Instructor

    MRU Graduate

    "The world is what you make of it"



    Message Edited by bamajim on 07-28-2007 07:25 PM
  • logan_ja

    53 Posts

    1097

    0

    Posted July 29th, 2007 14:00

    Ok bamajim:
     
    1.  HostsXpert 3.7 ran correctly....I believe
     
    2.  Combofix did give a log this time.  GREAT!!!  Here it is:
     
    ComboFix 07-07-28.4 - "LOG" 2007-07-28 22:20:43.2 [GMT -5:00] - NTFS
    Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.True

    (((((((((((((((((((((((((   Files Created from 2007-06-28 to 2007-07-29  )))))))))))))))))))))))))))))))

    2007-07-28 14:46 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-07-27 19:51   d-------- C:\Program Files\Trend Micro
    2007-07-25 22:13   d-------- C:\DOCUME~1\LOG\.housecall6.6
    2007-07-24 22:31 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
    2007-07-24 20:08   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-07-23 23:12   d-------- C:\Program Files\Windows Media Connect 2
    2007-07-23 23:08   d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
    2007-07-23 22:13   d-------- C:\VundoFix Backups
    2007-07-21 10:59 6,489 ---hs---- C:\WINDOWS\SYSTEM32\bccdd.bak1
    2007-07-21 09:48 6,488 ---hs---- C:\WINDOWS\SYSTEM32\dfhkj.bak1
    2007-07-21 04:56 6,488 ---hs---- C:\WINDOWS\SYSTEM32\mnnmp.bak1
    2007-07-21 03:42 6,488 ---hs---- C:\WINDOWS\SYSTEM32\rtstv.bak1
    2007-07-20 21:41   d-------- C:\Program Files\Windows Defender
    2007-07-20 21:36   d-------- C:\DOCUME~1\LOG\APPLIC~1\AdobeUM
    2007-07-20 20:27   d-------- C:\DOCUME~1\LOG\APPLIC~1\GTek
    2007-07-20 20:23 1,572,864 --ah----- C:\DOCUME~1\LOG\NTUSER.DAT
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Sonic
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Real
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Jasc Software Inc
    2007-07-20 17:17 4,628 --a------ C:\WINDOWS\SYSTEM32\ugepisij.exe
    2007-07-20 17:17 124,436 --a------ C:\WINDOWS\SYSTEM32\dftyhnst.dll
    2007-07-20 17:14 66,580 --a------ C:\WINDOWS\SYSTEM32\tdwrkcae.dll
    2007-07-20 17:14 66,068 --a------ C:\WINDOWS\SYSTEM32\uodomdsa.exe
    2007-07-20 16:18 66,580 --a------ C:\WINDOWS\SYSTEM32\xciasjyy.dll
    2007-07-19 00:27   d-------- C:\WINDOWS\SxsCaPendDel
    2007-07-19 00:08 4,628 --a------ C:\WINDOWS\SYSTEM32\xfeywfpm.exe
    2007-07-19 00:03 66,580 --a------ C:\WINDOWS\SYSTEM32\wgudcswf.dll
    2007-07-19 00:03 66,068 --a------ C:\WINDOWS\SYSTEM32\sxiusktd.exe
    2007-07-18 23:58   d-------- C:\Program Files\Lavasoft
    2007-07-18 23:58   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    2007-07-18 23:09 4,628 --a------ C:\WINDOWS\SYSTEM32\gasdokcp.exe
    2007-07-12 00:24 4,628 --a------ C:\WINDOWS\SYSTEM32\ducuqdwe.exe
    2007-07-12 00:21 66,580 --a------ C:\WINDOWS\SYSTEM32\jllubqpn.dll
    2007-07-12 00:15 66,068 --a------ C:\WINDOWS\SYSTEM32\vtfehylx.exe
    2007-07-12 00:03   d-------- C:\Temp\0c2
    2007-07-12 00:02   d-------- C:\Temp\brr
    2007-07-12 00:02   d-------- C:\Temp

    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    2007-07-28 14:53 --------- d-------- C:\Program Files\Messenger
    2007-07-18 23:50 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2007-06-04 15:18 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
    2007-06-04 15:17 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
    2007-06-04 15:14 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
    2007-05-16 10:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
    2007-05-11 12:54 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx0c.dll
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx07.dll
    2007-05-10 23:37 802816 --a--c--- C:\WINDOWS\system32\divx_xx11.dll
    2007-05-10 23:37 740442 --a------ C:\WINDOWS\system32\DivX.dll

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
     
     
    *Note* empty entries & legit default entries are not shown
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1038D379-1813-4C0F-8397-9672692E97CB}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C8F93F1-48BB-43C3-A166-433720FB97B5}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58B8FF42-D668-4BA9-8B7F-9E2B30DDF352}]
       C:\Program Files\ComPlus Applications\meqocano83122.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58C41142-D0CD-41AE-AFB4-73B1545B6AB0}]
       C:\WINDOWS\system32\mlljh.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{614E6CFA-8118-A8CD-4966-F98DB05482BC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "@"="" []
    "Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
    "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-19 03:07]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-02-19 03:07]
    "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47]
    "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11:06]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-25 00:09]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
    "Sonic RecordNow!"="" []
    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
    C:\Documents and Settings\LOG\Start Menu\Programs\Startup\
    DESKTOP.INI [2002-09-03 10:00:00]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-22 23:29:18]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
    America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-02-19 03:06:18]
    DESKTOP.INI [2002-09-03 10:00:00]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-02-19 03:04:15]
    Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2004-04-05 03:13:33]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
    Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2005-10-30 16:09:39]
    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
    Source= C:\Program Files\Messenger\rtele.html
    FriendlyName=
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=57.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"
    R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
    R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
    R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys
    R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
    R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys
    R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys
    R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys
    R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys
    R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys
    R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys
    R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
    R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys
    R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys
    R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
    R3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
    R3 wg111nd5;NETGEAR WG111 802.11g Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\wg111nd5.sys
    S3 I81tgmt;I81tgmt;C:\WINDOWS\system32\drivers\mf.sys
    S3 i81x;i81x;C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
    S3 iAimFP0;iAimFP0;C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
    S3 iAimFP1;iAimFP1;C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
    S3 iAimFP2;iAimFP2;C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
    S3 iAimFP3;iAimFP3;C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
    S3 iAimFP4;iAimFP4;C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
    S3 iAimTV0;iAimTV0;C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
    S3 iAimTV1;iAimTV1;C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
    S3 iAimTV2;iAimTV2;C:\WINDOWS\system32\DRIVERS\wATV03nt.sys
    S3 iAimTV3;iAimTV3;C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
    S3 iAimTV4;iAimTV4;C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
    S3 PalmUSBD;PalmUSBD;C:\WINDOWS\system32\drivers\PalmUSBD.sys
    S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys

    Contents of the 'Scheduled Tasks' folder
    2004-03-23 05:45:00 C:\WINDOWS\Tasks\ISP signup reminder 1.job
    2007-07-28 20:08:30 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
    2007-07-29 03:25:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A5663C8D-5144-42A6-8B35-B84957B0ECBB}.job - C:\WINDOWS\system32\msfeedssync.exe
    **************************************************************************
    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-28 22:25:32
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden registry entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    Completion time: 2007-07-28 22:27:41
    C:\ComboFix-quarantined-files.txt ... 2007-07-28 22:27
     --- E O F ---
  • bamajim

    10376 Posts

    1097

    0

    Posted July 29th, 2007 18:00

    logan_ja

    1. Open NotePad (not wordpad). Copy and paste the following into Notepad


    File::
    C:\WINDOWS\SYSTEM32\bccdd.bak1
    C:\WINDOWS\SYSTEM32\dfhkj.bak1
    C:\WINDOWS\SYSTEM32\mnnmp.bak1
    C:\WINDOWS\SYSTEM32\rtstv.bak1
    C:\WINDOWS\SYSTEM32\ugepisij.exe
    C:\WINDOWS\SYSTEM32\dftyhnst.dll
    C:\WINDOWS\SYSTEM32\tdwrkcae.dll
    C:\WINDOWS\SYSTEM32\uodomdsa.exe
    C:\WINDOWS\SYSTEM32\xciasjyy.dll
    C:\WINDOWS\SYSTEM32\xfeywfpm.exe
    C:\WINDOWS\SYSTEM32\wgudcswf.dll
    C:\WINDOWS\SYSTEM32\sxiusktd.exe
    C:\WINDOWS\SYSTEM32\gasdokcp.exe
    C:\WINDOWS\SYSTEM32\ducuqdwe.exe
    C:\WINDOWS\SYSTEM32\jllubqpn.dll
    C:\WINDOWS\SYSTEM32\vtfehylx.exe
    C:\WINDOWS\system32\mlljh.dll

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58C41142-D0CD-41AE-AFB4-73B1545B6AB0}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=-

    Save the File as CFScript ->> Save it to your Desktop

    Using the Image as a reference, drag CFScript into ComboFix.exe

    user posted image
    • You will be prompted to run Combofix again, Do so
      Following the same rules as indicated in my first post
      Then post the contents of the C:\ComboFix.txt log in your reply

    CastleCops Instructor

    MRU Graduate


    "The world is what you make of it"

  • logan_ja

    53 Posts

    1097

    0

    Posted July 29th, 2007 21:00

    OK, bamajim here is my new log: 
     
     
    ComboFix 07-07-28.4 - "LOG" 2007-07-29 17:30:02.3 [GMT -5:00] - NTFS
    Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.True
    Command switches used ::  C:\Documents and Settings\LOG\Desktop\CF Script.txt

    (((((((((((((((((((((((((   Files Created from 2007-06-28 to 2007-07-29  )))))))))))))))))))))))))))))))

    2007-07-28 14:46 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-07-27 19:51   d-------- C:\Program Files\Trend Micro
    2007-07-25 22:13   d-------- C:\DOCUME~1\LOG\.housecall6.6
    2007-07-24 22:31 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
    2007-07-24 20:08   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-07-23 23:12   d-------- C:\Program Files\Windows Media Connect 2
    2007-07-23 23:08   d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
    2007-07-23 22:13   d-------- C:\VundoFix Backups
    2007-07-21 10:59 6,489 ---hs---- C:\WINDOWS\SYSTEM32\bccdd.bak1
    2007-07-21 09:48 6,488 ---hs---- C:\WINDOWS\SYSTEM32\dfhkj.bak1
    2007-07-21 04:56 6,488 ---hs---- C:\WINDOWS\SYSTEM32\mnnmp.bak1
    2007-07-21 03:42 6,488 ---hs---- C:\WINDOWS\SYSTEM32\rtstv.bak1
    2007-07-20 21:41   d-------- C:\Program Files\Windows Defender
    2007-07-20 21:36   d-------- C:\DOCUME~1\LOG\APPLIC~1\AdobeUM
    2007-07-20 20:27   d-------- C:\DOCUME~1\LOG\APPLIC~1\GTek
    2007-07-20 20:23 1,572,864 --ah----- C:\DOCUME~1\LOG\NTUSER.DAT
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Sonic
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Real
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Jasc Software Inc
    2007-07-20 17:17 4,628 --a------ C:\WINDOWS\SYSTEM32\ugepisij.exe
    2007-07-20 17:17 124,436 --a------ C:\WINDOWS\SYSTEM32\dftyhnst.dll
    2007-07-20 17:14 66,580 --a------ C:\WINDOWS\SYSTEM32\tdwrkcae.dll
    2007-07-20 17:14 66,068 --a------ C:\WINDOWS\SYSTEM32\uodomdsa.exe
    2007-07-20 16:18 66,580 --a------ C:\WINDOWS\SYSTEM32\xciasjyy.dll
    2007-07-19 00:27   d-------- C:\WINDOWS\SxsCaPendDel
    2007-07-19 00:08 4,628 --a------ C:\WINDOWS\SYSTEM32\xfeywfpm.exe
    2007-07-19 00:03 66,580 --a------ C:\WINDOWS\SYSTEM32\wgudcswf.dll
    2007-07-19 00:03 66,068 --a------ C:\WINDOWS\SYSTEM32\sxiusktd.exe
    2007-07-18 23:58   d-------- C:\Program Files\Lavasoft
    2007-07-18 23:58   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    2007-07-18 23:09 4,628 --a------ C:\WINDOWS\SYSTEM32\gasdokcp.exe
    2007-07-12 00:24 4,628 --a------ C:\WINDOWS\SYSTEM32\ducuqdwe.exe
    2007-07-12 00:21 66,580 --a------ C:\WINDOWS\SYSTEM32\jllubqpn.dll
    2007-07-12 00:15 66,068 --a------ C:\WINDOWS\SYSTEM32\vtfehylx.exe
    2007-07-12 00:03   d-------- C:\Temp\0c2
    2007-07-12 00:02   d-------- C:\Temp\brr
    2007-07-12 00:02   d-------- C:\Temp

    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    2007-07-28 14:53 --------- d-------- C:\Program Files\Messenger
    2007-07-18 23:50 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2007-06-04 15:18 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
    2007-06-04 15:17 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
    2007-06-04 15:14 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
    2007-05-16 10:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
    2007-05-11 12:54 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx0c.dll
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx07.dll
    2007-05-10 23:37 802816 --a--c--- C:\WINDOWS\system32\divx_xx11.dll
    2007-05-10 23:37 740442 --a------ C:\WINDOWS\system32\DivX.dll

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
     
     
    *Note* empty entries & legit default entries are not shown
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1038D379-1813-4C0F-8397-9672692E97CB}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C8F93F1-48BB-43C3-A166-433720FB97B5}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58B8FF42-D668-4BA9-8B7F-9E2B30DDF352}]
       C:\Program Files\ComPlus Applications\meqocano83122.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58C41142-D0CD-41AE-AFB4-73B1545B6AB0}]
       C:\WINDOWS\system32\mlljh.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{614E6CFA-8118-A8CD-4966-F98DB05482BC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "@"="" []
    "Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
    "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-19 03:07]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-02-19 03:07]
    "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47]
    "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11:06]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-25 00:09]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
    "Sonic RecordNow!"="" []
    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
    C:\Documents and Settings\LOG\Start Menu\Programs\Startup\
    DESKTOP.INI [2002-09-03 10:00:00]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-22 23:29:18]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
    America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-02-19 03:06:18]
    DESKTOP.INI [2002-09-03 10:00:00]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-02-19 03:04:15]
    Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2004-04-05 03:13:33]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
    Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2005-10-30 16:09:39]
    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
    Source= C:\Program Files\Messenger\rtele.html
    FriendlyName=
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=57.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"
    R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
    R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
    R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys
    R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
    R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys
    R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys
    R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys
    R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys
    R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys
    R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys
    R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
    R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys
    R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys
    R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
    R3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
    R3 wg111nd5;NETGEAR WG111 802.11g Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\wg111nd5.sys
    S3 I81tgmt;I81tgmt;C:\WINDOWS\system32\drivers\mf.sys
    S3 i81x;i81x;C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
    S3 iAimFP0;iAimFP0;C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
    S3 iAimFP1;iAimFP1;C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
    S3 iAimFP2;iAimFP2;C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
    S3 iAimFP3;iAimFP3;C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
    S3 iAimFP4;iAimFP4;C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
    S3 iAimTV0;iAimTV0;C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
    S3 iAimTV1;iAimTV1;C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
    S3 iAimTV2;iAimTV2;C:\WINDOWS\system32\DRIVERS\wATV03nt.sys
    S3 iAimTV3;iAimTV3;C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
    S3 iAimTV4;iAimTV4;C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
    S3 PalmUSBD;PalmUSBD;C:\WINDOWS\system32\drivers\PalmUSBD.sys
    S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    *Newly Created Service* - CATCHME
    Contents of the 'Scheduled Tasks' folder
    2004-03-23 05:45:00 C:\WINDOWS\Tasks\ISP signup reminder 1.job
    2007-07-29 07:27:57 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
    2007-07-29 22:35:02 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A5663C8D-5144-42A6-8B35-B84957B0ECBB}.job - C:\WINDOWS\system32\msfeedssync.exe
    **************************************************************************
    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-29 17:34:36
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden registry entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    Completion time: 2007-07-29 17:37:38
    C:\ComboFix-quarantined-files.txt ... 2007-07-29 17:37
    C:\ComboFix2.txt ... 2007-07-28 22:27
     --- E O F ---
  • bamajim

    10376 Posts

    1097

    0

    Posted July 30th, 2007 00:00

    logan_ja

    That didn't work , and I think AVG Antispyware is interfering with it's operation. So we need to turn off AVG Antispyware till we finish cleaning your PC.

    Open AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
    • The main "Status" menu will appear. Select "Change state" to inactivate both 'Resident Shield' and 'Automatic Updates'. Close the Main window.
    • Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
    • Reboot your PC.

      2. Then repeat the proceedure Using the Image as a reference, drag CFScript into ComboFix.exe

      user posted image
      • You will be prompted to run Combofix again, Do so
        Following the same rules as indicated in my first post
        Then post the contents of the C:\ComboFix.txt log in your reply

    CastleCops Instructor

    MRU Graduate


    "The world is what you make of it"

  • logan_ja

    53 Posts

    1097

    0

    Posted July 30th, 2007 13:00

    bamajim I appreciate all your help....Thanks Tremendously.  Jacob
     
     
     
    ComboFix 07-07-28.4 - "LOG" 2007-07-30  9:19:41.4 [GMT -5:00] - NTFS
    Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.True
    Command switches used ::  C:\Documents and Settings\LOG\Desktop\CF Script.txt

    (((((((((((((((((((((((((   Files Created from 2007-06-28 to 2007-07-30  )))))))))))))))))))))))))))))))

    2007-07-29 18:16 5,632 --a------ C:\WINDOWS\SYSTEM32\ptpusb.dll
    2007-07-29 18:16 159,232 --a------ C:\WINDOWS\SYSTEM32\ptpusd.dll
    2007-07-28 14:46 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-07-27 19:51   d-------- C:\Program Files\Trend Micro
    2007-07-25 22:13   d-------- C:\DOCUME~1\LOG\.housecall6.6
    2007-07-24 22:31 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
    2007-07-24 20:08   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-07-23 23:12   d-------- C:\Program Files\Windows Media Connect 2
    2007-07-23 23:08   d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
    2007-07-23 22:13   d-------- C:\VundoFix Backups
    2007-07-21 10:59 6,489 ---hs---- C:\WINDOWS\SYSTEM32\bccdd.bak1
    2007-07-21 09:48 6,488 ---hs---- C:\WINDOWS\SYSTEM32\dfhkj.bak1
    2007-07-21 04:56 6,488 ---hs---- C:\WINDOWS\SYSTEM32\mnnmp.bak1
    2007-07-21 03:42 6,488 ---hs---- C:\WINDOWS\SYSTEM32\rtstv.bak1
    2007-07-20 21:41   d-------- C:\Program Files\Windows Defender
    2007-07-20 21:36   d-------- C:\DOCUME~1\LOG\APPLIC~1\AdobeUM
    2007-07-20 20:27   d-------- C:\DOCUME~1\LOG\APPLIC~1\GTek
    2007-07-20 20:23 1,835,008 --ah----- C:\DOCUME~1\LOG\NTUSER.DAT
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Sonic
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Real
    2007-07-20 20:23   d-------- C:\DOCUME~1\LOG\APPLIC~1\Jasc Software Inc
    2007-07-20 17:17 4,628 --a------ C:\WINDOWS\SYSTEM32\ugepisij.exe
    2007-07-20 17:17 124,436 --a------ C:\WINDOWS\SYSTEM32\dftyhnst.dll
    2007-07-20 17:14 66,580 --a------ C:\WINDOWS\SYSTEM32\tdwrkcae.dll
    2007-07-20 17:14 66,068 --a------ C:\WINDOWS\SYSTEM32\uodomdsa.exe
    2007-07-20 16:18 66,580 --a------ C:\WINDOWS\SYSTEM32\xciasjyy.dll
    2007-07-19 00:27   d-------- C:\WINDOWS\SxsCaPendDel
    2007-07-19 00:08 4,628 --a------ C:\WINDOWS\SYSTEM32\xfeywfpm.exe
    2007-07-19 00:03 66,580 --a------ C:\WINDOWS\SYSTEM32\wgudcswf.dll
    2007-07-19 00:03 66,068 --a------ C:\WINDOWS\SYSTEM32\sxiusktd.exe
    2007-07-18 23:58   d-------- C:\Program Files\Lavasoft
    2007-07-18 23:58   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    2007-07-18 23:09 4,628 --a------ C:\WINDOWS\SYSTEM32\gasdokcp.exe
    2007-07-12 00:24 4,628 --a------ C:\WINDOWS\SYSTEM32\ducuqdwe.exe
    2007-07-12 00:21 66,580 --a------ C:\WINDOWS\SYSTEM32\jllubqpn.dll
    2007-07-12 00:15 66,068 --a------ C:\WINDOWS\SYSTEM32\vtfehylx.exe
    2007-07-12 00:03   d-------- C:\Temp\0c2
    2007-07-12 00:02   d-------- C:\Temp\brr
    2007-07-12 00:02   d-------- C:\Temp
    2007-06-04 15:18 9,344 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
    2007-06-04 15:17 8,320 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AWRTRD.sys
    2007-06-04 15:14 6,272 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AWRTPD.sys

    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    2007-07-28 14:53 --------- d-------- C:\Program Files\Messenger
    2007-07-18 23:50 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2007-05-16 10:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
    2007-05-11 12:54 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx0c.dll
    2007-05-10 23:37 823296 --a--c--- C:\WINDOWS\system32\divx_xx07.dll
    2007-05-10 23:37 802816 --a--c--- C:\WINDOWS\system32\divx_xx11.dll
    2007-05-10 23:37 740442 --a------ C:\WINDOWS\system32\DivX.dll

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
     
     
    *Note* empty entries & legit default entries are not shown
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1038D379-1813-4C0F-8397-9672692E97CB}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C8F93F1-48BB-43C3-A166-433720FB97B5}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58B8FF42-D668-4BA9-8B7F-9E2B30DDF352}]
       C:\Program Files\ComPlus Applications\meqocano83122.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58C41142-D0CD-41AE-AFB4-73B1545B6AB0}]
       C:\WINDOWS\system32\mlljh.dll
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{614E6CFA-8118-A8CD-4966-F98DB05482BC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "@"="" []
    "Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
    "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-19 03:07]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-02-19 03:07]
    "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47]
    "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11:06]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-25 00:09]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
    "Sonic RecordNow!"="" []
    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
    C:\Documents and Settings\LOG\Start Menu\Programs\Startup\
    DESKTOP.INI [2002-09-03 10:00:00]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-22 23:29:18]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
    America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-02-19 03:06:18]
    DESKTOP.INI [2002-09-03 10:00:00]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-02-19 03:04:15]
    Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2004-04-05 03:13:33]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
    Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2005-10-30 16:09:39]
    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
    Source= C:\Program Files\Messenger\rtele.html
    FriendlyName=
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=57.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @="Service"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"
    R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
    R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
    R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys
    R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
    R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys
    R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys
    R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys
    R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys
    R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys
    R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys
    R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
    R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys
    R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys
    R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
    R3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
    R3 wg111nd5;NETGEAR WG111 802.11g Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\wg111nd5.sys
    S3 I81tgmt;I81tgmt;C:\WINDOWS\system32\drivers\mf.sys
    S3 i81x;i81x;C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
    S3 iAimFP0;iAimFP0;C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
    S3 iAimFP1;iAimFP1;C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
    S3 iAimFP2;iAimFP2;C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
    S3 iAimFP3;iAimFP3;C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
    S3 iAimFP4;iAimFP4;C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
    S3 iAimTV0;iAimTV0;C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
    S3 iAimTV1;iAimTV1;C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
    S3 iAimTV2;iAimTV2;C:\WINDOWS\system32\DRIVERS\wATV03nt.sys
    S3 iAimTV3;iAimTV3;C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
    S3 iAimTV4;iAimTV4;C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
    S3 PalmUSBD;PalmUSBD;C:\WINDOWS\system32\drivers\PalmUSBD.sys
    S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys

    Contents of the 'Scheduled Tasks' folder
    2004-03-23 05:45:00 C:\WINDOWS\Tasks\ISP signup reminder 1.job
    2007-07-30 14:17:20 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
    2007-07-30 14:20:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A5663C8D-5144-42A6-8B35-B84957B0ECBB}.job - C:\WINDOWS\system32\msfeedssync.exe
    **************************************************************************
    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-30 09:23:51
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden registry entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    Completion time: 2007-07-30  9:25:56
    C:\ComboFix-quarantined-files.txt ... 2007-07-30 09:25
    C:\ComboFix2.txt ... 2007-07-29 17:37
    C:\ComboFix3.txt ... 2007-07-28 22:27
     --- E O F ---
  • bamajim

    10376 Posts

    1097

    0

    Posted July 30th, 2007 22:00


    logan_ja

    That didn't have the desired results either. Let's do it this way

    1. Please download the Killbox.
    • 1)Save it to the desktop
      2) Rt Click->>Extract all->.Extract it to your Desktop
      3) Double Click Killbox.exe to run it
      4)Select " Delete on Reboot", and then select "All files".
      5) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

      • C:\WINDOWS\SYSTEM32\bccdd.bak1
        C:\WINDOWS\SYSTEM32\dfhkj.bak1
        C:\WINDOWS\SYSTEM32\mnnmp.bak1
        C:\WINDOWS\SYSTEM32\rtstv.bak1
        C:\WINDOWS\SYSTEM32\ugepisij.exe
        C:\WINDOWS\SYSTEM32\dftyhnst.dll
        C:\WINDOWS\SYSTEM32\tdwrkcae.dll
        C:\WINDOWS\SYSTEM32\uodomdsa.exe
        C:\WINDOWS\SYSTEM32\xciasjyy.dll
        C:\WINDOWS\SYSTEM32\xfeywfpm.exe
        C:\WINDOWS\SYSTEM32\wgudcswf.dll
        C:\WINDOWS\SYSTEM32\sxiusktd.exe
        C:\WINDOWS\SYSTEM32\gasdokcp.exe
        C:\WINDOWS\SYSTEM32\ducuqdwe.exe
        C:\WINDOWS\SYSTEM32\jllubqpn.dll
        C:\WINDOWS\SYSTEM32\vtfehylx.exe
        C:\Temp\0c2


      6) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
      7) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.

    2. Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log

    CastleCops Instructor

    MRU Graduate


    "The world is what you make of it"

  • logan_ja

    53 Posts

    1097

    0

    Posted July 31st, 2007 05:00

    Ok bamajim, hopefully this will help.  Thanks, Jacob
     
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:58:40 AM, on 7/31/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
    C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.wikipedia.org/wiki/Main_Page
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: 0 - {1038D379-1813-4C0F-8397-9672692E97CB} - (no file)
    O2 - BHO: (no name) - {1C8F93F1-48BB-43C3-A166-433720FB97B5} - (no file)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {58B8FF42-D668-4BA9-8B7F-9E2B30DDF352} - C:\Program Files\ComPlus Applications\meqocano83122.dll (file missing)
    O2 - BHO: (no name) - {58C41142-D0CD-41AE-AFB4-73B1545B6AB0} - C:\WINDOWS\system32\mlljh.dll (file missing)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {614E6CFA-8118-A8CD-4966-F98DB05482BC} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Image Transfer.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O20 - AppInit_DLLs: 57.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\rtele.html
    --
    End of file - 8631 bytes
  • bamajim

    10376 Posts

    517

    0

    Posted July 31st, 2007 13:00

    logan_ja

    That looks better.

    1. Rerun Hijackthis (scan only) and place checks beside the following entries
    • O2 - BHO: 0 - {1038D379-1813-4C0F-8397-9672692E97CB} - (no file)
      O2 - BHO: (no name) - {1C8F93F1-48BB-43C3-A166-433720FB97B5} - (no file)
      O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
      O2 - BHO: (no name) - {58B8FF42-D668-4BA9-8B7F-9E2B30DDF352} - C:\Program Files\ComPlus Applications\meqocano83122.dll (file missing)
      O2 - BHO: (no name) - {58C41142-D0CD-41AE-AFB4-73B1545B6AB0} - C:\WINDOWS\system32\mlljh.dll (file missing)
      O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
      O2 - BHO: (no name) - {614E6CFA-8118-A8CD-4966-F98DB05482BC} - (no file)
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
      O20 - AppInit_DLLs: 57.dll
    Close all other open windows except Hijackthis and Select " Fix checked"

    Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log

    CastleCops Instructor

    MRU Graduate

    "The world is what you make of it"