UNSOLVED

awjohnson008

updated

19 years ago

0

1832

October 14th, 2007 12:00

AVsystemcare? NEED HELP!!!

To who ever can help me,
I recently got a virus or something like it on my computer. I have been getting popups for a couple of days in regards to this AVsystemcare. Also, I am not able to use my system restore function and my computer doesn't not have me as an administrator anymore.  For instance, when I try to delete programs or change properties I get a message saying operation not allowed contact system administrator. I would like to know what I need to do in order to get rid of this problem and get my computer back in good working condition. I have downloaded the HJT program and these are my results:
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:21 AM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\printer.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\program files\mcafee\msc\mcshell.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MSC\mcregist.exe
C:\WINDOWS\system32\dlbxcoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: (no name) - {27CF1C68-19A6-58A8-F34A-D75AF141C93E} - (no file)
O2 - BHO: (no name) - {380C904F-55CD-338E-24B0-013D0423F1B0} - (no file)
O2 - BHO: (no name) - {44E12371-18A5-CADE-1043-D0FDEEBCF1CB} - (no file)
O2 - BHO: (no name) - {50B91207-4289-28BE-FC70-4CE72F0402CB} - (no file)
O2 - BHO: (no name) - {54351455-EFE9-7EFE-3393-B2622AF47B0F} - (no file)
O2 - BHO: (no name) - {651214D8-15FD-F7BB-3AF2-BA7967C08710} - (no file)
O2 - BHO: (no name) - {6F2EB59A-6F50-8B14-0D7D-BCC43DC7177A} - (no file)
O2 - BHO: (no name) - {77A8711A-0D8F-49B8-6DFB-AE85E05A493A} - (no file)
O2 - BHO: (no name) - {7FE16BED-1E1A-0F9A-E962-90627CF19B7B} - (no file)
O2 - BHO: (no name) - {801F3199-8EAB-0036-12D6-35DEE31205DC} - (no file)
O2 - BHO: (no name) - {8F7D04CA-6D30-6286-E432-22FFB0FB128A} - (no file)
O2 - BHO: (no name) - {916EEA1B-BCB7-4A5B-522D-4623137184B4} - (no file)
O2 - BHO: (no name) - {94BD1A37-5653-88A2-1E65-7852D1BEE72F} - (no file)
O2 - BHO: (no name) - {A72F96DF-A4F3-57A8-1C3A-8C57E40658C5} - (no file)
O2 - BHO: (no name) - {D6A0E97F-3C18-7E5D-E033-44852E515B86} - (no file)
O2 - BHO: (no name) - {E00B6257-B5AF-B5AF-80E5-5F0087457F4F} - (no file)
O2 - BHO: (no name) - {F18949DB-2CBC-81C3-5DC7-B25366CB61D4} - (no file)
O2 - BHO: (no name) - {F7375AC2-A5D6-EEBC-9B5B-3DFA6FA5DD51} - (no file)
O2 - BHO: (no name) - {FA682029-FE62-181C-B031-3233A3C5A91E} - (no file)
O2 - BHO: (no name) - {FA78BCF6-1C11-1477-172D-2FA8B8257F0B} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [mfcld.exe] C:\WINDOWS\mfcld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [MaBtSh] C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - Global Startup: autorun.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://domino1.ncat.edu/dwa7W.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä #·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apibv.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8251 bytes

  • Bugbatter

    4 Apprentice

    20487 Posts

    490

    0

    Posted October 14th, 2007 15:00

    Welcome. Thank you for using Dell Community Forums. :)

    That is quite a collection of malware. I cannot guarantee that we can fix all the damage it has done, but we'll try. It will take a few days.

    * Please let me know if you have posted this log on another forum.

    * I will not handle your log if you are using any cracked software, so if you are, either remove it, or repost your log in a New Message so that someone else will have the option of continuing with it.

    * If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
    Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple, file sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
    Since I find the nature of P2P programs counter productive to restoring your PC to a healthy state, please remove all P2P file sharing programs prior to my providing you with malware removal assistance.

    * Please let me know if you are an employee and this system is owned by your employer. If so, do you have permission to make changes to it?

    * Please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
    In some cases you may be working in Safemode and you will not have the internet available to read information. Please follow all instructions in sequence.

    * If your reply does not fit in one post, please reply to yourself until all text is submitted. It may take several posts.

    Please download Navilog1 by IL-MAFIOSO:
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip

    * Extract its contents to the desktop.
    * Double click on navilog1.exe to install it on your computer.
    * When the installation is complete, the tool will start automatically.
    * If it doesn't start automatically, please double click on Navilog1 shortcut on your desktop to run it.
    * Press E for English from the language Menu.
    * Type 1 in the next Menu to select Search and press Enter.
    * Wait for the Scan to finish (It may take a reasonable amount of time)
    * Press any key as requested .
    * A new document will be produced: fixnavi.txt.
    * Please copy/paste the contents of this report in your next reply.

    The report is also saved in the root of the directory, "% SystemDrive%\ fixnavi.txt". (usually C:\fixnavi.txt)
  • 490

    0

    Posted October 14th, 2007 20:00

    These are my results from using the Navilog1 program:
     
    Search Navipromo version 3.2.1 began on Sun 10/14/2007 at 16:52:32.75
    !!! Warning, this report may include legitimate files/programs !!!
    !!! Post this report on the forum you are being helped !!!
    !!! Don't continue with removal unless instructed by an authorized helper !!!
    Fix running from C:\Program Files\navilog1
    Updated on 09.10.2007 at 18h00 by IL-MAFIOSO
    Microsoft Windows XP [Version 5.1.2600]
    Version Internet Explorer : 6.0.2900.2180
    Done in normal mode
    *** Searching for installed Software ***
     

    *** Search folders in C:\WINDOWS ***
     
    *** Search folders in C:\Program Files ***
     
    *** Search folders in C:\Documents and Settings\All Users\Application Data ***
     

    *** Search folders in C:\Documents and Settings\ Johnson\Application Data ***

    *** Search folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs ***

    *** Search with Catchme-rootkit/stealth malware detector by gmer ***
    for more info :
    http://www.gmer.net
    No file found in :
    - C:\WINDOWS\system32
    - C:\DOCUME~1\AVISJO~1\LOCALS~1\APPLIC~1
     
    *** Search with GenericNaviSearch ***
    !!! Possibility of legitims files in the result !!!
    !!! To be always checked before manually deleting !!!
    * Scan C:\WINDOWS\system32 *
    * Scan C:\DOCUME~1\AVISJO~1\LOCALS~1\APPLIC~1 *
     
    *** Search files ***
     

    *** Search registry keys ***

    *** Complementary Search ***
    (Search specifics files)
    1)Search known files:
    2)Heuristic Search :
     
    3)Certificates Search :
    Certificate Egroup not found !

    *** Search completed on Sun 10/14/2007 at 16:53:33.25 ***
  • Bugbatter

    4 Apprentice

    20487 Posts

    490

    0

    Posted October 14th, 2007 22:00

    You did not answer my question about being an employee. Are you a homeuser?
    Please check Add/Remove Programs. If AVsystemcare is listed there, uninstall it.

    Please download Combofix from here:
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    ** Take note that the link is case sensitive

    Save ComboFix to the desktop.

    1. Double click on combo.exe & follow the prompts.
    2. When finished, it will produce a logfile located at C:\ComboFix.txt.
    3. Post the contents of that log in your next reply with a new HijackThis log.
    4. Please post an an extra report:
    Please launch Hijackthis again. At the Main window select "Open the misc tool section"
    Then select "Open uninstall manager"
    Then "save list" and save it to your desktop.

    Copy and paste that list as a reply to this thread. Thanks.

    Note:
    Do not mouseclick Combofix's window while it is running. That may cause your system to stall/hang.
    Do not proceed with the rest of the fix if you fail to run ComboFix.


    Note: The above instructions have been created specifically for this user. If you are not this user, do NOT follow these directions.
  • 491

    0

    Posted October 15th, 2007 19:00

    ABBYY FineReader 6.0 Sprint Plus
    Adobe Acrobat - Reader 6.0.2 Update
    Adobe Flash Player ActiveX
    Adobe Reader 6.0.1
    AOL Coach Version 1.0(Build:20040229.1 en)
    AOL Uninstaller (Choose which Products to Remove)
    Apple Software Update
    Dell Driver Reset Tool
    Dell Media Experience
    Dell Photo AIO Printer 962
    Dell Picture Studio v3.0
    DellConnect
    DellSupport
    Dreamweaver MX WCC
    EarthLink setup files
    Get High Speed Internet!
    getPlus(R)_ocx
    Google Earth
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    HijackThis 2.0.2
    Home  Search Assistent 
    Intel(R) 537EP V9x DF PCI Modem
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) PRO Network Adapters and Drivers
    Intel(R) PROSet for Wired Connections
    Internet Explorer Default Page
    IsoBuster 2.1
    Jasc Paint Shop Photo Album
    Jasc Paint Shop Photo Album 5
    Jasc Paint Shop Pro 8 Dell Edition
    Jasc Paint Shop Pro Studio, Dell Editon
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) SE Runtime Environment 6 Update 1
    Learn2 Player (Uninstall Only)
    LG VX9900 (Verizon) MA730 - Handset Manager V9.5
    Macromedia Dreamweaver 8
    Macromedia Dreamweaver MX
    Macromedia Extension Manager
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Access 2002 SBS Files
    Microsoft Encarta Encyclopedia Standard 2004
    Microsoft Excel 2002 SBS Files
    Microsoft Money 2004
    Microsoft Money 2004 System Pack
    Microsoft Office XP Professional with FrontPage
    Microsoft Outlook 2002 SBS Files
    Microsoft Picture It! Photo Premium 9
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft PowerPoint 2002 SBS Files
    Microsoft Streets and Trips 2004
    Microsoft Word 2002
    Microsoft Word 2002 SBS Files
    Microsoft Works
    Microsoft Works 2004 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    Modem Event Monitor
    Modem Helper
    Modem On Hold
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MusicIP Mixer 1.7
    MusicIP MyDJ Plug-in
    Musicmatch for Windows Media Player
    Musicmatch® Jukebox
    My Way Search Assistant
    Navilog1 3.2.1
    NetZeroInstallers
    OverDrive Media Console
    PowerDVD 5.3
    Print to Fax
    Qualxserve Service Agreement
    QuickTime
    RealPlayer Basic
    Search  Extender
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB903235)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911280)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922760)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925454)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928090)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931768)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933566)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937143)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Shockwave
    Shopping Wizard
    Sonic DLA
    Sonic RecordNow!
    Sonic Update Manager
    TechConnect
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB929338)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Viewpoint Media Player
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows Media Player 10
    Windows XP Hotfix - KB834707
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885626
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB890923
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Windows XP Hotfix - KB893086
    XoftSpySE
    Yahoo! Toolbar
     
    Thankyou for your help
     
  • 490

    0

    Posted October 15th, 2007 19:00

    I am a home user. These are my combofix results:
     
    ComboFix 07-10-12.4 - Avis Johnson 2007-10-15 15:51:05.1 - NTFSx86
    Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.216 [GMT -4:00]
    Running from: C:\Documents and Settings\Avis Johnson\My Documents\My eBooks\ComboFix.exe
     * Created a new restore point
    .
    ADS - system32: deleted 3584 bytes in 1 streams.
    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
    C:\Program Files\outlook
    C:\WINDOWS\system32\9_exception.nls
    C:\WINDOWS\system32\bszip.dll
    C:\WINDOWS\system32\cmd.com
    C:\WINDOWS\system32\drivers\Fqr60.sys
    C:\WINDOWS\system32\drivers\IP6FW.SYS
    C:\WINDOWS\system32\drivers\Kwen61.sys
    C:\WINDOWS\system32\drivers\runtime2.sy_
    C:\WINDOWS\system32\drivers\runtime2.sys
    C:\WINDOWS\system32\drivers\symavc32.sys
    C:\WINDOWS\system32\drivers\YRQ41.sys
    C:\WINDOWS\system32\netstat.com
    C:\WINDOWS\system32\ping.com
    C:\WINDOWS\system32\printer.exe
    C:\WINDOWS\system32\regedit.com
    C:\WINDOWS\system32\taskkill.com
    C:\WINDOWS\system32\tasklist.com
    C:\WINDOWS\system32\tracert.com
    C:\WINDOWS\system32\vtr.dll
    C:\WINDOWS\system32\vtr.dll
    C:\WINDOWS\system32\WinAvXX.exe
    .
    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    -------\LEGACY_RUNTIME
    -------\LEGACY_RUNTIME2
    -------\LEGACY_YRQ41

    (((((((((((((((((((((((((   Files Created from 2007-09-15 to 2007-10-15  )))))))))))))))))))))))))))))))
    .
    2007-10-15 15:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-10-14 16:48 
     d-------- C:\Program Files\Navilog1
    2007-10-14 09:04   d-------- C:\Program Files\XoftSpySE
    2007-10-14 08:49   d-------- C:\Program Files\Trend Micro
    2007-10-12 19:50 113,152 --a------ C:\WINDOWS\dravis.exe
    2007-10-12 19:46 170,408 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys
    2007-10-12 19:46 71,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys
    2007-10-12 19:46 37,480 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys
    2007-10-12 19:46 34,184 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys
    2007-10-12 19:46 32,008 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys
    2007-10-12 19:45 107,608 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys
    2007-10-12 19:44   d-------- C:\Program Files\McAfee
    2007-10-12 19:44   d-------- C:\Program Files\Common Files\McAfee
    2007-10-12 19:43   d-------- C:\Documents and Settings\All Users\Application Data\McAfee
    2007-10-12 19:03 20,992 --a------ C:\WINDOWS\dravic.exe
    2007-10-12 19:03 16,384 --a------ C:\WINDOWS\xlavra3.exe
    2007-10-11 20:18 7,849 --a------ C:\WINDOWS\SYSTEM32\sulimo.dat
    2007-10-09 21:39 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
    2007-10-07 11:49   d-------- C:\Documents and Settings\Avis Johnson\Application Data\OverDrive
    2007-10-07 11:41   d-------- C:\Program Files\OverDrive Media Console
    2007-10-05 16:29   d-------- C:\Program Files\Google
    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-12 23:49 --------- d-----w C:\Program Files\McAfee.com
    2007-10-12 23:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
    2007-10-12 23:14 --------- d-----w C:\Documents and Settings\Avis Johnson\Application Data\LimeWire
    2007-10-03 01:56 --------- d-----w C:\Documents and Settings\Pearlie McFadden\Application Data\AdobeUM
    2007-08-19 14:03 --------- d-----w C:\Program Files\MusicIP
    2007-08-19 13:59 --------- d-----w C:\Documents and Settings\Avis Johnson\Application Data\MusicIP
    2007-08-17 22:14 --------- d-----w C:\Program Files\Mobile Action
    2007-08-17 21:57 --------- d-----w C:\Documents and Settings\Avis Johnson\Application Data\MobileAction
    2007-08-16 23:29 --------- d-----w C:\Program Files\Smart Projects
    2007-08-16 22:25 --------- d-----w C:\Documents and Settings\Avis Johnson\Application Data\AdobeUM
    2007-08-15 00:16 --------- d-----w C:\Program Files\Incomplete
    2007-08-14 01:05 7,168 --sha-w C:\Program Files\Thumbs.db
    2007-07-29 22:27 315 ----a-w C:\KillUnin.bat
    2007-07-29 00:58 58,432 ----a-w C:\Documents and Settings\Avis Johnson\Application Data\GDIPFONTCACHEV1.DAT
    2007-03-22 22:45 49,066 ----a-w C:\Documents and Settings\Pearlie McFadden\Application Data\wklnhst.dat
    2006-09-25 06:57 58,432 ----a-w C:\Documents and Settings\Pearlie McFadden\Application Data\GDIPFONTCACHEV1.DAT
    2005-07-27 23:10 140 ----a-w C:\Documents and Settings\Avis Johnson\Application Data\wklnhst.dat
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27CF1C68-19A6-58A8-F34A-D75AF141C93E}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{380C904F-55CD-338E-24B0-013D0423F1B0}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{44E12371-18A5-CADE-1043-D0FDEEBCF1CB}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50B91207-4289-28BE-FC70-4CE72F0402CB}]

    These are the results of my new HijackThis scan:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:12, on 2007-10-15
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\WINDOWS\Explorer.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
    http://www.dell4me.com/myway
    O2 - BHO: (no name) - {27CF1C68-19A6-58A8-F34A-D75AF141C93E} - (no file)
    O2 - BHO: (no name) - {380C904F-55CD-338E-24B0-013D0423F1B0} - (no file)
    O2 - BHO: (no name) - {44E12371-18A5-CADE-1043-D0FDEEBCF1CB} - (no file)
    O2 - BHO: (no name) - {50B91207-4289-28BE-FC70-4CE72F0402CB} - (no file)
    O2 - BHO: (no name) - {54351455-EFE9-7EFE-3393-B2622AF47B0F} - (no file)
    O2 - BHO: (no name) - {651214D8-15FD-F7BB-3AF2-BA7967C08710} - (no file)
    O2 - BHO: (no name) - {6F2EB59A-6F50-8B14-0D7D-BCC43DC7177A} - (no file)
    O2 - BHO: (no name) - {77A8711A-0D8F-49B8-6DFB-AE85E05A493A} - (no file)
    O2 - BHO: (no name) - {7FE16BED-1E1A-0F9A-E962-90627CF19B7B} - (no file)
    O2 - BHO: (no name) - {801F3199-8EAB-0036-12D6-35DEE31205DC} - (no file)
    O2 - BHO: (no name) - {8F7D04CA-6D30-6286-E432-22FFB0FB128A} - (no file)
    O2 - BHO: (no name) - {916EEA1B-BCB7-4A5B-522D-4623137184B4} - (no file)
    O2 - BHO: (no name) - {94BD1A37-5653-88A2-1E65-7852D1BEE72F} - (no file)
    O2 - BHO: (no name) - {A72F96DF-A4F3-57A8-1C3A-8C57E40658C5} - (no file)
    O2 - BHO: (no name) - {D6A0E97F-3C18-7E5D-E033-44852E515B86} - (no file)
    O2 - BHO: (no name) - {E00B6257-B5AF-B5AF-80E5-5F0087457F4F} - (no file)
    O2 - BHO: (no name) - {F18949DB-2CBC-81C3-5DC7-B25366CB61D4} - (no file)
    O2 - BHO: (no name) - {F7375AC2-A5D6-EEBC-9B5B-3DFA6FA5DD51} - (no file)
    O2 - BHO: (no name) - {FA682029-FE62-181C-B031-3233A3C5A91E} - (no file)
    O2 - BHO: (no name) - {FA78BCF6-1C11-1477-172D-2FA8B8257F0B} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [MaBtSh] C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
    http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
    http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://domino1.ncat.edu/dwa7W.cab
    O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä #·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apibv.exe (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 7466 bytes

     


  • Bugbatter

    4 Apprentice

    20487 Posts

    491

    0

    Posted October 15th, 2007 20:00

    You're welcome. We have more to do...

    Please go to Add/Remove Programs and remove these:

    Shopping Wizard
    Search Extender



    Open Notepad and copy/paste the following bold text between the dotted lines into it. Do not copy the dotted lines.

    -----------------------------------------------------------------------------------------------

    File::
    C:\WINDOWS\dravic.exe
    C:\WINDOWS\dravis.exe
    C:\WINDOWS\SYSTEM32\sulimo.dat
    C:\WINDOWS\xlavra2.exe


    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{27CF1C68-19A6-58A8-F34A-D75AF141C93E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{380C904F-55CD-338E-24B0-013D0423F1B0}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{44E12371-18A5-CADE-1043-D0FDEEBCF1CB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{50B91207-4289-28BE-FC70-4CE72F0402CB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{54351455-EFE9-7EFE-3393-B2622AF47B0F}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{651214D8-15FD-F7BB-3AF2-BA7967C08710}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{6F2EB59A-6F50-8B14-0D7D-BCC43DC7177A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{77A8711A-0D8F-49B8-6DFB-AE85E05A493A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{7FE16BED-1E1A-0F9A-E962-90627CF19B7B}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{801F3199-8EAB-0036-12D6-35DEE31205DC}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{8F7D04CA-6D30-6286-E432-22FFB0FB128A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{916EEA1B-BCB7-4A5B-522D-4623137184B4}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{94BD1A37-5653-88A2-1E65-7852D1BEE72F}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{A72F96DF-A4F3-57A8-1C3A-8C57E40658C5}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{D6A0E97F-3C18-7E5D-E033-44852E515B86}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{E00B6257-B5AF-B5AF-80E5-5F0087457F4F}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{F18949DB-2CBC-81C3-5DC7-B25366CB61D4}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{F7375AC2-A5D6-EEBC-9B5B-3DFA6FA5DD51}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{FA682029-FE62-181C-B031-3233A3C5A91E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Browser Helper Objects\{FA78BCF6-1C11-1477-172D-2FA8B8257F0B}]



    --------------------------------------------------------------------------------------------------------

    Save this as CFScript.txt

    Photo Sharing and Video Hosting at Photobucket

    Referring to the picture above, drag CFScript into ComboFix.exe
    You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
    CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

    When finished, a log is produced here: C:\ComboFix.txt

    Please provide the contents of the new ComboFix log in your next reply along with a new HijackThis log, and let me know how things are running.

    Do you know what this is?
    KillUnin.bat
  • 491

    0

    Posted November 5th, 2007 20:00

    Please help me again.  I was on a few weeks ago trying to get help about some pop-ups I was getting. They have returned. Same message saying " WARNING POTENTIAL SPYWARE.."  unaurthorized... Now I am unable to use any of the programs I used before.  Everytime I try to use Navilog or Combofix I get a message saying another program is currently using this file.  Please if anyone could help me again it would be greatly appreciated.  I would like to know how to get rid of this problem once and for all. Also would like to know if there is any anti-virus software that I should use in particular.  Please Help me again. 
  • Bugbatter

    4 Apprentice

    20487 Posts

    491

    0

    Posted November 5th, 2007 22:00

    Two weeks ago you did not post the required logs for review, so that I could see if the infection was completely removed. Apparently it has regenerated because there were some remnants still in there.

    Please download the OTMoveIt by OldTimer
    • Save it to your desktop.
    • Run the tool by clicking on the icon.
    • Click the Cleanup button.
    • The tools that we used as well as this one will be removed from your system.


    After you have done that, please post a fresh Hijackthis log, so we can begin again.
  • Bugbatter

    4 Apprentice

    20487 Posts

    98

    0

    Posted November 9th, 2007 16:00

    According to your log, the infections that you had last month did not return. You remained vulnerable because last month's fix was not completed.
    We will not be able to fix these multiple infections with delayed replies, because there is a chance that the malware will return in the interim.
    Please let me know when you will have time to work on a fix that requires replies within 24 hours. Thanks.
  • 491

    0

    Posted November 9th, 2007 16:00

    The following is a copy of my latest HJT log.
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:31:45 PM, on 11/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\system32\mubhmovg.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\WINDOWS\Explorer.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\WINDOWS\mrofinu1000140.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
    C:\Documents and Settings\Avis Johnson\Start Menu\Programs\Startup\infos.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
    http://www.dell4me.com/myway
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1169982853\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [MaBtSh] C:\Program Files\Mobile Action\Bluetooth Manager\MaBtSh.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000140.exe 61A847B5BBF72813329B385776F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310F3D1DC7E4638E8323A15806F97BDE4417E6FD967002BA754E2C2832213369B26033AAC
    O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
    O4 - HKLM\..\Run: [743cb083] rundll32.exe "C:\WINDOWS\system32\najdldpm.dll",b
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\AVISJO~1\MYDOCU~1\WNSXS~1\mmc.exe" -vt yazb
    O4 - HKCU\..\Run: [Zqwwe] "C:\Documents and Settings\Avis Johnson\Application Data\?dobe\l?gonui.exe"
    O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
    O4 - Startup: infos.exe
    O4 - Global Startup: autos.exe
    O4 - Global Startup: dllhost.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
    http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
    http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://domino1.ncat.edu/dwa7W.cab
    O20 - AppInit_DLLs: C:\WINDOWS\system32\skuns.dat
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä #·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apibv.exe (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
    O23 - Service: DomainService -   - C:\WINDOWS\system32\mubhmovg.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\rterte.html
    --
    End of file - 5532 bytes