Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Please Help Diagnose


  • This topic is locked This topic is locked
8 replies to this topic

#1 T_Dilley

T_Dilley

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:33 AM

Posted 20 July 2007 - 10:59 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:59:02 PM, on 7/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avp.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\agent32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\mgrs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sys32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\64mon.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\powerlook.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\gcycjllc.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 5099 bytes

BC AdBot (Login to Remove)

 


#2 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:10:33 AM

Posted 21 July 2007 - 12:05 AM

Hello T_Dilley,

Please download Combofix to your desktop.
Doubleclick combo.exe to launch the application.
Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
Posted Image

#3 T_Dilley

T_Dilley
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:33 AM

Posted 21 July 2007 - 12:46 AM

"Administrator" - 2007-07-21 0:35:51 - ComboFix 07-07-14.6 - Service Pack 2 FAT32


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\xxyxwxw.dll
C:\WINDOWS\system32\ssqqqol.dll
C:\WINDOWS\system32\gcycjllc.dll
C:\WINDOWS\system32\ypjgbton.exe
C:\WINDOWS\system32\iqgpoefd.exe
C:\WINDOWS\system32\fdxooffl.dll
C:\WINDOWS\system32\teknnfed.dll
C:\WINDOWS\system32\jhfbpecu.dll
C:\WINDOWS\system32\yihdrpvb.dll
C:\WINDOWS\system32\xxyxwxw.dll
C:\WINDOWS\system32\winyom32.dll
C:\WINDOWS\system32\clljcycg.ini
C:\WINDOWS\system32\lnqru.bak1
C:\WINDOWS\system32\lnqru.bak2
C:\WINDOWS\system32\lnqru.ini
C:\WINDOWS\system32\lnqru.bak1
C:\WINDOWS\system32\lnqru.bak2
C:\WINDOWS\system32\lnqru.ini
C:\WINDOWS\system32\vtuvvvt.dll
C:\WINDOWS\system32\urqnl.dll
C:\WINDOWS\system32\vtuvvvt.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\bgdcecni.exe
C:\WINDOWS\system32\fpvlvxdf.exe
C:\WINDOWS\system32\gdcbfaos.exe
C:\WINDOWS\system32\intcoudm.exe
C:\WINDOWS\system32\syswin.exe
C:\WINDOWS\system32\vasbcrul.exe


((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))


2007-07-21 00:34 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-20 22:54 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-16 23:13 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-16 23:12 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.housecall6.6
2007-07-15 12:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-06 16:22 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2007-07-06 16:22 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2007-07-06 16:22 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2007-07-06 16:22 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2007-07-06 16:22 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2007-07-06 16:22 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2007-07-06 16:22 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2007-07-06 16:22 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2007-06-30 23:44 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
2007-06-30 23:43 740,442 --a------ C:\WINDOWS\system32\divx.dll
2007-06-30 23:43 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-06-30 23:43 593,920 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-06-30 23:43 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-06-30 23:43 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-06-30 23:43 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-06-30 23:43 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-06-30 23:43 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-06-22 18:06 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
2007-06-22 18:01 <DIR> d-------- C:\Program Files\QuickTime
2007-06-22 18:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-15 14:40:24 9,216 ----a-w C:\WINDOWS\system32\avgwlntf.dll
2007-06-15 14:40:24 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-06-15 14:40:24 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-06-15 14:40:24 110,592 ----a-w C:\WINDOWS\system32\avgfwafu.dll
2007-06-15 05:15:56 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
2007-06-15 05:14:32 -------- d-----w C:\Program Files\Nero
2007-06-15 05:14:32 -------- d-----w C:\Program Files\Common Files\Ahead
2007-06-15 04:35:42 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2007-06-15 04:13:26 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
2007-06-15 04:11:56 -------- d-----w C:\Program Files\LimeWire
2007-06-12 05:21:34 1,156 ----a-w C:\WINDOWS\mozver.dat
2007-06-12 03:35:36 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-06-12 03:35:18 -------- d-----w C:\Program Files\Lavasoft
2007-06-12 02:59:46 -------- d-----w C:\Program Files\MSN Messenger
2007-06-11 21:58:48 -------- d-----w C:\Program Files\Winamp
2007-06-11 21:54:36 0 ----a-w C:\WINDOWS\nsreg.dat
2007-06-07 03:38:42 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-05 01:36:08 -------- d-----w C:\Program Files\CyberLink
2007-05-16 15:32:56 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 14:42:22 972,336 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-05-15 14:45:14 972,336 ----a-w C:\WINDOWS\UNNeroVision.exe
2007-05-13 23:57:56 0 --sha-r C:\MSDOS.SYS
2007-05-13 23:57:56 0 --sha-r C:\IO.SYS
2007-05-13 23:57:56 0 ----a-w C:\CONFIG.SYS
2007-05-13 23:57:56 0 ----a-w C:\AUTOEXEC.BAT
2007-05-13 23:54:08 21,640 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-05-13 23:50:10 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2007-05-13 23:50:10 8,192 ----a-w C:\WINDOWS\system32\tsbyuv.dll
2007-05-13 23:50:10 8,192 ----a-w C:\WINDOWS\system32\streamci.dll
2007-05-13 23:50:10 77,891 ----a-w C:\WINDOWS\system32\usrmlnka.exe
2007-05-13 23:50:10 77,890 ----a-w C:\WINDOWS\system32\usrdpa.dll
2007-05-13 23:50:10 77,883 ----a-w C:\WINDOWS\system32\usrrtosa.dll
2007-05-13 23:50:10 72,192 ----a-w C:\WINDOWS\system32\sprio800.dll
2007-05-13 23:50:10 70,656 ----a-w C:\WINDOWS\system32\sprio600.dll
2007-05-13 23:50:10 69,700 ----a-w C:\WINDOWS\system32\usrshuta.exe
2007-05-13 23:50:10 69,699 ----a-w C:\WINDOWS\system32\usrcoina.dll
2007-05-13 23:50:10 69,632 ----a-w C:\WINDOWS\system32\spnike.dll
2007-05-13 23:50:10 61,508 ----a-w C:\WINDOWS\system32\usrprbda.exe
2007-05-13 23:50:10 61,500 ----a-w C:\WINDOWS\system32\usrcntra.dll
2007-05-13 23:50:10 55,296 ----a-w C:\WINDOWS\system32\dvdplay.exe
2007-05-13 23:50:10 53,305 ----a-w C:\WINDOWS\system32\usrlbva.dll
2007-05-13 23:50:10 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
2007-05-13 23:50:10 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
2007-05-13 23:50:10 49,211 ----a-w C:\WINDOWS\system32\usrvpa.dll
2007-05-13 23:50:10 49,211 ----a-w C:\WINDOWS\system32\usrsdpia.dll
2007-05-13 23:50:10 49,209 ----a-w C:\WINDOWS\system32\usrv80a.dll
2007-05-13 23:50:10 476,160 ----a-w C:\WINDOWS\system32\wzcsvc.dll
2007-05-13 23:50:10 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
2007-05-13 23:50:10 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
2007-05-13 23:50:10 45,116 ----a-w C:\WINDOWS\system32\usrvoica.dll
2007-05-13 23:50:10 41,019 ----a-w C:\WINDOWS\system32\usrsvpia.dll
2007-05-13 23:50:10 35,328 ----a-w C:\WINDOWS\system32\pid.dll
2007-05-13 23:50:10 323,641 ----a-w C:\WINDOWS\system32\usrdtea.dll
2007-05-13 23:50:10 3,200 ----a-w C:\WINDOWS\system32\wowfax.dll
2007-05-13 23:50:10 20,992 ----a-w C:\WINDOWS\system32\hid.dll
2007-05-13 23:50:10 17,408 ----a-w C:\WINDOWS\system32\msyuv.dll
2007-05-13 23:50:10 157,696 ----a-w C:\WINDOWS\system32\paqsp.dll
2007-05-13 23:50:10 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
2007-05-13 23:50:10 147,968 ----a-w C:\WINDOWS\system32\mdwmdmsp.dll
2007-05-13 23:50:10 13,824 ----a-w C:\WINDOWS\system32\wowfaxui.dll
2007-05-13 23:50:10 102,457 ----a-w C:\WINDOWS\system32\usrv42a.dll
2007-05-13 23:38:34 95,344 ----a-w C:\WINDOWS\system32\wudfcoinstaller.dll
2007-05-13 23:38:34 55,808 ----a-w C:\WINDOWS\system32\wudfsvc.dll
2007-05-13 23:38:34 316,416 ----a-w C:\WINDOWS\system32\wudfx.dll
2007-05-13 23:38:34 165,376 ----a-w C:\WINDOWS\system32\wudfplatform.dll
2007-05-13 23:38:32 38,400 ----a-w C:\WINDOWS\system32\wpdshextres.dll
2007-05-13 23:38:32 356,352 ----a-w C:\WINDOWS\system32\WPDSp.dll
2007-05-13 23:38:32 17,408 ----a-w C:\WINDOWS\system32\wpdshextautoplay.exe
2007-05-13 23:38:32 146,432 ----a-w C:\WINDOWS\system32\wudfhost.exe
2007-05-13 23:38:32 133,632 ----a-w C:\WINDOWS\system32\wpdshserviceobj.dll
2007-05-13 23:38:30 2,603,008 ----a-w C:\WINDOWS\system32\wpdshext.dll
2007-05-13 23:38:28 63,488 ----a-w C:\WINDOWS\system32\wpdmtpus.dll
2007-05-13 23:38:26 629,760 ----a-w C:\WINDOWS\system32\wpd_ci.dll
2007-05-13 23:38:26 35,840 ----a-w C:\WINDOWS\system32\wpdconns.dll
2007-05-13 23:38:26 154,624 ----a-w C:\WINDOWS\system32\wpdmtp.dll
2007-05-13 23:38:24 767,488 ----a-w C:\WINDOWS\system32\wmvsencd.dll
2007-05-13 23:38:24 656,896 ----a-w C:\WINDOWS\system32\wmvxencd.dll
2007-05-13 23:38:22 1,382,912 ----a-w C:\WINDOWS\system32\wmvsdecd.dll
2007-05-13 23:38:20 1,574,912 ----a-w C:\WINDOWS\system32\wmvencod.dll
2007-05-13 23:38:18 4,096 ----a-w C:\WINDOWS\system32\wmvdmoe2.dll
2007-05-13 23:38:18 4,096 ----a-w C:\WINDOWS\system32\wmvdmod.dll
2007-05-13 23:38:18 1,543,680 ----a-w C:\WINDOWS\system32\wmvdecod.dll
2007-05-13 23:38:14 4,096 ----a-w C:\WINDOWS\system32\wmvadve.dll
2007-05-13 23:38:12 4,096 ----a-w C:\WINDOWS\system32\wmvadvd.dll
2007-05-13 23:38:12 1,329,152 ----a-w C:\WINDOWS\system32\wmspdmoe.dll
2007-05-13 23:38:10 99,840 ----a-w C:\WINDOWS\system32\wmpshell.dll
2007-05-13 23:38:10 603,648 ----a-w C:\WINDOWS\system32\wmspdmod.dll
2007-05-13 23:38:10 4,096 ----a-w C:\WINDOWS\system32\wmsdmoe2.dll
2007-05-13 23:38:10 4,096 ----a-w C:\WINDOWS\system32\wmsdmod.dll
2007-05-13 23:38:10 204,288 ----a-w C:\WINDOWS\system32\wmpsrcwp.dll
2007-05-13 23:38:10 130,048 ----a-w C:\WINDOWS\system32\wmpps.dll
2007-05-13 23:38:08 8,231,936 ----a-w C:\WINDOWS\system32\wmploc.dll
2007-05-13 23:38:08 613,376 ----a-w C:\WINDOWS\system32\wmpmde.dll
2007-05-13 23:37:56 1,661,440 ----a-w C:\WINDOWS\system32\WMPEncEn.dll
2007-05-13 23:37:54 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
2007-05-13 23:37:52 314,880 ----a-w C:\WINDOWS\system32\wmpdxm.dll
2007-05-13 23:37:52 242,688 ----a-w C:\WINDOWS\system32\wmpasf.dll
2007-05-13 23:37:30 937,984 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
2007-05-13 23:37:30 157,184 ----a-w C:\WINDOWS\system32\wmidx.dll
2007-05-13 23:37:28 534,528 ----a-w C:\WINDOWS\system32\wmdrmsdk.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-15 09:40]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 08:18]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"ShowDeskFix"=regsvr32 /s /n /i:u shell32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll --a------ 2007-06-15 09:40 9216 C:\WINDOWS\system32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"smgr"=mgrs.exe


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-21 00:42:10
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-21 0:43:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-21 00:43

--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:46, on 7/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 4782 bytes

#4 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:10:33 AM

Posted 21 July 2007 - 11:47 AM

Hello T_Dilley,

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

Now close all windows other than HiJackThis, then click Fix Checked. Close HijackThis.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

Posted Image

#5 T_Dilley

T_Dilley
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:33 AM

Posted 22 July 2007 - 03:37 PM

Incident Status Location

Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NIRCMD.EXE
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@stats.drivecleaner[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@azjmp[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.winantivirus[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@winantivirus[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@drivecleaner[2].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@yadro[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@target[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@enhance[2].txt
Spyware:Cookie/66.246.209 Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@66.246.209[1].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@systemdoctor[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.2o7.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.serving-sys.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.doubleclick.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.serving-sys.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.atdmt.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.ads.pointroll.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.realmedia.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.trafficmp.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.bluestreak.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.casalemedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.questionmarket.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.apmebf.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.mediaplex.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.zedo.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.fastclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.advertising.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.247realmedia.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[www.winantiviruspro.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.systemdoctor.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[statse.webtrendslive.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.tradedoubler.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.adultfriendfinder.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.atwola.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.bravenet.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.burstnet.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.go.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[.perf.overture.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[citi.bridgetrack.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[landing.domainsponsor.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yox47w45.default\COOKIES.TXT[winantispyware.com/]
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gdcbfaos.exe.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\fpvlvxdf.exe.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\intcoudm.exe.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bgdcecni.exe.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\vasbcrul.exe.vir
Adware:Adware/UltimateCleaner Not disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\syswin.exe.vir
Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xxyxwxw.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ssqqqol.dll.vir
Virus:Trj/Downloader.PJT Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ypjgbton.exe.vir
Virus:Trj/Downloader.PCQ Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\iqgpoefd.exe.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\teknnfed.dll.vir
Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jhfbpecu.dll.vir
Adware:Adware/SpywareNo Not disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winyom32.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\vtuvvvt.dll.vir
Adware:Adware/DriveCleaner Not disinfected C:\QooBox\Quarantine\C\WINDOWS\avp.exe.vir
Adware:Adware/Antivirus-gold Not disinfected C:\QooBox\Quarantine\C\WINDOWS\mgrs.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Recycled\Dc2.exe[nircmd.exe]

#6 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:10:33 AM

Posted 22 July 2007 - 10:07 PM

Hello T_Dilley,

Using Windows Explorer delete the following folders (if present): (To get into Windows Explorer, right click the START button and select "explore.")

C:\QooBox

Please post back with a fresh HJT log and an update on how your computer is running.
Posted Image

#7 T_Dilley

T_Dilley
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:33 AM

Posted 22 July 2007 - 10:59 PM

Computer is running much better. No more popups.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:58, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 4830 bytes

#8 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:10:33 AM

Posted 23 July 2007 - 09:46 AM

Hello T_Dilley,

let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. Turn off System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Restart your computer.

3. Turn ON System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
[/list]System Restore will now be active again.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources
  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

Posted Image

#9 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:10:33 AM

Posted 06 September 2007 - 12:24 AM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users