Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Firefox Freeze


  • Please log in to reply
9 replies to this topic

#1 eddiedev

eddiedev

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 03 August 2007 - 11:48 AM

Firefox freezes for about 20 seconds whenever i click on anything. its extremely annoying, and i consider my computer lucky that i havent punted it out teh window yet.

heres my HJT log....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:38, on 2007-08-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\RACLE~1\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Documents and Settings\ed\Desktop\Fixin Stuff\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\ed\LOCALS~1\Temp\MBDownloader_876919.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\amorxyfg.dll",forkonce
O4 - HKCU\..\Run: [Cpue] "C:\WINDOWS\RACLE~1\explorer.exe" -vt yazb
O4 - HKCU\..\Run: [Hydjlkwv] C:\WINDOWS\??pPatch\??rvices.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1184881944414
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 6061 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:57 AM

Posted 03 August 2007 - 04:54 PM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum eddiedev :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Post the contents of C:\vundofix.txt into your next reply.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

---------------------------------------------

Please download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

---------------------------------------------

Now go to:
C:\Documents and Settings\ed\Desktop\Fixin Stuff\HiJackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Posted Image
Posted Image

#3 eddiedev

eddiedev
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 05 August 2007 - 06:43 PM

been having a few more problems since my last post... im getting some pop ups from IE and my CPU is running pretty slow.... here are the logs you requested.


VundoFix......


VundoFix V6.5.6

Checking Java version...

Scan started at 18:08:09 2007-08-03

Listing files found while scanning....

C:\WINDOWS\system32\oqtss.bak1
C:\WINDOWS\system32\oqtss.ini
C:\WINDOWS\system32\sstqo.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\oqtss.bak1
C:\WINDOWS\system32\oqtss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\oqtss.ini
C:\WINDOWS\system32\oqtss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstqo.dll
C:\WINDOWS\system32\sstqo.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version...

Scan started at 18:59:33 2007-08-05

Listing files found while scanning....

C:\WINDOWS\system32\lmllm.bak1
C:\WINDOWS\system32\lmllm.ini
C:\WINDOWS\system32\mllml.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\lmllm.bak1
C:\WINDOWS\system32\lmllm.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\lmllm.ini
C:\WINDOWS\system32\lmllm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mllml.dll
C:\WINDOWS\system32\mllml.dll Has been deleted!

Performing Repairs to the registry.
Done!


ComboFix....

"ed" - 2007-08-05 19:18:58 - ComboFix 07-07-17.8 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\system32\klkkj.bak1
C:\WINDOWS\system32\klkkj.ini


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\ppatch~1
C:\WINDOWS\racle~1
C:\WINDOWS\racle~1\explorer.exe
C:\WINDOWS\sembly~1
C:\WINDOWS\sembly~1\?hkntfs.exe
C:\WINDOWS\system32\bewmidjd.exe
C:\WINDOWS\system32\hacjxvuk.exe
C:\WINDOWS\system32\rejknpfw.exe
C:\WINDOWS\system32\wapisu32.exe
C:\WINDOWS\system32\win


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-05 03:20 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-08-05 03:19 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-04 20:41 125,504 --a------ C:\WINDOWS\system32\taqvlola.dll
2007-08-03 20:18 60,928 --a------ C:\WINDOWS\system32\ruynflz.dll
2007-08-03 18:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-08-03 18:08 <DIR> d-------- C:\VundoFix Backups
2007-08-03 12:53 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-08-03 12:53 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-08-03 09:06 69,184 --a------ C:\WINDOWS\system32\tjdlcdqh.dll
2007-08-03 08:33 125,504 --a------ C:\WINDOWS\system32\amorxyfg.dll
2007-08-02 19:53 31,254 --a------ C:\WINDOWS\system32\vturpmj.dll
2007-07-30 19:06 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\CyberLink
2007-07-24 21:13 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-07-24 21:13 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-07-24 21:13 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-07-24 21:13 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-07-24 21:13 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-07-24 21:13 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-07-24 21:13 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-07-24 21:12 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-07-24 21:12 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-07-24 21:12 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-07-24 21:12 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-07-24 21:12 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-07-24 21:12 345,088 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-07-24 21:12 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-07-24 21:12 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-07-24 21:12 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-07-24 21:12 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-07-24 21:12 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-07-24 21:12 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-07-24 21:12 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-07-24 21:12 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-07-22 10:03 <DIR> d-------- C:\Program Files\WinXMedia
2007-07-21 18:27 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\AdobeUM
2007-07-21 12:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 18:02 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-19 18:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-19 17:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-18 13:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-18 13:45 <DIR> d-------- C:\Program Files\msn gaming zone
2007-07-18 04:47 <DIR> d---s---- C:\DOCUME~1\ed\UserData
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\Z11
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\b02FdUe
2007-07-17 14:40 <DIR> d-------- C:\Temp\brr
2007-07-17 14:40 <DIR> d-------- C:\Temp\0c2
2007-07-17 14:40 <DIR> d-------- C:\Temp
2007-07-10 17:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-07 11:54 <DIR> d-------- C:\Program Files\iPod
2007-07-07 11:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-07 11:49 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-07 11:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-25 01:13:13 -------- d-----w C:\Program Files\Windows NT
2007-07-18 16:25:53 -------- d-----w C:\Program Files\Common Files\Real
2007-07-07 15:54:50 -------- d-----w C:\Program Files\iTunes
2007-06-30 16:11:01 -------- d-----w C:\Program Files\Symantec
2007-06-30 16:10:50 -------- d-----w C:\Program Files\SymNetDrv
2007-06-30 16:10:22 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-16 14:07:59 -------- d-----w C:\Program Files\Apple Software Update
2007-06-10 18:44:35 1,290 ----a-w C:\WINDOWS\mozver.dat
2007-06-10 18:44:34 -------- d-----w C:\Program Files\DivX
2007-06-07 10:57:45 -------- d-----w C:\DOCUME~1\ed\APPLIC~1\Viewpoint
2007-06-05 18:28:51 -------- d-----w C:\Program Files\Microsoft ActiveSync
2007-06-05 18:26:31 -------- d-----w C:\Program Files\Common Files\ODBC
2007-06-04 20:32:50 60 ----a-w C:\WINDOWS\system32\SYSDRV.DAT


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 17:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CB41020-8E23-45B5-A390-112C43A63DC9}]
C:\WINDOWS\system32\mllml.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{385EF57F-8F5A-4270-A58D-7A360C43D103}]
C:\WINDOWS\system32\sstqo.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3964D8D6-86D0-493A-B460-A805B5401114}]
2007-08-02 19:53 31254 --a------ C:\WINDOWS\system32\vturpmj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C8EAB98-3E0C-4ADA-2175-4AB6023CF0CE}]
2007-08-01 09:43 60928 --a------ C:\WINDOWS\system32\ruynflz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-08-18 02:34 103592 --a------ C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
2007-08-03 09:20 69184 --a------ C:\WINDOWS\system32\tjdlcdqh.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 10:34 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2004-03-03 20:29 C:\WINDOWS\system32\nwiz.exe]
"nForce Tray Options"="sstray.exe" [2003-09-03 04:25 C:\WINDOWS\system32\sstray.exe]
"CHotkey"="zHotkey.exe" [2004-05-18 04:30 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 19:09 C:\WINDOWS\ShowWnd.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 05:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"NAV CfgWiz"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 21:24]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-12 01:18]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-06-30 12:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cpue"="C:\WINDOWS\RACLE~1\explorer.exe" []
"Jdrl"="C:\WINDOWS\??sembly\?hkntfs.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{3964D8D6-86D0-493A-B460-A805B5401114}"="C:\WINDOWS\system32\vturpmj.dll" [2007-08-02 19:53]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturpmj]
vturpmj.dll --a------ 2007-08-02 19:53 31254 C:\WINDOWS\system32\vturpmj.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\ed\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WebBuying"=C:\Program Files\Web Buying\v1.7.8\webbuying.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

*Newly Created Service* - GTNDIS5

Contents of the 'Scheduled Tasks' folder
2007-08-04 10:49:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-08-04 00:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2007-06-30 16:05:28 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 19:31:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-05 19:34:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-05 19:34
C:\ComboFix2.txt ... 2007-07-21 12:51

--- E O F ---


and HJT.....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:32 PM, on 8/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\ed\Desktop\Fixin Stuff\abc.bat.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB41020-8E23-45B5-A390-112C43A63DC9} - C:\WINDOWS\system32\mllml.dll (file missing)
O2 - BHO: (no name) - {385EF57F-8F5A-4270-A58D-7A360C43D103} - C:\WINDOWS\system32\sstqo.dll (file missing)
O2 - BHO: (no name) - {3964D8D6-86D0-493A-B460-A805B5401114} - C:\WINDOWS\system32\vturpmj.dll
O2 - BHO: (no name) - {4C8EAB98-3E0C-4ADA-2175-4AB6023CF0CE} - C:\WINDOWS\system32\ruynflz.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\tjdlcdqh.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Cpue] "C:\WINDOWS\RACLE~1\explorer.exe" -vt yazb
O4 - HKCU\..\Run: [Jdrl] C:\WINDOWS\??sembly\?hkntfs.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1186159966046
O20 - Winlogon Notify: vturpmj - C:\WINDOWS\SYSTEM32\vturpmj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 6504 bytes

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:57 AM

Posted 05 August 2007 - 07:31 PM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\taqvlola.dll
C:\WINDOWS\system32\ruynflz.dll
C:\WINDOWS\system32\tjdlcdqh.dll
C:\WINDOWS\system32\amorxyfg.dll
C:\WINDOWS\system32\vturpmj.dll

Folder::
C:\WINDOWS\system32\Z11
C:\WINDOWS\system32\b02FdUe
C:\Temp\brr
C:\Temp\0c2
C:\DOCUME~1\ed\APPLIC~1\Viewpoint

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CB41020-8E23-45B5-A390-112C43A63DC9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{385EF57F-8F5A-4270-A58D-7A360C43D103}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3964D8D6-86D0-493A-B460-A805B5401114}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C8EAB98-3E0C-4ADA-2175-4AB6023CF0CE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cpue"=-
"Jdrl"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{3964D8D6-86D0-493A-B460-A805B5401114}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturpmj]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WebBuying"=-

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Let me know how your pc is running now.
Posted Image
Posted Image

#5 eddiedev

eddiedev
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 06 August 2007 - 10:54 AM

Firefox doesnt freeze up anymore, howeveri still get a pop up or two from IE every now and then, and once every brief while ill get one from firefox.

"ed" - 2007-08-06 10:48:48 - ComboFix 07-07-17.8 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\ed\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ed\APPLIC~1\Viewpoint
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\-1047652577.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\-1241215004.mtx
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\1819212666.mtj&p2=1&p3=10605728068861076121330828811199&p4=50463258
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\353335032.mtz
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1141136244.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1233786184.mtx
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1270184280.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1355542221.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1787438168.mtj&p2=1&p3=10605728068861076121330828811199&p4=50463258
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\1439616145.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\1581793880.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\1939605770.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\2060173587.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\353335039.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\907465110.mtj&p2=1&p3=10605728068861076121330828811199&p4=0
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\939132219.swf
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\-1047608846.swf
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\-157354182.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\-942604390.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\1222968857.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\1519480151.swf
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\1581833997.swf
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\160189405.mzv
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\1769081669.mzv
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\257492326.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\407034558.ini
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\589291352.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-1510534710.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-1867829355.mtz
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-1890015939.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-264463341.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-474211254.mzv
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-768327976.swf
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-882707288.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\1575878256.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\1786638470.mzv
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\922728436.mts
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\DOCUME~1\ed\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\UpdateVersionList_v2.mtx
C:\Temp\0c2
C:\Temp\0c2\tmpFF.log
C:\Temp\brr
C:\Temp\brr\tmpZTF.log
C:\WINDOWS\system32\amorxyfg.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b02FdUe\b02FdUe1065.exe
C:\WINDOWS\system32\rdkimrmn.exe
C:\WINDOWS\system32\ruynflz.dll
C:\WINDOWS\system32\taqvlola.dll
C:\WINDOWS\system32\tjdlcdqh.dll
C:\WINDOWS\system32\vturpmj.dll
C:\WINDOWS\system32\Z11


((((((((((((((((((((((((( Files Created from 2007-07-06 to 2007-08-06 )))))))))))))))))))))))))))))))


2007-08-06 08:47 125,504 --a------ C:\WINDOWS\system32\mnjpfciu.dll
2007-08-05 20:36 228,960 --a------ C:\WINDOWS\system32\pmkjj.dll
2007-08-05 20:36 1,757,795 --ahs---- C:\WINDOWS\system32\jjkmp.bak1
2007-08-05 03:20 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-08-05 03:19 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-03 18:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-08-03 18:08 <DIR> d-------- C:\VundoFix Backups
2007-08-03 12:53 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-08-03 12:53 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-30 19:06 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\CyberLink
2007-07-24 21:13 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-07-24 21:13 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-07-24 21:13 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-07-24 21:13 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-07-24 21:13 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-07-24 21:13 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-07-24 21:13 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-07-24 21:12 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-07-24 21:12 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-07-24 21:12 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-07-24 21:12 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-07-24 21:12 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-07-24 21:12 345,088 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-07-24 21:12 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-07-24 21:12 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-07-24 21:12 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-07-24 21:12 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-07-24 21:12 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-07-24 21:12 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-07-24 21:12 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-07-24 21:12 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-07-22 10:03 <DIR> d-------- C:\Program Files\WinXMedia
2007-07-21 18:27 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\AdobeUM
2007-07-21 12:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 18:02 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-19 18:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-19 17:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-18 13:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-18 13:45 <DIR> d-------- C:\Program Files\msn gaming zone
2007-07-18 04:47 <DIR> d---s---- C:\DOCUME~1\ed\UserData
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-17 14:40 <DIR> d-------- C:\Temp
2007-07-10 17:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-07 11:54 <DIR> d-------- C:\Program Files\iPod
2007-07-07 11:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-07 11:49 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-07 11:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-25 01:13:13 -------- d-----w C:\Program Files\Windows NT
2007-07-18 16:25:53 -------- d-----w C:\Program Files\Common Files\Real
2007-07-07 15:54:50 -------- d-----w C:\Program Files\iTunes
2007-06-30 16:11:01 -------- d-----w C:\Program Files\Symantec
2007-06-30 16:10:50 -------- d-----w C:\Program Files\SymNetDrv
2007-06-30 16:10:22 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-16 14:07:59 -------- d-----w C:\Program Files\Apple Software Update
2007-06-10 18:44:35 1,290 ----a-w C:\WINDOWS\mozver.dat
2007-06-10 18:44:34 -------- d-----w C:\Program Files\DivX
2007-06-04 20:32:50 60 ----a-w C:\WINDOWS\system32\SYSDRV.DAT


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 17:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A5091247-8258-48A6-A99F-7EFED0332154}]
2007-08-05 20:36 228960 --a------ C:\WINDOWS\system32\pmkjj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-08-18 02:34 103592 --a------ C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
2007-08-06 11:05 69184 --a------ C:\WINDOWS\system32\vehtbibh.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 10:34 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2004-03-03 20:29 C:\WINDOWS\system32\nwiz.exe]
"nForce Tray Options"="sstray.exe" [2003-09-03 04:25 C:\WINDOWS\system32\sstray.exe]
"CHotkey"="zHotkey.exe" [2004-05-18 04:30 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 19:09 C:\WINDOWS\ShowWnd.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 05:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"NAV CfgWiz"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 21:24]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-12 01:18]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-06-30 12:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-03-03 20:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjj]
C:\WINDOWS\system32\pmkjj.dll --a------ 2007-08-05 20:36 228960 C:\WINDOWS\system32\pmkjj.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\ed\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

*Newly Created Service* - GTNDIS5

Contents of the 'Scheduled Tasks' folder
2007-08-04 10:49:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-08-04 00:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2007-06-30 16:05:28 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-06 11:02:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

C:\WINDOWS\system32\vehtbibh.dll

scan completed successfully
hidden files: 1

**************************************************************************

Completion time: 2007-08-06 11:07:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-06 11:06
C:\ComboFix2.txt ... 2007-08-05 19:34
C:\ComboFix3.txt ... 2007-07-21 12:51

--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:52:54 AM, on 8/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ed\Desktop\Fixin Stuff\abc.bat.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A5091247-8258-48A6-A99F-7EFED0332154} - C:\WINDOWS\system32\pmkjj.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1186159966046
O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 6047 bytes

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:57 AM

Posted 06 August 2007 - 01:46 PM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\mnjpfciu.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\vehtbibh.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A5091247-8258-48A6-A99F-7EFED0332154}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjj]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Let me know how your pc is running now.
Posted Image
Posted Image

#7 eddiedev

eddiedev
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 07 August 2007 - 03:02 PM

i havent gotten any since i just ran the last combo fix and hjt, but before i did, i was still getting IE popups, and the occasional firefox popup for those "registry cleaners" that make the webpage look like an error message.

"ed" - 2007-08-07 15:05:24 - ComboFix 07-07-17.8 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\ed\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\mnjpfciu.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\psuwpube.exe
C:\WINDOWS\system32\vehtbibh.dll


((((((((((((((((((((((((( Files Created from 2007-07-07 to 2007-08-07 )))))))))))))))))))))))))))))))


2007-08-07 08:47 125,504 --a------ C:\WINDOWS\system32\riaoutuq.dll
2007-08-07 08:44 69,184 --a------ C:\WINDOWS\system32\yqijdahj.dll
2007-08-07 08:37 1,764,127 --ahs---- C:\WINDOWS\system32\jjkmp.bak2
2007-08-05 03:20 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-08-05 03:19 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-03 18:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-08-03 18:08 <DIR> d-------- C:\VundoFix Backups
2007-08-03 12:53 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-08-03 12:53 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-30 19:06 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\CyberLink
2007-07-24 21:13 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-07-24 21:13 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-07-24 21:13 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-07-24 21:13 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-07-24 21:13 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-07-24 21:13 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-07-24 21:13 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-07-24 21:12 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-07-24 21:12 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-07-24 21:12 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-07-24 21:12 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-07-24 21:12 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-07-24 21:12 345,088 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-07-24 21:12 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-07-24 21:12 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-07-24 21:12 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-07-24 21:12 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-07-24 21:12 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-07-24 21:12 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-07-24 21:12 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-07-24 21:12 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-07-22 10:03 <DIR> d-------- C:\Program Files\WinXMedia
2007-07-21 18:27 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\AdobeUM
2007-07-21 12:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 18:02 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-19 18:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-19 17:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-18 13:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-18 13:45 <DIR> d-------- C:\Program Files\msn gaming zone
2007-07-18 04:47 <DIR> d---s---- C:\DOCUME~1\ed\UserData
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-17 14:40 <DIR> d-------- C:\Temp
2007-07-10 17:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-07 11:54 <DIR> d-------- C:\Program Files\iPod
2007-07-07 11:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-07 11:49 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-07 11:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-25 01:13:13 -------- d-----w C:\Program Files\Windows NT
2007-07-18 16:25:53 -------- d-----w C:\Program Files\Common Files\Real
2007-07-07 15:54:50 -------- d-----w C:\Program Files\iTunes
2007-06-30 16:11:01 -------- d-----w C:\Program Files\Symantec
2007-06-30 16:10:50 -------- d-----w C:\Program Files\SymNetDrv
2007-06-30 16:10:22 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-16 14:07:59 -------- d-----w C:\Program Files\Apple Software Update
2007-06-10 18:44:35 1,290 ----a-w C:\WINDOWS\mozver.dat
2007-06-10 18:44:34 -------- d-----w C:\Program Files\DivX
2007-06-04 20:32:50 60 ----a-w C:\WINDOWS\system32\SYSDRV.DAT


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 17:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-08-18 02:34 103592 --a------ C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 10:34 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2004-03-03 20:29 C:\WINDOWS\system32\nwiz.exe]
"nForce Tray Options"="sstray.exe" [2003-09-03 04:25 C:\WINDOWS\system32\sstray.exe]
"CHotkey"="zHotkey.exe" [2004-05-18 04:30 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 19:09 C:\WINDOWS\ShowWnd.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 05:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"NAV CfgWiz"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 21:24]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-12 01:18]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-06-30 12:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-03-03 20:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\ed\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

*Newly Created Service* - GTNDIS5

Contents of the 'Scheduled Tasks' folder
2007-08-04 10:49:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-08-04 00:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2007-06-30 16:05:28 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 15:16:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-07 15:19:03 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-07 15:18
C:\ComboFix2.txt ... 2007-08-06 11:07
C:\ComboFix3.txt ... 2007-08-05 19:34

--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:59:08 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ed\Desktop\Fixin Stuff\abc.bat.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1186159966046
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 5804 bytes

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:57 AM

Posted 07 August 2007 - 03:32 PM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\riaoutuq.dll
C:\WINDOWS\system32\yqijdahj.dll
C:\WINDOWS\system32\jjkmp.bak2
C:\DOCUME~1\ed\LOCALS~1\Temp\MBDownloader_876919.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Let me know how your pc is running now.
Posted Image
Posted Image

#9 eddiedev

eddiedev
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 09 August 2007 - 08:11 AM

it was running a lot better last night. i think i only got one of the "registry cleaner" pop ups, and one IE pop up.

"ed" - 2007-08-09 8:46:28 - ComboFix 07-07-17.8 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\ed\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\riaoutuq.dll
C:\WINDOWS\system32\yqijdahj.dll


((((((((((((((((((((((((( Files Created from 2007-07-09 to 2007-08-09 )))))))))))))))))))))))))))))))


2007-08-05 03:20 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-08-05 03:19 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-03 18:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-08-03 18:08 <DIR> d-------- C:\VundoFix Backups
2007-08-03 12:53 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-08-03 12:53 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-30 19:06 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\CyberLink
2007-07-24 21:13 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-07-24 21:13 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-07-24 21:13 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-07-24 21:13 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-07-24 21:13 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-07-24 21:13 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-07-24 21:13 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-07-24 21:12 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-07-24 21:12 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-07-24 21:12 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-07-24 21:12 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-07-24 21:12 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-07-24 21:12 345,088 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-07-24 21:12 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-07-24 21:12 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-07-24 21:12 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-07-24 21:12 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-07-24 21:12 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-07-24 21:12 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-07-24 21:12 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-07-24 21:12 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-07-22 10:03 <DIR> d-------- C:\Program Files\WinXMedia
2007-07-21 18:27 <DIR> d-------- C:\DOCUME~1\ed\APPLIC~1\AdobeUM
2007-07-21 12:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 18:02 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-19 18:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-19 17:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-18 13:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-18 13:45 <DIR> d-------- C:\Program Files\msn gaming zone
2007-07-18 04:47 <DIR> d---s---- C:\DOCUME~1\ed\UserData
2007-07-17 14:40 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-17 14:40 <DIR> d-------- C:\Temp
2007-07-10 17:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-25 01:13:13 -------- d-----w C:\Program Files\Windows NT
2007-07-18 16:25:53 -------- d-----w C:\Program Files\Common Files\Real
2007-07-07 15:54:50 -------- d-----w C:\Program Files\iTunes
2007-07-07 15:54:26 -------- d-----w C:\Program Files\iPod
2007-07-07 15:49:41 -------- d-----w C:\Program Files\Common Files\Apple
2007-06-30 16:11:01 -------- d-----w C:\Program Files\Symantec
2007-06-30 16:10:50 -------- d-----w C:\Program Files\SymNetDrv
2007-06-30 16:10:22 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-16 14:07:59 -------- d-----w C:\Program Files\Apple Software Update
2007-06-10 18:44:35 1,290 ----a-w C:\WINDOWS\mozver.dat
2007-06-10 18:44:34 -------- d-----w C:\Program Files\DivX
2007-06-04 20:32:50 60 ----a-w C:\WINDOWS\system32\SYSDRV.DAT


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 17:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-08-18 02:34 103592 --a------ C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 10:34 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2004-03-03 20:29 C:\WINDOWS\system32\nwiz.exe]
"nForce Tray Options"="sstray.exe" [2003-09-03 04:25 C:\WINDOWS\system32\sstray.exe]
"CHotkey"="zHotkey.exe" [2004-05-18 04:30 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 19:09 C:\WINDOWS\ShowWnd.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 05:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"NAV CfgWiz"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 21:24]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-12 01:18]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-06-30 12:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

*Newly Created Service* - GTNDIS5

Contents of the 'Scheduled Tasks' folder
2007-08-04 10:49:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-08-04 00:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2007-06-30 16:05:28 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-09 08:51:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

C:\WINDOWS\system32\cmd.exe [2704] 0x83906270


scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-09 8:51:54
C:\ComboFix-quarantined-files.txt ... 2007-08-09 08:51
C:\ComboFix2.txt ... 2007-08-07 15:19
C:\ComboFix3.txt ... 2007-08-06 11:07

--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:11:06 AM, on 8/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\ed\Desktop\Fixin Stuff\abc.bat.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1186159966046
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 5719 bytes

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:57 AM

Posted 09 August 2007 - 10:06 AM

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
----------------------------------------------------------------
Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.

Now run AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

[1.]Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

[2.]Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done,then restart your pc.
----------------------------------------------------------------
Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.

Restart your pc.
Post the AVG Anti-Spyware report,the BitDefender log,and a new Hijackthis log.
Let me know how your pc is running now.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users