Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winanti Virus Pop-ups Along With More Unwanted Pop-ups, Malware?


  • This topic is locked This topic is locked
9 replies to this topic

#1 n827

n827

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:16 AM

Posted 10 August 2007 - 12:29 AM

I have Windows XP
ANY help and/or response will be greatly appreciated :thumbsup:
-N827


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:10 PM, on 8/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\qwerty12.exe
C:\Program Files\Airlink101\AWLC5025\WLService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Airlink101\AWLC5025\AWLC5025.exe
C:\WINDOWS\System32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe
C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\tnxdxgiA.exe
C:\DOCUME~1\NORMAD~1\LOCALS~1\Temp\MBDownloader_876919.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\WinPop\winpop.exe
C:\WINDOWS\system32\cidaemon.exe
c:\program files\common files\aol\1178925597\ee\aexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HiJackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common

Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program

Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program

Files\Webshots\WSToolbar4IE.dll
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [HP Metrics] C:\Program Files\HP\Personal Printing Solutions Product

Research\HP Product Research.exe a
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [tnxdxgiA] C:\WINDOWS\tnxdxgiA.exe
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\NORMAD~1\LOCALS~1\Temp\MBDownloader_876919.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\fgqnasib.dll",forkonce
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe

61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager]

C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\TISKY009.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless

LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM

Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program

Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -

http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -

http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - AppInit_DLLs: ?A c:\windows\system32\ldcore.dll

C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. -

C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - - C:\WINDOWS\System32\qwerty12.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop

Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -

C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MIMO XR TM Cardbus Adapter WLService (MIMO XR TM Cardbus WLService) - Unknown

owner - C:\Program Files\Airlink101\AWLC5025\WLService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation -

C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton

AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file

missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program

Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. -

C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mvzhwgx.exe (file

missing)

--
End of file - 8138 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 10 August 2007 - 07:28 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum n827 :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

The current formatting of your log makes it difficult to read/evaluate.
Open 'Notepad',click on 'Format' at the top,then uncheck 'Word Wrap' if it's checked.
--------------------------------------------------
Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".
This will change from what we know in 2006 read this article:
http://www.clickz.com/news/article.php/3561546

You are well advised to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:

Viewpoint
Viewpoint Manager
Viewpoint Media Player


Then restart your pc.
--------------------------------------------------
Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.
-------------------------------------------------
Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
-------------------------------------------------
Download SmitfraudFix (by S!Ri), to your desktop.
Double click on Smitfraudfix.cmd
Select option 1 Search, by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy and paste the content of that report into your next reply.

*IMPORTANT*
Do NOT run any other options until you are asked to do so!

Also post a new Hijackthis log.
Posted Image
Posted Image

#3 n827

n827
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:16 AM

Posted 10 August 2007 - 10:19 PM

SDFix: Version 1.97

Run by Norma on Fri 08/10/2007 at 18:43 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
DomainService
Windows Overlay Components

ImagePath:
C:\WINDOWS\System32\qwerty12.exe /service
C:\WINDOWS\mvzhwgx.exe

DomainService - Deleted
Windows Overlay Components - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value


Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun4.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun6.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun3.exe - Deleted
C:\WINDOWS\Temp\stdrun1.exe - Deleted
C:\WINDOWS\Temp\stdrun3.exe - Deleted
C:\DOCUME~1\NORMAD~1\LOCALS~1\Temp\nseE1.tmp\nsProcess.dll - Deleted
C:\DOCUME~1\NORMAD~1\LOCALS~1\Temp\nsiDC.tmp\nsProcess.dll - Deleted
C:\Program Files\InetGet2\YazzleBundle-1122.exe - Deleted
C:\Program Files\poolsv\k11u72.exe - Deleted
C:\Program Files\poolsv\svhost.exe - Deleted
C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe - Deleted
C:\Program Files\poolsv\wr-1-0000077.exe - Deleted
C:\Program Files\poolsv\YazzleBundle-1549.exe - Deleted
C:\Documents and Settings\Norma Dinh\Start Menu\Programs\Startup\TA_Start.lnk - Deleted
C:\Documents and Settings\Norma Dinh\Application Data\Install.dat - Deleted
C:\DOCUME~1\NORMAD~1\LOCALS~1\Temp\abc123.pid - Deleted
C:\sstray.exe - Deleted
C:\WINDOWS\b104.exe - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\csrss.exe - Deleted
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe - Deleted
C:\WINDOWS\poolsv.exe - Deleted
C:\WINDOWS\retadpu77.exe - Deleted
C:\WINDOWS\svhost.exe - Deleted
C:\WINDOWS\system32\ldcore.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\n.ini - Deleted
C:\WINDOWS\system32\qwerty12.exe - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\wr.txt - Deleted


Folder C:\Program Files\InetGet2 - Removed
Folder C:\Program Files\poolsv - Removed
Folder C:\WINDOWS\system32\b02FdUe - Removed
Folder C:\WINDOWS\system32\b06FdUe - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\DOCUME~1\\NORMAD~1\\LOCALS~1\\Temp\\bl4ck.com"="C:\\DOCUME~1\\NORMAD~1\\LOCALS~1\\Temp\\bl4ck.com:*:ENABLED:0"
"C:\\WINDOWS\\System32\\qwerty12.exe"="C:\\WINDOWS\\System32\\qwe"

Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Program Files\Common Files\aolshare\shell\us\shellext.dll
C:\Program Files\America Online 9.0a\aolphx.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\America Online 9.0a\RBM.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
C:\Program Files\Common Files\s?mbols\csrss.exe
C:\Program Files\Picasa2\setup.exe
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP734\A0084966.exe
C:\WINDOWS\tnxdxgiA.exe
C:\WINDOWS\S?mantec\wucrtupd.exe
C:\I386\KGyGaAvL.sys
C:\WINDOWS\SYSTEM32\86E5F0384D.sys
C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp
C:\WINDOWS\SoftwareDistribution\Download\deb995e7b7d2953ec6904bd5047bd45f\BIT19.tmp

Finished



ComboFix 07-08-11 - "Norma" 2007-08-10 19:36:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.197 [GMT -7:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ProductCode
C:\DOCUME~1\NORMAD~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\NORMAD~1\APPLIC~1.\winantispyware 2007 free
C:\DOCUME~1\NORMAD~1\APPLIC~1.\winantispyware 2007 free\DownloadUWAS7.url
C:\DOCUME~1\NORMAD~1\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\NORMAD~1\APPLIC~1\Sskcwrd.dll
C:\DOCUME~1\NORMAD~1\APPLIC~1\Sskknwrd.dll
C:\DOCUME~1\NORMAD~1\APPLIC~1\WinAntiSpyware 2007 Free\DownloadUWAS7.url
C:\DOCUME~1\NORMAD~1\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\Program Files\cmsystem
C:\Program Files\cmsystem\hf.txt
C:\Program Files\cmsystem\rf.txt
C:\Program Files\cmsystem\sf.txt
C:\Program Files\cmsystem\Uninstall.exe
C:\Program Files\Common Files\{1CD31~1
C:\Program Files\Common Files\{1CD31~1\services.dll
C:\Program Files\Common Files\{1CD31~1\Update.exe
C:\Program Files\Common Files\{3CD31~1
C:\Program Files\Common Files\{3CD31~1\MyToolBar.dll
C:\Program Files\Common Files\{3CD31~1\Uninst.exe
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\smbols~1\csrss.exe
C:\Program Files\Common Files\smbols~1\s?mbols\
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\is-65J0M.tmp
C:\Program Files\Common Files\WinAntiSpyware 2007\is-65J0M.tmp
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\winpop
C:\Program Files\winpop\UnInstall.exe
C:\Program Files\winpop\winpop.exe
C:\Program Files\ymante~1
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\WINDOWS\offun.exe
C:\WINDOWS\pf78.exe
C:\WINDOWS\smante~1
C:\WINDOWS\smante~1\S?mantec\
C:\WINDOWS\smante~1\wucrtupd.exe
C:\WINDOWS\system32\b10FdUe
C:\WINDOWS\system32\bbaypuhy.exe
C:\WINDOWS\SYSTEM32\bisanqgf.ini
C:\WINDOWS\system32\bltyvkyc.exe
C:\WINDOWS\system32\cbxurss.dll
C:\WINDOWS\system32\ddccayx.dll
C:\WINDOWS\system32\ddcyvvs.dll
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\emnnjerx.exe
C:\WINDOWS\system32\fgqnasib.dll
C:\WINDOWS\SYSTEM32\gdnxaktp.ini
C:\WINDOWS\system32\iiffgdb.dll
C:\WINDOWS\system32\ilsmlmop.exe
C:\WINDOWS\system32\ogvxaflq.dll
C:\WINDOWS\system32\pmnnopn.dll
C:\WINDOWS\system32\ptkaxndg.dll
C:\WINDOWS\system32\purvmypf.exe
C:\WINDOWS\system32\puxbevif.exe
C:\WINDOWS\system32\rhkockvr.exe
C:\WINDOWS\system32\rpqmjqkl.dll
C:\WINDOWS\SYSTEM32\rtsru.bak1
C:\WINDOWS\SYSTEM32\rtsru.bak2
C:\WINDOWS\SYSTEM32\rtsru.ini
C:\WINDOWS\SYSTEM32\rtsru.tmp
C:\WINDOWS\system32\udexjhpa.exe
C:\WINDOWS\system32\urstr.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\win
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\kmhp83122.exe
C:\WINDOWS\system32\X11
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X3\wr725.exe
C:\WINDOWS\system32\X7
C:\WINDOWS\system32\xqhaqknk.exe
C:\WINDOWS\tnxdxgiA.exe
C:\WINDOWS\WebAssist.dll
C:\WINDOWS\xhelper.dll
C:\WINDOWS\xmlhelper.dll
C:\WINDOWS\xmlhelper2.dll
C:\WINDOWS\xmlhelper4.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FOPN
-------\ApiMon
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-10 19:20 75,328 --a------ C:\WINDOWS\SYSTEM32\sdshodvt.exe
2007-08-10 18:40 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-09 22:01 <DIR> d-------- C:\Program Files\backups
2007-08-09 21:38 401,720 --a------ C:\Program Files\HiJackThis.exe
2007-08-09 18:41 75,328 --a------ C:\WINDOWS\SYSTEM32\sxgdeefm.exe
2007-08-08 18:26 75,328 --a------ C:\WINDOWS\SYSTEM32\mysyydrq.exe
2007-08-01 09:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-01 09:17 1,152 --a------ C:\WINDOWS\SYSTEM32\windrv.sys
2007-07-31 22:41 12,413,440 --a------ C:\Program Files\avgas-setup-7.5.1.43.exe
2007-07-31 22:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-31 21:29 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-07-30 22:31 7,649,240 --a------ C:\Program Files\Windows-KB890830-V1.31.exe
2007-07-30 20:18 <DIR> d-------- C:\Temp
2007-07-25 20:33 94,208 --a------ C:\WINDOWS\SYSTEM32\GTW32N50.dll
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT2661.bin
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rt2561s.bin
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT2561.bin
2007-07-25 20:33 40,960 --a------ C:\WINDOWS\SYSTEM32\AWLC5025.dll
2007-07-25 20:33 36,864 --a------ C:\WINDOWS\SYSTEM32\ss.dll
2007-07-25 20:33 319,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT61.sys
2007-07-25 20:33 19,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ss.sys
2007-07-25 20:33 19,915 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys
2007-07-25 20:33 15,872 --a------ C:\WINDOWS\SYSTEM32\GTNDIS5.sys
2007-07-25 20:33 <DIR> d-------- C:\Program Files\Airlink101
2007-07-23 23:06 1,156 --a------ C:\WINDOWS\mozver.dat


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-09 22:10 8139 --a------ C:\Program Files\hijackthis.log
2007-08-09 20:22 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-01 09:55 --------- d-------- C:\Program Files\QuickTime
2007-08-01 09:37 --------- d-------- C:\Program Files\Google
2007-07-31 22:51 --------- d-------- C:\Program Files\TBONAS
2007-07-25 20:33 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-15 19:50 --------- d-------- C:\Program Files\Picasa2
2007-06-26 20:25 87990 --a------ C:\Program Files\GoogleCalendar.gg
2007-06-26 20:25 1827640 --a------ C:\Program Files\GoogleDesktopSetup.exe
2007-06-18 20:59 6010424 --a------ C:\Program Files\Firefox Setup 2.0.0.4.exe
2007-02-20 16:30 359112 --a------ C:\Program Files\LimeWireWin.exe
2007-01-15 17:18 218871288 --a------ C:\Program Files\PaintShopPro1111.exe
2007-01-10 11:18 218306392 --a------ C:\Program Files\MOA7024Express.exe
2006-12-28 23:57 36808256 --a------ C:\Program Files\iTunesSetup.exe
2006-12-26 13:47 3346320 --a------ C:\Program Files\wbsamp5.exe
2006-12-15 01:18 14879120 --a------ C:\Program Files\GoogleEarthWin.exe
2006-11-28 15:21 1581768 --a------ C:\Program Files\googletalk-setup.exe
2006-04-22 18:54 20087 --a------ C:\Program Files\applesauce_aimcolors.zip
2006-03-27 10:57 532616 --a------ C:\Program Files\ImageResizerPowertoySetup.exe
2005-11-20 17:02 610 --a------ C:\Program Files\AIM.lnk
2005-11-16 12:20 2855080 --a------ C:\Program Files\aawsepersonal.exe
2005-11-16 12:08 546217 --a------ C:\Program Files\LavaSoftUsa.zip
2005-09-05 14:33 2600700 --a------ C:\Program Files\Word.zip
2005-09-04 01:49 353888 --a------ C:\Program Files\LimeWire.exe
2005-04-07 21:48 4466776 --a------ C:\Program Files\Install_AIM.exe
2005-02-23 21:40 7415936 --a------ C:\Program Files\PrevxProDownload.exe
2005-02-21 19:30 273248 --a------ C:\Program Files\Windows-KB890830-V1.1-ENU.exe
2005-02-21 19:07 161416 --a------ C:\Program Files\FxMydoom.exe
2005-02-19 18:53 11045792 --a------ C:\Program Files\kav5.0.149.4_personalen_trial1m.exe
2005-02-18 12:34 4236160 --a------ C:\Program Files\sdinstall.exe
2004-12-11 21:41 10135688 --a------ C:\Program Files\MPSetupXP.exe
2004-12-07 23:08 2206405 --a------ C:\Program Files\Webshots.exe
2004-09-23 12:02 724 --a------ C:\Program Files\QuickTime Player.lnk
2004-09-23 12:02 1614 --a------ C:\Program Files\iTunes.lnk
2004-09-05 16:03 1740 --a------ C:\Program Files\Adobe Reader 6.0.lnk
2004-09-05 16:01 9143000 --a------ C:\Program Files\AdbeRdr60_enu.exe
2004-08-30 00:34 823296 --a------ C:\Program Files\Winmx353.exe
2007-02-07 00:01:52 88 --sh--r C:\WINDOWS\SYSTEM32\86E5F0384D.sys
2007-02-07 00:02:38 3,714 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00F1D395-4744-40f0-A611-980F61AE2C59}]
C:\WINDOWS\dsr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4487598C-2EC7-43A2-870E-6D8D720FDD9F}]
C:\WINDOWS\System32\pkshhumz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C8EE6669-0D02-4FA7-8B4B-CDE63D57B6B2}]
C:\Program Files\NetMeeting\qucohapuc83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5DE8ADB-4A69-4e56-96AB-823171C8E9D8}]
C:\Program Files\TBONAS\TBONlchr.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FD44536-9DF0-4034-939F-5BD4D98E3187}"= C:\Program Files\TBONAS\TBONlchr.dll [ ]

[HKEY_CLASSES_ROOT\CLSID\{7FD44536-9DF0-4034-939F-5BD4D98E3187}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]
[HKEY_CLASSES_ROOT\TypeLib\{4EF67630-DD6C-4e66-B175-60BCCD1CA89B}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dinst"="C:\WINDOWS\dinst.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"HP Metrics"="C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe" [2004-01-16 13:11]
"HostManager"="C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe" [2006-04-13 13:36]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 16:15]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" []
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 14:17]

C:\Documents and Settings\Norma Dinh\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 07:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-12-07 23:08:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 07:00:00]
IEEE 802.11g USB Wireless LAN Utility.lnk - C:\Program Files\Wireless LAN\WlanUtil.exe [2006-02-19 23:02:42]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Norma Dinh^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Norma Dinh\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DadApp]
C:\Program Files\Dell\AccessDirect\dadapp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

R2 MIMO XR TM Cardbus WLService;MIMO XR TM Cardbus Adapter WLService;C:\Program Files\Airlink101\AWLC5025\WLService.exe
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\System32\DRIVERS\BCMSM.sys
R3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\System32\DRIVERS\ss.sys
R3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\System32\ZDPNDIS5.SYS
S2 SvcProc;System Startup Service ;C:\WINDOWS\svcproc.exe
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\System32\Drivers\Icam3.sys
S3 TNET1130;802.11 WLAN;C:\WINDOWS\System32\DRIVERS\tnet1130.sys
S3 ZD1211U(WLAN);IEEE 802.11g USB Wireless LAN Driver(WLAN);C:\WINDOWS\System32\DRIVERS\zd1211u.sys


Contents of the 'Scheduled Tasks' folder
2007-08-01 18:16:33 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-07-24 07:00:00 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-06 16:00:00 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-07 17:00:00 C:\WINDOWS\Tasks\At11.job
2007-07-22 18:00:33 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-22 19:00:30 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-08 20:01:55 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-08 21:00:35 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-22 22:00:31 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-23 23:00:31 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-24 00:00:36 C:\WINDOWS\Tasks\At18.job
2007-08-10 01:00:00 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-07-23 08:00:30 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-10 02:00:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-10 03:00:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-10 04:00:00 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-10 05:00:00 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-10 06:00:00 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-05-19 09:00:54 C:\WINDOWS\Tasks\At3.job
2007-08-05 10:00:01 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-04 11:00:03 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-04 12:00:01 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-06 13:00:00 C:\WINDOWS\Tasks\At7.job
2007-08-05 14:00:00 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-08-05 15:00:00 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\System32\MtQt2w80.exe
2007-06-30 03:00:11 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
2007-08-10 15:22:34 C:\WINDOWS\Tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 20:00:45
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-10 20:03:40 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-10 20:03

--- E O F ---






SmitFraudFix v2.210

Scan done at 20:13:15.22, Fri 08/10/2007
Run from C:\Documents and Settings\Norma\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Airlink101\AWLC5025\WLService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Airlink101\AWLC5025\AWLC5025.exe
C:\WINDOWS\System32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe
C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\WINDOWS\System32\wuauclt.exe
c:\program files\common files\aol\1178925597\ee\aexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\CSCRIPT.EXE

hosts


C:\


C:\WINDOWS

C:\WINDOWS\Tasks\At?.job FOUND !
C:\WINDOWS\Tasks\At??.job FOUND !

C:\WINDOWS\system


C:\WINDOWS\Web


C:\WINDOWS\system32


C:\Documents and Settings\Norma Dinh


C:\Documents and Settings\Norma Dinh\Application Data


Start Menu


C:\DOCUME~1\NORMAD~1\FAVORI~1


Desktop


C:\Program Files


Corrupted keys


Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"LoadAppInit_DLLs"=dword:00000001


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Rustock



DNS

Description: Airlink101 MIMO XR Cardbus Adapter - Packet Scheduler Miniport
DNS Server Search Order: 205.171.2.65
DNS Server Search Order: 205.171.3.65

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS3\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65


Scanning for wininet.dll infection


End

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 11 August 2007 - 03:51 AM

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Double click on Smitfraudfix.cmd
Select #2 and hit Enter to delete the infected files.
You will be prompted: 'Do you want to clean the registry?' answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): 'Replace infected file ?' answer Y (yes) and hit Enter to restore a clean file.
A reboot may be needed to finish the cleaning process.
The report can be found at the root of the system drive, usually at C:\rapport.txt

Post the smitfraudfix report into your next reply.
-----------------------------------------------------------------------------------
Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\SYSTEM32\sdshodvt.exe
C:\WINDOWS\SYSTEM32\sxgdeefm.exe
C:\WINDOWS\SYSTEM32\mysyydrq.exe

Folder::
C:\Program Files\TBONAS

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00F1D395-4744-40f0-A611-980F61AE2C59}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4487598C-2EC7-43A2-870E-6D8D720FDD9F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C8EE6669-0D02-4FA7-8B4B-CDE63D57B6B2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5DE8ADB-4A69-4e56-96AB-823171C8E9D8}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FD44536-9DF0-4034-939F-5BD4D98E3187}"=-
[-HKEY_CLASSES_ROOT\CLSID\{7FD44536-9DF0-4034-939F-5BD4D98E3187}]
[-HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher.1]
[-HKEY_CLASSES_ROOT\TypeLib\{4EF67630-DD6C-4e66-B175-60BCCD1CA89B}]
[HKEY_CLASSES_ROOT\MyNewsBarLauncher.IE5BarLauncher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dinst"=-

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#5 n827

n827
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:16 AM

Posted 11 August 2007 - 03:18 PM

SmitFraudFix v2.210

Scan done at 12:31:40.75, Sat 08/11/2007
Run from C:\Documents and Settings\Norma\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

Killing process


hosts

127.0.0.1 localhost

Generic Renos Fix

GenericRenosFix by S!Ri


Deleting infected files

C:\WINDOWS\Tasks\At?.job Deleted
C:\WINDOWS\Tasks\At??.job Deleted

DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS3\Services\Tcpip\..\{0DB32415-A1BF-4077-9FF7-C9372AC98690}: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=205.171.2.65 205.171.3.65


Deleting Temp Files


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Registry Cleaning

Registry Cleaning done.

SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


End



ComboFix 07-08-11 - "Norma" 2007-08-11 13:08:05.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.273 [GMT -7:00]
Command switches used :: C:\Documents and Settings\Norma\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\SYSTEM32\sdshodvt.exe
C:\WINDOWS\SYSTEM32\sxgdeefm.exe
C:\WINDOWS\SYSTEM32\mysyydrq.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\TBONAS
C:\Program Files\TBONAS\center_wnd.htm
C:\Program Files\TBONAS\grb12.rtk
C:\WINDOWS\SYSTEM32\mysyydrq.exe
C:\WINDOWS\SYSTEM32\sdshodvt.exe
C:\WINDOWS\SYSTEM32\sxgdeefm.exe


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-10 20:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-08-10 20:13 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-08-10 20:13 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-08-10 20:13 2,004 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-10 18:40 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-09 22:01 <DIR> d-------- C:\Program Files\backups
2007-08-09 21:38 401,720 --a------ C:\Program Files\HiJackThis.exe
2007-08-01 09:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-01 09:17 1,152 --a------ C:\WINDOWS\SYSTEM32\windrv.sys
2007-07-31 22:41 12,413,440 --a------ C:\Program Files\avgas-setup-7.5.1.43.exe
2007-07-31 22:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-31 21:29 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-07-30 22:31 7,649,240 --a------ C:\Program Files\Windows-KB890830-V1.31.exe
2007-07-30 20:18 <DIR> d-------- C:\Temp
2007-07-25 20:33 94,208 --a------ C:\WINDOWS\SYSTEM32\GTW32N50.dll
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT2661.bin
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rt2561s.bin
2007-07-25 20:33 8,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT2561.bin
2007-07-25 20:33 40,960 --a------ C:\WINDOWS\SYSTEM32\AWLC5025.dll
2007-07-25 20:33 36,864 --a------ C:\WINDOWS\SYSTEM32\ss.dll
2007-07-25 20:33 319,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\RT61.sys
2007-07-25 20:33 19,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ss.sys
2007-07-25 20:33 19,915 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys
2007-07-25 20:33 15,872 --a------ C:\WINDOWS\SYSTEM32\GTNDIS5.sys
2007-07-25 20:33 <DIR> d-------- C:\Program Files\Airlink101
2007-07-23 23:06 1,156 --a------ C:\WINDOWS\mozver.dat


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-09 22:10 8139 --a------ C:\Program Files\hijackthis.log
2007-08-09 20:22 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-01 09:55 --------- d-------- C:\Program Files\QuickTime
2007-08-01 09:37 --------- d-------- C:\Program Files\Google
2007-07-25 20:33 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-15 19:50 --------- d-------- C:\Program Files\Picasa2
2007-06-26 20:25 87990 --a------ C:\Program Files\GoogleCalendar.gg
2007-06-26 20:25 1827640 --a------ C:\Program Files\GoogleDesktopSetup.exe
2007-06-18 20:59 6010424 --a------ C:\Program Files\Firefox Setup 2.0.0.4.exe
2007-02-20 16:30 359112 --a------ C:\Program Files\LimeWireWin.exe
2007-01-15 17:18 218871288 --a------ C:\Program Files\PaintShopPro1111.exe
2007-01-10 11:18 218306392 --a------ C:\Program Files\MOA7024Express.exe
2006-12-28 23:57 36808256 --a------ C:\Program Files\iTunesSetup.exe
2006-12-26 13:47 3346320 --a------ C:\Program Files\wbsamp5.exe
2006-12-15 01:18 14879120 --a------ C:\Program Files\GoogleEarthWin.exe
2006-11-28 15:21 1581768 --a------ C:\Program Files\googletalk-setup.exe
2006-04-22 18:54 20087 --a------ C:\Program Files\applesauce_aimcolors.zip
2006-03-27 10:57 532616 --a------ C:\Program Files\ImageResizerPowertoySetup.exe
2005-11-20 17:02 610 --a------ C:\Program Files\AIM.lnk
2005-11-16 12:20 2855080 --a------ C:\Program Files\aawsepersonal.exe
2005-11-16 12:08 546217 --a------ C:\Program Files\LavaSoftUsa.zip
2005-09-05 14:33 2600700 --a------ C:\Program Files\Word.zip
2005-09-04 01:49 353888 --a------ C:\Program Files\LimeWire.exe
2005-04-07 21:48 4466776 --a------ C:\Program Files\Install_AIM.exe
2005-02-23 21:40 7415936 --a------ C:\Program Files\PrevxProDownload.exe
2005-02-21 19:30 273248 --a------ C:\Program Files\Windows-KB890830-V1.1-ENU.exe
2005-02-21 19:07 161416 --a------ C:\Program Files\FxMydoom.exe
2005-02-19 18:53 11045792 --a------ C:\Program Files\kav5.0.149.4_personalen_trial1m.exe
2005-02-18 12:34 4236160 --a------ C:\Program Files\sdinstall.exe
2004-12-11 21:41 10135688 --a------ C:\Program Files\MPSetupXP.exe
2004-12-07 23:08 2206405 --a------ C:\Program Files\Webshots.exe
2004-09-23 12:02 724 --a------ C:\Program Files\QuickTime Player.lnk
2004-09-23 12:02 1614 --a------ C:\Program Files\iTunes.lnk
2004-09-05 16:03 1740 --a------ C:\Program Files\Adobe Reader 6.0.lnk
2004-09-05 16:01 9143000 --a------ C:\Program Files\AdbeRdr60_enu.exe
2004-08-30 00:34 823296 --a------ C:\Program Files\Winmx353.exe
2007-02-07 00:01:52 88 --sh--r C:\WINDOWS\SYSTEM32\86E5F0384D.sys
2007-02-07 00:02:38 3,714 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"HP Metrics"="C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe" [2004-01-16 13:11]
"HostManager"="C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe" [2006-04-13 13:36]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 16:15]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" []
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 14:17]

C:\Documents and Settings\Norma\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 07:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-12-07 23:08:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 07:00:00]
IEEE 802.11g USB Wireless LAN Utility.lnk - C:\Program Files\Wireless LAN\WlanUtil.exe [2006-02-19 23:02:42]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Norma Dinh^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Norma Dinh\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DadApp]
C:\Program Files\Dell\AccessDirect\dadapp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

R2 MIMO XR TM Cardbus WLService;MIMO XR TM Cardbus Adapter WLService;C:\Program Files\Airlink101\AWLC5025\WLService.exe
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\System32\DRIVERS\BCMSM.sys
R3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\System32\DRIVERS\ss.sys
R3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\System32\ZDPNDIS5.SYS
S2 SvcProc;System Startup Service ;C:\WINDOWS\svcproc.exe
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\System32\Drivers\Icam3.sys
S3 TNET1130;802.11 WLAN;C:\WINDOWS\System32\DRIVERS\tnet1130.sys
S3 ZD1211U(WLAN);IEEE 802.11g USB Wireless LAN Driver(WLAN);C:\WINDOWS\System32\DRIVERS\zd1211u.sys


Contents of the 'Scheduled Tasks' folder
2007-08-01 18:16:33 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-06-30 03:00:11 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
2007-08-11 19:22:25 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 13:10:34
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-11 13:11:35
C:\ComboFix-quarantined-files.txt ... 2007-08-11 13:11
C:\ComboFix2.txt ... 2007-08-10 20:03

--- E O F ---





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:14:13 PM, on 8/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe
C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Airlink101\AWLC5025\WLService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Airlink101\AWLC5025\AWLC5025.exe
C:\WINDOWS\System32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\EXPLORER.EXE
C:\Documents and Settings\Norma\Desktop\HiJackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [HP Metrics] C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe a
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MIMO XR TM Cardbus Adapter WLService (MIMO XR TM Cardbus WLService) - Unknown owner - C:\Program Files\Airlink101\AWLC5025\WLService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 7225 bytes




Just wanted to say thank you for your quick responses, I really appreciate it! What ever you have requested me to do thus far the pop-ups are gone. Success! (so far) :thumbsup:
-Norma


#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 11 August 2007 - 03:46 PM

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

------------------------------------------

Copy and paste the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.bat to your desktop.
Then double click on the fix.bat file on your desktopPosted Image
You'll see a black screen flash,thats normal.

@echo off
sc stop SvcProc
sc delete SvcProc

Restart your pc.

------------------------------------------

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#7 n827

n827
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:16 AM

Posted 12 August 2007 - 09:15 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/12/2007 at 07:03 PM

Application Version : 3.9.1008

Core Rules Database Version : 3284
Trace Rules Database Version: 1295

Scan type : Complete Scan
Total Scan Time : 02:07:17

Memory items scanned : 407
Memory threats detected : 0
Registry items scanned : 5624
Registry threats detected : 11
File items scanned : 30944
File threats detected : 163

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\PSHWR.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\pshower
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\pshower#Path

Adware.Tracking Cookie
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ads.addynamix[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@statse.webtrendslive[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.burstnet[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@traffic-tracker[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@247realmedia[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adrevolver[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@track.bestbuy[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@winantivirus[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adbrite[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[7].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@msnportal.112.2o7[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ads.adbrite[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.adnetinteractive[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@toplist[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@findwhat[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@44153975[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@atdmt[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@stats[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adserving.cpxinteractive[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@amaena[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@heavycom.122.2o7[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.iconadserver[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@hitbox[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.epilot[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.interclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@bestoffersnetworks[6].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ehg-foxsports.hitbox[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@risk[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adopt.specificclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@realmedia[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@doubleclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adsrevenue[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@3.adbrite[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@tribalfusion[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@tacoda[3].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@exitexchange[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@azjmp[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.creafi[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ehg-myspaceinc.hitbox[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.free-sex-sexy-gallery[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@fastclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.winantispyware[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@redorbit[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@drivecleaner[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@stats.drivecleaner[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@reduxads.valuead[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.yieldmanager[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@perf.overture[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@tradedoubler[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ads.pointroll[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@bs.serving-sys[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@zedo[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@incisivemedia.112.2o7[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@media.top-banners[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@anad.tacoda[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@mediaplex[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adserver[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[7].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@specificclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@server.iad.liveperson[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.amaena[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@rotator.adjuggler[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@revenuesense[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@citi.bridgetrack[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@h.starware[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@overture[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@winantispyware[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@revsci[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@localsrv[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.globalinteractive[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@sales.liveperson[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.directanetworks[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@burstnet[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@questionmarket[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@publishers.clickbooth[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adtech[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@try.starware[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adopt.euroclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@linksynergy[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@advertising[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@cgi-bin[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@casalemedia[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad.abum[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ad[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@serving-sys[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@bluestreak[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@4.adbrite[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@cliks[5].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@stats1.reliablestats[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@recipe[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@adrevolver[3].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@cpvfeed[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@ads.k8l[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@trafficmp[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.xctrk[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@goclick[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@1070870746[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@tremor.adbureau[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@2o7[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@www.burstbeacon[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@clickz[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@riskwaters[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@hitstats[1].txt
C:\Documents and Settings\Guest\Cookies\guest@btg.btgrab[2].txt
C:\Documents and Settings\Guest\Cookies\guest@offeroptimizer[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[3].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[4].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@btg.btgrab[6].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@casalemedia[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[1].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[2].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[4].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[5].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@offeroptimizer[6].txt
C:\Documents and Settings\Norma Dinh\Cookies\norma dinh@tacoda[1].txt

Browser Hijacker.Begin2Search
HKU\S-1-5-21-2006666815-2642861256-1730731680-1007\Software\In3rd

Adware.IEPlugin
HKCR\Remove

Adware.Best Offers Network
HKU\S-1-5-21-2006666815-2642861256-1730731680-1007\Software\tbon
C:\WINDOWS\IPEPZHUXS.EXE

Adware.ClickSpring/Yazzle
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#Publisher
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1122OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1281OINUNINSTALLER.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1549OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1549OINUNINSTALLER.EXE.VIR

Adware.BetterInternet
HKU\S-1-5-21-2006666815-2642861256-1730731680-1007\Software\aurora

Trojan.TagASaurus
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\DESKTOP\SEARCHUS.EXE

Adware.ClickSpring
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\SMBOLS~1\CSRSS.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089946.EXE

Trojan.WinAntiSpyware 2007
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\WINANTISPYWARE 2007\IS-65J0M.TMP.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\WINANTISPYWARE 2007\WAS7MON.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089947.EXE

Adware.ToolBar888
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\{3CD31~1\MYTOOLBAR.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089955.DLL

Trojan.Downloader-VisFX
C:\QOOBOX\QUARANTINE\C\WINDOWS\OFFUN.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089959.EXE

Worm.Sober Variant
C:\QOOBOX\QUARANTINE\C\WINDOWS\SMANTE~1\WUCRTUPD.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089952.EXE

Adware.Vundo Variant
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DDCCAYX.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DDCYVVS.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PMNNOPN.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\VTUTQPN.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089937.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089938.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089941.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089944.DLL

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\X1\KMHP83122.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089805.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089820.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089957.EXE

Adware.Agent-XMLHelp
C:\QOOBOX\QUARANTINE\C\WINDOWS\XMLHELPER4.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089924.DLL

Trojan.WinAntiSpyware/WinAntiVirus 2006
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089800.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089839.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089840.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\UWA7P_0001_N91M0809NETINSTALLER.EXE

Trojan.Downloader-Gen/Win
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089810.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089830.EXE

Trojan.Downloader-LDCORE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089814.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP744\A0089825.DLL

Trojan.Downloader-Gen/HitItQuitIt
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089940.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP745\A0089971.DLL

Adware.Aurora/Nail
C:\WINDOWS\NAIL.EXE
C:\WINDOWS\Prefetch\NAIL.EXE-00088443.pf





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:10:54 PM, on 8/12/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe
C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Airlink101\AWLC5025\WLService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Airlink101\AWLC5025\AWLC5025.exe
C:\WINDOWS\System32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Norma Dinh\Desktop\HiJackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Metrics] C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe a
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1178925597\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MIMO XR TM Cardbus Adapter WLService (MIMO XR TM Cardbus WLService) - Unknown owner - C:\Program Files\Airlink101\AWLC5025\WLService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 7734 bytes



My computer is running quicker than it has in the past year. No more pop-ups whatsoever! Thank you so much!
-Norma


#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 13 August 2007 - 03:22 AM

Your log is clean :thumbsup:
If all's ok,please do the following.

Find and delete:
SDFix.exe
Combofix
fix.bat
SmitfraudFix

C:\QOOBOX
C:\SDFix
C:\rapport.txt

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.

-------------------------------------------------------------

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

You may now want to install Service Pack 2 via Windows Update.
If you decide to install SP2 i suggest you first create a new System Restore point,just as a precautionary measure.

Edited by RichieUK, 13 August 2007 - 03:22 AM.

Posted Image
Posted Image

#9 n827

n827
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:16 AM

Posted 14 August 2007 - 01:13 AM

Thank you so much Richie! I've followed all of your instructions and my computer is running quickly with no disruptions or anything! I don't know how to thank you so the best offer I have is if you are ever in the states, specifically Scottsdale, Arizona and head out to one of the nightclubs specifically Pussycat Lounge or Dirty Pretty Rockbar drinks on me! Just send me a message and they'll take care of you.

Thank you times a million!

Sincerely,
-Norma

:flowers: :thumbsup:

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 14 August 2007 - 02:05 PM

You're most welcome Norma :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users