Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hjt Logfile


  • This topic is locked This topic is locked
9 replies to this topic

#1 NinjaDMM

NinjaDMM

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:49 AM

Posted 27 September 2007 - 04:15 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:08 PM, on 9/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Video ActiveX Access\iesmn.exe
C:\Program Files\Video ActiveX Access\imsmain.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Video ActiveX Access\imsmn.exe
C:\Program Files\Common Files\PrivacyProtector Free\dcsm.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Video ActiveX Access\iesmin.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DAVE\Application Data\Mozilla\Profiles\default\axecqzl4.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19a73686-6ec2-40b5-a46e-32abb1997620} - C:\WINDOWS\system32\ir4sam.dll
O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - C:\Program Files\Video ActiveX Access\iesplg.dll
O2 - BHO: (no name) - {392BAF48-A26A-45B5-9263-97128E429268} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {8A06A1A7-9E64-4359-8556-B6EA03D69814} - C:\WINDOWS\system32\ir4sam.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: IKatzu Class - {EA5159DF-E413-4878-8AE2-D921D41BB942} - C:\WINDOWS\system32\bkingcrf.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Protection Bar - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - C:\Program Files\Video ActiveX Access\iesbpl.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sms_msn] C:\WINDOWS\system32\sms_msn.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [{0E-E1-1C-C3-ZN}] C:\DOCUME~1\Mark\LOCALS~1\Temp\nsk164.tmp P2D001
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\mliiig.dll",forkonce
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\PrivacyProtector Free\dcsm.exe"
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\Program Files\Extreme Messenger\ExtremeMessenger.exe nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Video ActiveX Access\iesmn.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Video ActiveX Access\imsmain.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures02.aim.com/ygp/aol/plugin/u...AIM.9.5.1.6.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O20 - Winlogon Notify: ir4sam - C:\WINDOWS\SYSTEM32\ir4sam.dll
O22 - SharedTaskScheduler: coexpire - {d4c4bc43-0974-4dec-a669-9f7bfcb3503d} - C:\WINDOWS\system32\vmlwp.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 10842 bytes

there we go, finally, had the old version, had to get to the new one! if anyone could help, i would appreciate it!! have the nasty winfixer privacy protection popups, im not that advanced enough to get rid of it, and any help would be greatly appreciated, there are three different user names on my computer, but mine is the main one, so if i need to get rid of the other two for now, i will, if need be! thanks again!

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 28 September 2007 - 07:24 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum NinjaDMM :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

First enable the viewing of hidden files and folders:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

W'ed like a sample of the following file if you would please:
C:\WINDOWS\system32\bkingcrf.dll
Fill in the details here,then press 'Send File':
http://www.bleepingcomputer.com/submit-malware.php?channel=8

Many thanks :blink:

Download SmitfraudFix (by S!Ri),to your desktop.
Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".
Double click on Smitfraudfix.cmd
Select #2 and hit Enter to delete the infected files.
You will be prompted: 'Do you want to clean the registry?' answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): 'Replace infected file ?' answer Y (yes) and hit Enter to restore a clean file.
A reboot may be needed to finish the cleaning process.
The report can be found at the root of the system drive, usually at C:\rapport.txt
Post the Smitfraudfix report into your next reply.

Note:
If you have previously downloaded ComboFix,please delete that version and download it again from below.
Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on Combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.

Edited by RichieUK, 28 September 2007 - 08:04 AM.

Posted Image
Posted Image

#3 NinjaDMM

NinjaDMM
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:49 AM

Posted 28 September 2007 - 02:13 PM

Thanks for your response! here are the logs you have asked for, it took me a while to to the combofix one, i didnt do it in safe mode first, then i did again, and finally got it, i might have messed it up, but i can already tell the two flashing things are gone, so thats good!!!

SmitFraudFix v2.232

Scan done at 14:12:52.46, Fri 09/28/2007
Run from C:\Documents and Settings\Dave\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}"="coexpire"

[HKEY_CLASSES_ROOT\CLSID\{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}\InProcServer32]
@="C:\WINDOWS\system32\vmlwp.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}\InProcServer32]
@="C:\WINDOWS\system32\vmlwp.dll"


Killing process


hosts


127.0.0.1 localhost

Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\vmlwp.dll -> Hoax.Win32.Renos.gen.o
C:\WINDOWS\system32\vmlwp.dll -> Deleted


Deleting infected files

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\AntiVirGear 3.7\ Deleted
C:\Program Files\Video ActiveX Access\ Deleted

DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{424BFBC2-72BE-4389-99F9-60860D636927}: DhcpNameServer=68.87.77.130 68.87.72.130
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CB77E8A1-B3CE-4050-9528-1B441EBBB75E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{424BFBC2-72BE-4389-99F9-60860D636927}: DhcpNameServer=68.87.77.130 68.87.72.130
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CB77E8A1-B3CE-4050-9528-1B441EBBB75E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{424BFBC2-72BE-4389-99F9-60860D636927}: DhcpNameServer=68.87.77.130 68.87.72.130
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CB77E8A1-B3CE-4050-9528-1B441EBBB75E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.77.130 68.87.72.130
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.87.77.130 68.87.72.130
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=68.87.77.130 68.87.72.130


Deleting Temp Files


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Registry Cleaning

Registry Cleaning done.

SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


End

here is combo

ComboFix 07-09-28.7 - Dave 2007-09-28 14:57:52.3 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.389 [GMT -4:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-28 )))))))))))))))))))))))))))))))
.

2007-09-28 14:20 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-28 14:13 2,252 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-28 14:12 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-28 14:12 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-28 14:12 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-28 14:12 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-28 14:12 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-09-27 23:30 <DIR> d-------- C:\WINDOWS\PaltalkScene
2007-09-25 12:03 <DIR> d-------- C:\WINDOWS\system32\logs
2007-09-20 16:17 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2007-09-20 16:14 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-09-20 16:14 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-09-20 16:14 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-09-20 16:14 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-09-20 16:14 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-09-20 16:14 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-09-20 16:13 <DIR> d-------- C:\Program Files\McAfee.com
2007-09-20 16:12 <DIR> d-------- C:\Program Files\McAfee
2007-09-20 16:12 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-09-20 15:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-09-19 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-09-19 20:40 <DIR> d-------- C:\Program Files\Common Files\supportsoft
2007-09-19 20:40 <DIR> d-------- C:\Program Files\Comcast
2007-09-19 09:46 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 20:32 <DIR> d-------- C:\Program Files\Paltalk Messenger
2007-09-17 20:32 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Paltalk
2007-08-31 22:03 <DIR> d-------- C:\Program Files\BearShare Applications
2007-08-30 19:48 <DIR> d-------- C:\Program Files\Absolute Poker
2007-08-30 19:48 <DIR> d-------- C:\Program Files\_uninstallation_info

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-20 15:31 --------- d-------- C:\Documents and Settings\Dave\Application Data\AdobeUM
2007-09-17 22:28 --------- d-------- C:\Program Files\ewido anti-malware
2007-08-28 20:56 --------- d-------- C:\Program Files\LimeWire
2007-08-25 01:23 24576 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-08-25 00:21 44922 --a------ C:\WINDOWS\system32\IKatzuUninstall.exe
2007-08-25 00:21 421888 --a------ C:\WINDOWS\system32\bkingcrf.dll
2007-08-25 00:21 118784 --a------ C:\WINDOWS\system32\artchker.exe
2007-08-20 20:56 --------- d-------- C:\Documents and Settings\Mark\Application Data\Talkback
2007-08-17 09:19 --------- d-------- C:\Program Files\MTV Networks
2007-08-16 20:09 --------- d-------- C:\Documents and Settings\Dave\Application Data\Talkback
2007-08-14 07:49 --------- d-------- C:\Program Files\PartyGaming
2007-08-12 22:17 1190939 ---hs---- C:\WINDOWS\filmpo.ini2
2007-08-10 00:12 --------- d-------- C:\Documents and Settings\Mark\Application Data\Real
2007-08-08 15:03 --------- d-------- C:\Program Files\ESPN
2007-08-04 19:53 --------- dr-h----- C:\Documents and Settings\Mark\Application Data\yahoo!
2007-08-04 19:52 --------- d-------- C:\Documents and Settings\Mark\Application Data\Google
2007-08-04 19:51 --------- d-------- C:\Documents and Settings\Mark\Application Data\MySpace
2007-08-04 17:48 --------- d-------- C:\Program Files\MySpace
2007-08-04 17:48 --------- d-------- C:\Documents and Settings\Dave\Application Data\MySpace
2007-08-03 17:42 --------- d-------- C:\Program Files\BroadJump
2007-08-03 17:17 --------- d-------- C:\Program Files\support.com
2007-08-03 17:11 --------- d-------- C:\Documents and Settings\All Users\Application Data\Support.com
2007-08-02 16:48 --------- d-------- C:\Documents and Settings\Mark\Application Data\Aim
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-06-20 13:18 53739 --a------ C:\Program Files\unrar.exe
2005-12-22 23:16 71 --a--c--- C:\Documents and Settings\Dave\killjobs.bat
2005-09-28 22:50 806 --a--c--- C:\Program Files\Warez P2P ClientIPGUARD.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{392BAF48-A26A-45B5-9263-97128E429268}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5159DF-E413-4878-8AE2-D921D41BB942}]
2007-08-25 00:21 421888 --a------ C:\WINDOWS\system32\bkingcrf.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunKistEM"="C:\Program Files\eMachines Bay Reader\shwiconem.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" []
"IPInSightLAN 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" []
"IPInSightMonitor 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
"sms_msn"="C:\WINDOWS\system32\sms_msn.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
"{0E-E1-1C-C3-ZN}"="C:\DOCUME~1\Mark\LOCALS~1\Temp\nsk164.tmp P2D001" []
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 14:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Extreme Messenger for AIM"="C:\Program Files\Extreme Messenger\ExtremeMessenger.exe" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 19:11]
"SP2ConnPatcher"="C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" []
"SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" []
"PlaxoUpdate"="C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 22:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 16:44]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 20:04]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 14:09:15]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [2007-09-08 10:31:00]

C:\Documents and Settings\Mark\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-08-16 18:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 14:09:15]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [2007-09-08 10:31:00]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

S2 sprtsvc_ddoctorv2;SupportSoft Sprocket Service (ddoctorv2);"C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe" /service /P ddoctorv2
S2 WUSB54Gv4SVC;WUSB54Gv4SVC;"C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe"
S3 PciTest;WinMTA PCI Service;\??\C:\WINDOWS\SYSTEM32\DRIVERS\pcitest.sys
S3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-28 18:00:02 C:\WINDOWS\Tasks\6CDA67C99ED7AE99.job"
- c:\docume~1\dave\applic~1\itchmp~1\atomremotedale.exe
"2007-09-28 18:00:03 C:\WINDOWS\Tasks\ADA277019181EA81.job"
- c:\docume~1\dave\applic~1\itchmp~1\atomremotedale.exe
"2007-09-20 20:13:53 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2007-09-20 20:13:52 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-28 15:01:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-09-28 15:02:40
C:\ComboFix-quarantined-files.txt ... 2007-09-28 15:02
.
--- E O F ---

and my new hijack this logfile

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:49 PM, on 9/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DAVE\Application Data\Mozilla\Profiles\default\axecqzl4.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {392BAF48-A26A-45B5-9263-97128E429268} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: IKatzu Class - {EA5159DF-E413-4878-8AE2-D921D41BB942} - C:\WINDOWS\system32\bkingcrf.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sms_msn] C:\WINDOWS\system32\sms_msn.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [{0E-E1-1C-C3-ZN}] C:\DOCUME~1\Mark\LOCALS~1\Temp\nsk164.tmp P2D001
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\Program Files\Extreme Messenger\ExtremeMessenger.exe nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures02.aim.com/ygp/aol/plugin/u...AIM.9.5.1.6.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 9251 bytes


also, i appreciate your help, i will not be back until sunday afternoon, so please understand the delay in my reponse, i will be helping a fellow friend move, and all friday and saturday i will be gone, but i look forward to reading what you say next!! thanks ALOT already, i definately appreciate it, i hope this helps you out, and im sorry if i messed up the combofix, i will check back in on sunday!!! have a great weekend!!!

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 28 September 2007 - 02:32 PM

You have a Backdoor Trojan present on your pc
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to by used by the attacker for malicious purposes unknown to the user.

They are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such risks may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
They should be changed by using a different computer and not the infected one,if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech.

Since your computer was compromised read:
How to report ID theft, fraud, drive-by installs, hijacking and malware:
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall:
http://www.dslreports.com/faq/10063

If you want us to go ahead and clean up your system then carry on below:


Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\filmpo.ini2
C:\WINDOWS\system32\bkingcrf.dll
C:\WINDOWS\system32\artchker.exe
C:\WINDOWS\Tasks\6CDA67C99ED7AE99.job
C:\WINDOWS\Tasks\ADA277019181EA81.job

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{392BAF48-A26A-45B5-9263-97128E429268}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5159DF-E413-4878-8AE2-D921D41BB942}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sms_msn"=-
"{0E-E1-1C-C3-ZN}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}"=-
[-HKEY_CLASSES_ROOT\CLSID\{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}\InProcServer32]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{d4c4bc43-0974-4dec-a669-9f7bfcb3503d}\InProcServer32]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#5 NinjaDMM

NinjaDMM
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:49 AM

Posted 01 October 2007 - 02:08 PM

hey, sorry for the delay in my response, been busy! alright, i did what you said, here is my new combo fix log

ComboFix 07-09-28.7 - Dave 2007-10-01 14:53:57.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.270 [GMT -4:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dave\Desktop\CFScript_used_2007-10-01@14.52.txt
* Created a new restore point

FILE::
C:\WINDOWS\filmpo.ini2
C:\WINDOWS\system32\bkingcrf.dll
C:\WINDOWS\system32\artchker.exe
C:\WINDOWS\Tasks\6CDA67C99ED7AE99.job
C:\WINDOWS\Tasks\ADA277019181EA81.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\filmpo.ini2
C:\WINDOWS\system32\artchker.exe
C:\WINDOWS\system32\bkingcrf.dll
C:\WINDOWS\Tasks\6CDA67C99ED7AE99.job
C:\WINDOWS\Tasks\ADA277019181EA81.job

.
((((((((((((((((((((((((( Files Created from 2007-09-01 to 2007-10-01 )))))))))))))))))))))))))))))))
.

2007-09-28 14:20 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-28 14:13 2,252 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-28 14:12 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-28 14:12 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-28 14:12 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-28 14:12 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-28 14:12 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-09-27 23:30 <DIR> d-------- C:\WINDOWS\PaltalkScene
2007-09-25 12:03 <DIR> d-------- C:\WINDOWS\system32\logs
2007-09-20 16:17 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2007-09-20 16:14 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-09-20 16:14 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-09-20 16:14 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-09-20 16:14 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-09-20 16:14 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-09-20 16:14 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-09-20 16:13 <DIR> d-------- C:\Program Files\McAfee.com
2007-09-20 16:12 <DIR> d-------- C:\Program Files\McAfee
2007-09-20 16:12 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-09-20 15:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-09-19 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-09-19 20:40 <DIR> d-------- C:\Program Files\Common Files\supportsoft
2007-09-19 20:40 <DIR> d-------- C:\Program Files\Comcast
2007-09-19 09:46 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 20:32 <DIR> d-------- C:\Program Files\Paltalk Messenger
2007-09-17 20:32 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Paltalk

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-23 18:18 --------- d-------- C:\Program Files\Absolute Poker
2007-09-20 15:31 --------- d-------- C:\Documents and Settings\Dave\Application Data\AdobeUM
2007-09-17 22:28 --------- d-------- C:\Program Files\ewido anti-malware
2007-09-02 23:52 --------- d-------- C:\Program Files\BearShare Applications
2007-08-30 19:48 --------- d-------- C:\Program Files\_uninstallation_info
2007-08-28 20:56 --------- d-------- C:\Program Files\LimeWire
2007-08-17 09:19 --------- d-------- C:\Program Files\MTV Networks
2007-08-16 20:09 --------- d-------- C:\Documents and Settings\Dave\Application Data\Talkback
2007-08-14 07:49 --------- d-------- C:\Program Files\PartyGaming
2007-08-08 15:03 --------- d-------- C:\Program Files\ESPN
2007-08-04 17:48 --------- d-------- C:\Program Files\MySpace
2007-08-04 17:48 --------- d-------- C:\Documents and Settings\Dave\Application Data\MySpace
2007-08-03 17:42 --------- d-------- C:\Program Files\BroadJump
2007-08-03 17:17 --------- d-------- C:\Program Files\support.com
2007-08-03 17:11 --------- d-------- C:\Documents and Settings\All Users\Application Data\Support.com
2007-06-20 13:18 53739 --a------ C:\Program Files\unrar.exe
2005-12-22 23:16 71 --a--c--- C:\Documents and Settings\Dave\killjobs.bat
2005-09-28 22:50 806 --a--c--- C:\Program Files\Warez P2P ClientIPGUARD.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunKistEM"="C:\Program Files\eMachines Bay Reader\shwiconem.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" []
"IPInSightLAN 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" []
"IPInSightMonitor 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 14:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Extreme Messenger for AIM"="C:\Program Files\Extreme Messenger\ExtremeMessenger.exe" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 19:11]
"SP2ConnPatcher"="C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" []
"SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" []
"PlaxoUpdate"="C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 22:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 16:44]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 20:04]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 14:09:15]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [2007-09-08 10:31:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 14:09:15]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [2007-09-08 10:31:00]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

R2 sprtsvc_ddoctorv2;SupportSoft Sprocket Service (ddoctorv2);"C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe" /service /P ddoctorv2
R2 WUSB54Gv4SVC;WUSB54Gv4SVC;"C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe"
S3 PciTest;WinMTA PCI Service;\??\C:\WINDOWS\SYSTEM32\DRIVERS\pcitest.sys
S3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-20 20:13:53 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2007-10-01 05:00:12 C:\WINDOWS\Tasks\McQcTask.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-01 15:00:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-10-01 15:04:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-01 15:03
C:\ComboFix2.txt ... 2007-09-28 15:02
.
--- E O F ---

and my hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:06:35 PM, on 10/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DAVE\Application Data\Mozilla\Profiles\default\axecqzl4.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\Program Files\Extreme Messenger\ExtremeMessenger.exe nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures02.aim.com/ygp/aol/plugin/u...AIM.9.5.1.6.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 8793 bytes


again sorry for the delay, had a busy busy weekend, hopefully yours was great!! thanks again for taking the time to help me out!

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 01 October 2007 - 02:31 PM

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.


Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,on the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#7 NinjaDMM

NinjaDMM
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:49 AM

Posted 01 October 2007 - 07:52 PM

ok, here goes!! i got rid of all the other javas on my comp, here is the super spyware log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/01/2007 at 05:09 PM

Application Version : 3.9.1008

Core Rules Database Version : 3316
Trace Rules Database Version: 1317

Scan type : Complete Scan
Total Scan Time : 00:45:58

Memory items scanned : 433
Memory threats detected : 0
Registry items scanned : 4926
Registry threats detected : 2
File items scanned : 38276
File threats detected : 129

Adware.Tracking Cookie
C:\Documents and Settings\Dave\Cookies\dave@CA6831WU.txt
C:\Documents and Settings\Dave\Cookies\dave@atdmt[2].txt
C:\Documents and Settings\Dave\Cookies\dave@www.winantispyware[1].txt
C:\Documents and Settings\Dave\Cookies\dave@www.viruslocker[1].txt
C:\Documents and Settings\Dave\Cookies\dave@ad.yieldmanager[2].txt
C:\Documents and Settings\Dave\Cookies\dave@doubleclick[2].txt
C:\Documents and Settings\Dave\Cookies\dave@www.antivirgear[1].txt
C:\Documents and Settings\Dave\Cookies\dave@mediaplex[2].txt
C:\Documents and Settings\Dave\Cookies\dave@ehg-foxsports.hitbox[2].txt
C:\Documents and Settings\Dave\Cookies\dave@adopt.euroclick[2].txt
C:\Documents and Settings\Dave\Cookies\dave@dr1[2].txt
C:\Documents and Settings\Dave\Cookies\dave@winantivirus[1].txt
C:\Documents and Settings\Dave\Cookies\dave@adopt.specificclick[1].txt
C:\Documents and Settings\Dave\Cookies\dave@CAYWDJP9.txt
C:\Documents and Settings\Dave\Cookies\dave@stats.privacyprotector[1].txt
C:\Documents and Settings\Dave\Cookies\dave@specificclick[2].txt
C:\Documents and Settings\Dave\Cookies\dave@drivecleaner[2].txt
C:\Documents and Settings\Dave\Cookies\dave@hitbox[1].txt
C:\Documents and Settings\Dave\Cookies\dave@trafficmp[2].txt
C:\Documents and Settings\Dave\Cookies\dave@html[1].txt
C:\Documents and Settings\Dave\Cookies\dave@winantispyware[2].txt
C:\Documents and Settings\Dave\Cookies\dave@go.drivecleaner[1].txt
C:\Documents and Settings\Dave\Cookies\dave@atwola[2].txt
C:\Documents and Settings\Dave\Cookies\dave@stats1.reliablestats[1].txt
C:\Documents and Settings\Dave\Cookies\dave@www.winantiviruspro[1].txt
C:\Documents and Settings\Dave\Cookies\dave@tribalfusion[1].txt
C:\Documents and Settings\Dave\Cookies\dave@2o7[1].txt
C:\Documents and Settings\Dave\Cookies\dave@realmedia[1].txt
C:\Documents and Settings\Dave\Cookies\dave@interclick[2].txt
C:\Documents and Settings\Dave\Cookies\dave@www.winantivirus[1].txt
C:\Documents and Settings\Dave\Cookies\dave@stats.drivecleaner[2].txt
C:\Documents and Settings\Dave\Cookies\dave@www.screensavers[1].txt
C:\Documents and Settings\Dave\Cookies\dave@CAVZQPUG.txt
C:\Documents and Settings\Dave\Cookies\dave@ar.atwola[1].txt
C:\Documents and Settings\Dave\Cookies\dave@atwola[1].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[10].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[11].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[1].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[3].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[4].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[5].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[6].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[7].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[8].txt
C:\Documents and Settings\Dave\Cookies\dave@azjmp[9].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[10].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[11].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[1].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[2].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[3].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[4].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[5].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[6].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[7].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[8].txt
C:\Documents and Settings\Dave\Cookies\dave@i.screensavers[9].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[10].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[11].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[1].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[2].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[3].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[4].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[5].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[6].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[7].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[8].txt
C:\Documents and Settings\Dave\Cookies\dave@screensavers[9].txt
C:\Documents and Settings\Eddie\Cookies\eddie@67.15.239[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@ad.yieldmanager[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adinterax[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adopt.euroclick[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adopt.specificclick[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adrevolver[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adrevolver[3].txt
C:\Documents and Settings\Eddie\Cookies\eddie@ads.pointroll[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@ads.revsci[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@adserver.mediarun[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@advertising[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@atdmt[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@bluestreak[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@cpvfeed[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@doubleclick[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@drivecleaner[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@enhance[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@fastclick[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@go.drivecleaner[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@go.winantispyware[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@go.winantispyware[3].txt
C:\Documents and Settings\Eddie\Cookies\eddie@hqthefilmsxxx[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@hqthefilmsxxx[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@hqthefilmsxxx[3].txt
C:\Documents and Settings\Eddie\Cookies\eddie@hqthefilmsxxx[5].txt
C:\Documents and Settings\Eddie\Cookies\eddie@image.masterstats[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@m1.webstats.motigo[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@media.adrevolver[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@mediaplex[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@questionmarket[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@realmedia[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@redirect.clickshield[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@richmedia.yahoo[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@rotabanner100.utro[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@specificclick[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@stats.drivecleaner[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@stats.privacyprotector[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@stats1.reliablestats[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@trafficmp[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@tribalfusion[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@winantispyware[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@www.googleadservices[2].txt
C:\Documents and Settings\Eddie\Cookies\eddie@www.googleadservices[3].txt
C:\Documents and Settings\Eddie\Cookies\eddie@yadro[1].txt
C:\Documents and Settings\Eddie\Cookies\eddie@zvuki.madbanner[1].txt
C:\Documents and Settings\Mark\Cookies\mark@drivecleaner[2].txt
C:\Documents and Settings\Mark\Cookies\mark@go.drivecleaner[2].txt
C:\Documents and Settings\Mark\Cookies\mark@stats.drivecleaner[2].txt

Trojan.NewDotNet
HKU\.DEFAULT\Software\New.net
HKU\S-1-5-18\Software\New.net

Browser Hijacker.Favorites
C:\DOCUMENTS AND SETTINGS\EDDIE\FAVORITES\ONLINE SECURITY TEST.URL

Malware.AntiVirGear
C:\DOCUMENTS AND SETTINGS\EDDIE\LOCAL SETTINGS\TEMP\BR12B.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP843\A0065169.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP852\A0067218.EXE

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\EDDIE\LOCAL SETTINGS\TEMP\LAF1.EXE

Trojan.WinAntiSpyware 2007
C:\DOCUMENTS AND SETTINGS\EDDIE\LOCAL SETTINGS\TEMP\WINANTISPYWARE2007SETUP.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP844\A0065276.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP846\A0065696.EXE

Trojan.Downloader/Media-Codec
C:\DOCUMENTS AND SETTINGS\EDDIE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\DHCH0DWS\VIDEOACCESSCODECINSTALL[1].EXE

Trojan.Downloader-Stera/WinSoftware
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP844\A0065269.EXE

Trojan.Smitfraud Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP852\A0067217.DLL

Trojan.Duncan
C:\SYSTEM VOLUME INFORMATION\_RESTORE{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP853\A0067264.DLL

Trojan.ESDWindowsIE
C:\WINDOWS\SYSTEM32\BAK\SMS_MSN.EXE

Adware.Unknown Origin
C:\WINDOWS\SYSTEM32\IESH12052004.CFG


and my new hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:24 PM, on 10/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DAVE\Application Data\Mozilla\Profiles\default\axecqzl4.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\Program Files\Extreme Messenger\ExtremeMessenger.exe nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures02.aim.com/ygp/aol/plugin/u...AIM.9.5.1.6.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 9319 bytes


hopefully that helps, it seems my pc is running fine, but if you see anything, let me know!! thanks again!!!

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 02 October 2007 - 03:55 AM

Your log is clean :thumbsup:
If all's ok,please do the following.

Find and delete:
SmitfraudFix.exe
Combofix.exe

C:\QOOBOX
C:\rapport.txt

Reverse the following:
First enable the viewing of hidden files and folders:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.


Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
How to prevent Malware by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#9 NinjaDMM

NinjaDMM
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:49 AM

Posted 02 October 2007 - 02:08 PM

ok, sweet, i think i did all that right, lol, thanks soooooo much for your help, it seems my pc is fine, theres 3 people on this comp so who knows when i got it or if i even did it, but thanks for your time and effort in helping me

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 02 October 2007 - 06:22 PM

You're most welcome :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users