Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need Help With Hijackthis Log


  • This topic is locked This topic is locked
16 replies to this topic

#1 1010101

1010101

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 30 November 2007 - 03:19 PM

was infected with smitfraud and malwarealarm, did some research and finally got rid of them.

I already ran:
combofix
smitfaudfix
vundofix
spybot
ad-aware
panda anti virus
symantec anti virus
mcafee stinger

i was still getting pop ups so i installed zone alarm, now there's no more pop up but i think the hijackthis log is still not clean, need someone to look at it. many thanks in advance.


here is the hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:16:52 PM, on 11/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\ntvdm.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54B9BA58-B0E6-4950-8519-8158F548D0B7} - \
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {DD895B6D-2AE1-4540-A846-D13193DA19F6} - \
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SystemMgr] C:\WINDOWS\system32\Ir32_a.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Phjpka] "C:\Program Files\s?stem\?poolsv.exe"
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Joyo - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: PowerWord - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\POWERW~1\XDictExB.dll
O9 - Extra button: PowerWord - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Documentum Content Transfer 5.2.5 - http://zetes.gmu.edu/lcms/wdk/contentXfer/ContentXfer.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) - https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 13828 bytes

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 01 December 2007 - 09:09 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum 1010101
My name is Richie and i'll be helping you to fix your problems.

You have Symantec AntiVirus and McAfee installed.
Its definitely not a good idea to have more than one antivirus program installed on your computer.
Each program may interpret the actions of the other as viral, therefore giving you false virus warnings about virus-related activities.
It could also lead to system slowdowns and other problems within the operating system,due to the two conflicting with each other.
You should uninstall one of them now,then restart your pc.

If you decide to uninstall Symantec/Norton,if there is no uninstaller available in Add\Remove Programs then you will need to download and run the Norton Removal Tool:
http://service1.symantec.com/SUPPORT/tsgen...005033108162039
*Please Note*
The Norton Removal Tool will remove all Norton/Symantec products from your pc.


If you have previously downloaded ComboFix,please delete that version now.

*Warning*
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert,not for private use.
Using this tool incorrectly could lead to your system becoming unusable.

Now download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Disconnect from the Internet.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
*Note*
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 02 December 2007 - 11:48 AM

Thank you Richie.

Here is the combofix.txt:

ComboFix 07-12-02.5 - LEE 2007-12-02 11:20:55.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.363 [GMT -5:00]
Running from: C:\Documents and Settings\LEE.HOME\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\WINDOWS\system32\rMa02yy

.
((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))
.

2007-11-29 18:48 . 2007-12-02 10:53 677,920 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2007-11-29 18:48 . 2007-12-02 10:53 8,300 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2007-11-29 18:41 . 2007-11-29 18:41 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
2007-11-29 18:40 . 2007-09-06 16:14 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-11-29 18:40 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-11-29 18:40 . 2007-11-29 18:46 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-11-29 18:37 . 2007-12-02 11:14 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-11-29 15:20 . 2007-11-29 15:20 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2007-11-29 15:20 . 2007-11-29 15:20 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-11-29 15:20 . 2007-11-29 15:20 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2007-11-29 15:19 . 2007-11-29 17:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-11-29 14:31 . 2007-11-29 14:31 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-29 14:31 . 2007-11-29 14:31 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2007-11-29 14:30 . 2007-11-29 14:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-29 11:31 . 2007-11-29 11:31 <DIR> d-------- C:\Program Files\MetaStream
2007-11-26 22:42 . 2007-11-26 22:42 0 --a------ C:\WINDOWS\vpc32.INI
2007-11-26 22:29 . 2007-11-26 22:30 110,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-11-26 22:29 . 2007-11-26 22:30 48,768 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-11-26 22:29 . 2007-11-26 22:30 8,014 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-11-26 22:29 . 2007-11-26 22:30 805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-11-26 22:28 . 2007-12-02 10:55 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2007-11-26 22:27 . 2007-11-26 22:27 <DIR> d-------- C:\temp\nav
2007-11-25 23:29 . 2007-11-28 22:38 4,298 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-25 21:34 . 2007-11-29 16:46 <DIR> d-------- C:\VundoFix Backups
2007-11-23 15:53 . 2007-11-23 15:53 2,238 --a------ C:\WINDOWS\SYSTEM32\ClickToFindandFixErrors_US.ico
2007-11-23 15:47 . 2007-11-23 15:47 <DIR> d-------- C:\Program Files\mtkvubyb
2007-11-23 15:47 . 2007-11-23 15:47 <DIR> d-------- C:\Program Files\Gedegpav
2007-11-23 15:47 . 2007-11-23 18:42 <DIR> d-------- C:\Program Files\Cool
2007-11-23 15:47 . 2007-11-23 15:47 1,149,472 --a------ C:\Install
2007-11-23 15:47 . 2007-11-23 15:47 102,912 --a------ C:\WINDOWS\SYSTEM32\drvbak.dll
2007-11-23 15:46 . 2007-11-23 15:59 <DIR> d-------- C:\WINDOWS\SYSTEM32\cc1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 15:55 --------- d-----w C:\Program Files\McAfee.com
2007-12-02 15:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com
2007-12-01 18:42 --------- d-----w C:\Program Files\NJStar Communicator
2007-11-30 19:36 --------- d-----w C:\Documents and Settings\LEE.HOME\Application Data\Juniper Networks
2007-11-29 21:21 --------- d-----w C:\Program Files\MSN Messenger
2007-11-29 21:15 --------- d-----w C:\Program Files\iTunes
2007-11-29 21:15 --------- d-----w C:\Program Files\Google
2007-11-29 21:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-29 16:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2007-11-28 04:46 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-11-27 03:30 --------- d-----w C:\Program Files\Symantec
2007-11-27 03:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2007-11-27 03:07 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-23 23:46 --------- d-----w C:\Program Files\Canon
2007-11-23 05:08 --------- d-----w C:\Documents and Settings\LEE.HOME\Application Data\WeatherBug
2007-10-26 15:43 --------- d-----w C:\Program Files\Juniper Networks
2007-10-03 20:12 61,493 ----a-w C:\WINDOWS\SYSTEM32\dsGinaLoader.dll
2007-10-03 17:48 23,552 ----a-w C:\WINDOWS\system32\drivers\dsNcAdpt.sys
2007-09-06 21:14 1,086,952 ----a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2003-04-28 15:29 207,759 -c--a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54B9BA58-B0E6-4950-8519-8158F548D0B7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DD895B6D-2AE1-4540-A846-D13193DA19F6}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\Weather.exe" [2004-09-09 16:35]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 21:49]
"Phjpka"="C:\Program Files\s?stem\?poolsv.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 00:31]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 07:00]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 07:00]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 11:28]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-28 21:52]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"SystemMgr"="C:\WINDOWS\system32\Ir32_a.exe" [2000-01-09 23:00]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-01-12 22:46:25]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-05-17 22:01:31]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 23:05:56]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-01-22 21:30:03]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\ldcore.dll

R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;C:\oracle\ora81\BIN\ONRSD.EXE
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 SjyPkt;SjyPkt;\??\C:\WINDOWS\System32\Drivers\SjyPkt.sys
S3 Tomcat5;Apache Tomcat;"C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe" //RS//Tomcat5

.
Contents of the 'Scheduled Tasks' folder
"2007-11-29 18:15:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-02 11:26:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-nt.exe"
.
Completion time: 2007-12-02 11:27:23
.
--- E O F ---

#4 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 02 December 2007 - 11:49 AM

here is the hijackthis.log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:20 AM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\DOCUME~1\LEE~1.HOM\LOCALS~1\Temp\2007122105248_mcinfo.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54B9BA58-B0E6-4950-8519-8158F548D0B7} - \
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {DD895B6D-2AE1-4540-A846-D13193DA19F6} - \
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SystemMgr] C:\WINDOWS\system32\Ir32_a.exe
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\LEE~1.HOM\LOCALS~1\Temp\2007122105248_mcinfo.exe /insfin
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Phjpka] "C:\Program Files\s?stem\?poolsv.exe"
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Joyo - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: PowerWord - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\POWERW~1\XDictExB.dll
O9 - Extra button: PowerWord - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Documentum Content Transfer 5.2.5 - http://zetes.gmu.edu/lcms/wdk/contentXfer/ContentXfer.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) - https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 13485 bytes

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 02 December 2007 - 12:20 PM

Click Start/Control Panel/Add or Remove Programs and remove AWS,then restart your pc.

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\vpc32.INI
C:\WINDOWS\SYSTEM32\drvbak.dll
Folder::
C:\VundoFix Backups
C:\Program Files\mtkvubyb
C:\Program Files\Gedegpav
C:\WINDOWS\SYSTEM32\cc1
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
C:\Program Files\McAfee.com
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54B9BA58-B0E6-4950-8519-8158F548D0B7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DD895B6D-2AE1-4540-A846-D13193DA19F6}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Phjpka"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemMgr"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#6 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 02 December 2007 - 01:50 PM

Thanks again Richie.

Here you go....


ComboFix 07-12-02.5 - LEE 2007-12-02 13:21:04.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.389 [GMT -5:00]
Running from: C:\Documents and Settings\LEE.HOME\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LEE.HOME\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\SYSTEM32\drvbak.dll
C:\WINDOWS\vpc32.INI
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com\Agent\Cache\McSubDB.Bak
C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee.com\Agent\McSubDB.Dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1023449145.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1054744159.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1134284413.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1257552095.712536053
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1476482372.712535979
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1550700062.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1675323418.713836840
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1744624506.713836803
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1767541886.713836716
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-1792851963.712535981
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-251317963.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-685991849.712535954
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-708065856.713836749
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-732913299.712536002
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-763019087.713836937
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\-96559883.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\1461440338.712535953
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\1564877131.712535908
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\2132695476.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\253621806.fdg
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\253621806.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\340035850.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\385814962.712536011
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\467515700.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\475343437.mts
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\501688438.712536046
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\924053971.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\99837075.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1018429957.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1041161462.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1216699398.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1545690586.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1568127352.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-167467785.712535921
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-1735078747.713836821
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-2040853405.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-378119151.712535947
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-583022627.712535910
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-787478019.712535915
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-907638366.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\-982355842.712536070
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\1176327029.713836865
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\1220223377.712535992
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\1247495568.712535999
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\1304666343.712536034
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\1772106491.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\346281577.713836896
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\512589962.712536028
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\570073743.713863076
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\768763562.712535994
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\860502393.712536026
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\925975223.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1140250495.713836908
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1149444489.712536068
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1219180738.713836830
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1270717649.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1437572679.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1438713594.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1610302144.712536009
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1621127722.swf
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1651440994.712535931
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1676547782.mts
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1679536239.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1801392204.712535990
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1817435829.712536059
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-1819899927.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-2034384745.713836872
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-2108356295.712535989
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-243470204.712536022
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-300725744.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-41890203.712536041
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-575272626.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-582640680.712536049
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-654067379.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-668285516.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-72580264.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\-764272172.712535942
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\1229517749.712535939
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\1385903037.713836769
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\143415706.712536017
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\1520622600.712535996
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\164380830.748461319
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\172992995.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\2142072298.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\407034558.ini
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\434599021.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\475306063.mtz
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\705794319.748464007
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\833975032.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1037005395.713836741
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1106322216.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1233561107.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1294591352.712536065
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1307685966.713836843
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1603077681.712535983
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1625577909.713836700
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1720476204.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1799102199.713836711
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1877319710.713836793
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-1926077123.712535997
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-583862537.712536063
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\-66919675.712536043
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1013774213.swf
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1071317150.713836906
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1173877197.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\11996273.748461276
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\119964245.713836888
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1382942631.713836864
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1385887584.713836838
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1418335590.713836807
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1610426641.swf
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1669572585.712536032
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1838517554.712536007
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\1978047516.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\2021793278.712535944
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\30244730.mtz
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\398485060.MTZ
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\446305278.swf
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\489659170.712536061
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\581741786.713836754
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\582067880.712535985
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\746857229.713836914
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\770800983.712535978
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\848588323.SWF
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\879056853.712535933
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\932053967.712536014
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\980018594.mtx
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint\Viewpoint\Resources\UpdateVersionList_v2.mtx
C:\Program Files\Gedegpav
C:\Program Files\Gedegpav\lppoufpu.dll
C:\Program Files\McAfee.com
C:\Program Files\McAfee.com\Personal Firewall\data\certi.idx
C:\Program Files\McAfee.com\Personal Firewall\data\Dump.ini
C:\Program Files\McAfee.com\Personal Firewall\data\hwcache.xdb
C:\Program Files\McAfee.com\Personal Firewall\data\hwid.idx
C:\Program Files\McAfee.com\Personal Firewall\data\IpRules.xdb
C:\Program Files\McAfee.com\Personal Firewall\data\log.edb
C:\Program Files\McAfee.com\Personal Firewall\data\mvtx\LS.idx
C:\Program Files\McAfee.com\Personal Firewall\data\mvtx\Settings.idx
C:\Program Files\McAfee.com\Personal Firewall\data\options.idx
C:\Program Files\McAfee.com\Personal Firewall\data\rdns.idx
C:\Program Files\McAfee.com\Personal Firewall\data\style\RED\Dump.ini
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon0.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon1.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon2.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon3.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon4.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon5.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\appicons\appicon6.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\sum_04_hw.htm
C:\Program Files\McAfee.com\Personal Firewall\data\summary\tools\images\inbound-min-app.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\tools\images\inbound-min.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\tools\images\inoutbound-usage.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\tools\images\outbound-min-app.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\tools\images\outbound-min.bmp
C:\Program Files\McAfee.com\Personal Firewall\data\summary\worldmap.png
C:\Program Files\McAfee.com\Personal Firewall\data\TrafficHist.xdb
C:\Program Files\McAfee.com\Personal Firewall\MpfTrayErrors.txt
C:\Program Files\McAfee.com\VSO\804mbd1.chk
C:\Program Files\McAfee.com\VSO\804mbd1.IMG
C:\Program Files\McAfee.com\VSO\ashldres.dll
C:\Program Files\McAfee.com\VSO\clean.dat
C:\Program Files\McAfee.com\VSO\edisk.dll
C:\Program Files\McAfee.com\VSO\ediskimg.inf
C:\Program Files\McAfee.com\VSO\extra.dat
C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe
C:\Program Files\McAfee.com\VSO\mcscan32.dll
C:\Program Files\McAfee.com\VSO\McShield.exe
C:\Program Files\McAfee.com\VSO\mcurial.dll
C:\Program Files\McAfee.com\VSO\mcvsctl.dll
C:\Program Files\McAfee.com\VSO\mcvsmap.exe
C:\Program Files\McAfee.com\VSO\mcvsrte.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\naiann.dll
C:\Program Files\McAfee.com\VSO\NaiEvent.dll
C:\Program Files\McAfee.com\VSO\Naifiltr.cat
C:\Program Files\McAfee.com\VSO\NaiFiltr.inf
C:\Program Files\McAfee.com\VSO\Names.dat
C:\Program Files\McAfee.com\VSO\ntclient.dll
C:\Program Files\McAfee.com\VSO\PATCHW32.DLL
C:\Program Files\McAfee.com\VSO\readme.txt
C:\Program Files\McAfee.com\VSO\Res09\McShield.dll
C:\Program Files\McAfee.com\VSO\scan.dat
C:\Program Files\McAfee.com\VSO\ScanServ.dll
C:\Program Files\McAfee.com\VSO\vsagntui.dll
C:\Program Files\McAfee.com\VSO\vsez.adf
C:\Program Files\McAfee.com\VSO\vsezres.dll
C:\Program Files\McAfee.com\VSO\vso.adf
C:\Program Files\McAfee.com\VSO\vso.chm
C:\Program Files\McAfee.com\VSO\vso.inf
C:\Program Files\McAfee.com\VSO\vsocfg.inf
C:\Program Files\McAfee.com\VSO\vsodat.inf
C:\Program Files\McAfee.com\VSO\vsoeng.inf
C:\Program Files\McAfee.com\VSO\vsoui.dll
C:\Program Files\McAfee.com\VSO\vsoupd.dll
C:\Program Files\mtkvubyb
C:\Program Files\mtkvubyb\gbepidqp.dll
C:\VundoFix Backups
C:\WINDOWS\SYSTEM32\cc1
C:\WINDOWS\SYSTEM32\drvbak.dll
C:\WINDOWS\vpc32.INI

.
((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))
.

2007-11-29 18:48 . 2007-12-02 13:31 720,928 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2007-11-29 18:48 . 2007-12-02 13:31 9,500 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2007-11-29 18:41 . 2007-11-29 18:41 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
2007-11-29 18:40 . 2007-09-06 16:14 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-11-29 18:40 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-11-29 18:40 . 2007-11-29 18:46 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-11-29 18:37 . 2007-12-02 13:17 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-11-29 15:20 . 2007-11-29 15:20 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2007-11-29 15:20 . 2007-11-29 15:20 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-11-29 15:20 . 2007-11-29 15:20 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2007-11-29 15:19 . 2007-11-29 17:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-11-29 14:31 . 2007-11-29 14:31 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-29 14:31 . 2007-11-29 14:31 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2007-11-29 14:30 . 2007-11-29 14:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-29 11:31 . 2007-11-29 11:31 <DIR> d-------- C:\Program Files\MetaStream
2007-11-26 22:29 . 2007-11-26 22:30 110,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-11-26 22:29 . 2007-11-26 22:30 48,768 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-11-26 22:29 . 2007-11-26 22:30 8,014 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-11-26 22:29 . 2007-11-26 22:30 805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-11-26 22:28 . 2007-12-02 13:34 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2007-11-26 22:27 . 2007-11-26 22:27 <DIR> d-------- C:\temp\nav
2007-11-25 23:29 . 2007-11-28 22:38 4,298 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-23 15:53 . 2007-11-23 15:53 2,238 --a------ C:\WINDOWS\SYSTEM32\ClickToFindandFixErrors_US.ico
2007-11-23 15:47 . 2007-11-23 18:42 <DIR> d-------- C:\Program Files\Cool
2007-11-23 15:47 . 2007-11-23 15:47 1,149,472 --a------ C:\Install

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-01 18:42 --------- d-----w C:\Program Files\NJStar Communicator
2007-11-30 19:36 --------- d-----w C:\Documents and Settings\LEE.HOME\Application Data\Juniper Networks
2007-11-29 21:21 --------- d-----w C:\Program Files\MSN Messenger
2007-11-29 21:15 --------- d-----w C:\Program Files\iTunes
2007-11-29 21:15 --------- d-----w C:\Program Files\Google
2007-11-29 21:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-28 04:46 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-11-27 03:30 --------- d-----w C:\Program Files\Symantec
2007-11-27 03:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2007-11-27 03:07 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-23 23:46 --------- d-----w C:\Program Files\Canon
2007-11-23 05:08 --------- d-----w C:\Documents and Settings\LEE.HOME\Application Data\WeatherBug
2007-10-26 15:43 --------- d-----w C:\Program Files\Juniper Networks
2007-10-03 20:12 61,493 ----a-w C:\WINDOWS\SYSTEM32\dsGinaLoader.dll
2007-10-03 17:48 23,552 ----a-w C:\WINDOWS\system32\drivers\dsNcAdpt.sys
2007-09-06 21:14 1,086,952 ----a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2003-04-28 15:29 207,759 -c--a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 21:49]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 00:31]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 07:00]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 07:00]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 11:28]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-28 21:52]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-01-12 22:46:25]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-05-17 22:01:31]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 23:05:56]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-01-22 21:30:03]

R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;C:\oracle\ora81\BIN\ONRSD.EXE
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 SjyPkt;SjyPkt;\??\C:\WINDOWS\System32\Drivers\SjyPkt.sys
S3 Tomcat5;Apache Tomcat;"C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe" //RS//Tomcat5

.
Contents of the 'Scheduled Tasks' folder
"2007-11-29 18:15:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-02 13:34:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-nt.exe"
.
Completion time: 2007-12-02 13:36:21 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-02 11:27
.
--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:54 PM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Joyo - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: PowerWord - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\POWERW~1\XDictExB.dll
O9 - Extra button: PowerWord - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\POWERW~1\IEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Documentum Content Transfer 5.2.5 - http://zetes.gmu.edu/lcms/wdk/contentXfer/ContentXfer.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) - https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 12864 bytes

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 02 December 2007 - 05:49 PM

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
Exit Hijackthis.

Find and delete:
C:\Documents and Settings\LEE.HOME\Application Data\WeatherBug

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#8 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 02 December 2007 - 11:04 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/02/2007 at 10:43 PM

Application Version : 3.9.1008

Core Rules Database Version : 3353
Trace Rules Database Version: 1352

Scan type : Complete Scan
Total Scan Time : 01:13:50

Memory items scanned : 501
Memory threats detected : 0
Registry items scanned : 4935
Registry threats detected : 10
File items scanned : 61092
File threats detected : 60

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\InprocServer32
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\InprocServer32#ThreadingModel
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\ProgID
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\Programmable
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\TypeLib
HKCR\CLSID\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}\VersionIndependentProgID
C:\POWERW~1\IEPLUGIN.DLL
HKLM\Software\Microsoft\Internet Explorer\Extensions\{8DE0FCD4-5EB5-11D3-AD25-00002100131B}
C:\DOCUMENTS AND SETTINGS\LEE.HOME\DESKTOP\BACKUPS\BACKUP-20071128-000145-540.DLL

Adware.Tracking Cookie
C:\Documents and Settings\LEE.HOME\Cookies\lee@specificclick[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@realmedia[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@gcc[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads.adbrite[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@msnportal.112.2o7[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@rotator.adjuggler[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@tribalfusion[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@adserver[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@advertising[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@adopt.specificclick[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@indiads[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads.pointroll[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@tremor.adbureau[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@adlegend[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@richmedia.yahoo[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@optimost[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@mediaplex[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@trafficmp[3].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@adopt.euroclick[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@clicksor[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@questionmarket[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads.addynamix[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@revsci[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@www.burstbeacon[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@interclick[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@atdmt[3].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@path.pureadstracking[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@adbrite[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@tacoda[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads4.blastro[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads3.blastro[3].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ad.yieldmanager[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads.adbrite[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@ads3.blastro[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@apmebf[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@atdmt[2].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@doubleclick[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@electronicarts.112.2o7[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@rotator.adjuggler[1].txt
C:\Documents and Settings\LEE.HOME\Cookies\lee@trafficmp[2].txt

Adware.Vundo Variant
C:\DOCUMENTS AND SETTINGS\LEE.HOME\DESKTOP\BACKUPS\BACKUP-20071128-000145-153.DLL
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\GEDEGPAV\LPPOUFPU.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000007.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP7\A0001446.DLL

Adware.Vundo-Variant
C:\DOCUMENTS AND SETTINGS\LEE.HOME\DESKTOP\BACKUPS\BACKUP-20071128-000145-526.DLL
C:\DOCUMENTS AND SETTINGS\LEE.HOME\DESKTOP\BACKUPS\BACKUP-20071128-000316-755.DLL
C:\DOCUMENTS AND SETTINGS\LEE.HOME\DESKTOP\BACKUPS\BACKUP-20071128-000425-368.DLL

Trojan.Downloader-Gen/Cool
C:\PROGRAM FILES\COOL\COOL.DLL
C:\RECYCLER\NPROTECT\01383878.DLL

Trojan.Unclassified/DrvVeb
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRVBAK.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP7\A0001477.DLL

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000006.EXE

Malware.Ultimate Defender
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000008.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000009.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000010.EXE

Trojan.Downloader-Gen/TaLDrv
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP2\A0000019.EXE

Adware.AdHost/DR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{83BF3C68-EECB-41BA-8667-80BE3572D2C1}\RP6\A0001335.EXE


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:01:07 PM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: PowerWord - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\POWERW~1\XDictExB.dll
O9 - Extra button: PowerWord - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\POWERW~1\IEPlugin.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Documentum Content Transfer 5.2.5 - http://zetes.gmu.edu/lcms/wdk/contentXfer/ContentXfer.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) - https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 12915 bytes

#9 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 02 December 2007 - 11:09 PM

actually my pc has been running ok even before i started this topic, pop ups were gone after i installed zone alarm.

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 03 December 2007 - 04:43 AM

Click on Start/Run,copy and paste ComboFix /u into the 'Open:' space,then press Ok.

Posted Image

Clear your 'System Restore' points by doing the following:
Right-click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Select 'Turn Off System Restore On All Drives'.
Select 'Apply'.
You will then get the following warning:
"You have chosen to turn off System Restore.
If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.
Do you want to turn off System Restore?".
Then select 'Yes',your 'System Restore' directories will be purged.

Restart your pc.

Turn 'System Restore' back on:

Right click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Unselect 'Turn Off System Restore On All Drives'.
Select 'Apply',then click 'Ok'.

Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

You should copy/print the following because you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Scan with DrWeb-CureIt as follows:
* Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
* Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
* Once the short scan has finished, Click Options > Change settings
* Choose the "Scan tab" and UNcheck "Heuristic analysis"
* Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
* Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
* When done, a message will be displayed at the bottom advising if any viruses were found.
* Click "Yes to all" if it asks if you want to cure/move the file.
* When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
* Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
* Save the DrWeb.csv report to your desktop.
* Exit Dr.Web Cureit when done.
* Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
* After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Also post a new Hijackthis log.
Posted Image
Posted Image

#11 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 03 December 2007 - 05:37 PM

DrWeb.csv

Process.exe;C:\Documents and Settings\LEE.HOME\Desktop\SmitfraudFix;Tool.Prockill;Deleted.;
restart.exe;C:\Documents and Settings\LEE.HOME\Desktop\SmitfraudFix;Tool.ShutDown.11;Deleted.;

#12 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 03 December 2007 - 05:39 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:38:12 PM, on 12/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\LEE\Application Data\Mozilla\Profiles\default\5i6rnfdj.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: PowerWord - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\POWERW~1\XDictExB.dll
O9 - Extra button: PowerWord - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\POWERW~1\IEPlugin.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Documentum Content Transfer 5.2.5 - http://zetes.gmu.edu/lcms/wdk/contentXfer/ContentXfer.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {5EB6A98B-F75B-4AC7-821D-BAD2C29D18C2} (CVALAXObj Class) - https://autoins1.progressivedirect.com/ptt/cv/CVALAX.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.0\bin\tomcat5.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 12881 bytes

#13 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 03 December 2007 - 06:02 PM

Your log is clean :thumbsup: ,please do the following:

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:

Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

How to prevent Malware:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

So how did I get infected in the first place:
http://forums.spybot.info/showthread.php?t=279

Malware Cleanup Programs and Preventative Procedures:
http://russelltexas.com/malware/allclear.htm
Posted Image
Posted Image

#14 1010101

1010101
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:31 PM

Posted 03 December 2007 - 06:15 PM

thank you very much Richie!
may i ask one more question? in the hijackthis log, i saw this entry:
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

can you please tell me what it means and why it's there?

#15 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 03 December 2007 - 08:29 PM

File Name:
nwprovau.dll
Product Name:
Microsoft® Windows® Operating System

Client Service for NetWare Provider and Authentication Package DLL
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users