Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Annoying Ad Popups


  • This topic is locked This topic is locked
14 replies to this topic

#1 nielie

nielie

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 24 February 2008 - 04:17 PM

I'm getting ad popups most of them are telling me I have some kind of infection, click for a free scan. Some are win a free imac, etc. I've scanned my computer with everything i can get my hands on spybot, norton antivirus, adware 2007, windows defender, and so on... the problem is still there

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:58:47 PM, on 24/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\hphmon04.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...wlscbase370.cab
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

--
End of file - 6054 bytes

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 02:14 PM

Hello nielie,

NOTE: If you have downloaded SmitfraudFix previously please delete that version and download it again! Also delete C:\rapport.txt

Please download SmitfraudFix

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of the SmitfraudFix report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 28 February 2008 - 04:29 PM

Attached File  rapport.txt   222.77KB   20 downloads

Attached File  hijackthis.log   5.27KB   36 downloads

#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 04:33 PM

Hi nielie,



Please post the Hijackthis log, as the attached Hijackthis log is hard to read. Thanks. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 28 February 2008 - 04:43 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:24:39 PM, on 28/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...wlscbase370.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe

--
End of file - 5391 bytes

Sorry about that.

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 04:58 PM

Hi nielie,

You SmitfraudFix log is clean and I am not seeing malware in your Hijackthis log.


Lets look deeper and run ComboFix.

You need to disable your Avast Antivirus, Window Defender and Spybot Teatimer before running ComboFix, as they will prevent it from running.


to disable avast antivirus:
Right click on the avast! icon in system tray (looks like this: Posted Image) and choose (Stop On-Access Protection)

To disable Spybot's Teatimer:
Run Spybot-S&D
Go to the Mode menu, and make sure "Advanced Mode" is selected
On the left hand side, choose Tools -> Resident
Uncheck "Resident TeaTimer" and OK any prompts


To disable Windows Defender Real-time Protection
  • Open Windows Defender.
  • Click on Tools, General Settings.
  • Scroll down and uncheck Turn on real-time protection (recommended).
  • After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.





You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.

Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to install the Windows XP Recovery Console in case you have not installed it yet. <== IMPORTANT

We need Recovery Console because malware damages a lot and causes an instable system - and because of that, it may happen that your computer won't be able to boot anymore. With the Recovery Console installed, there are extra options present to repair whatever malware damaged.
Also, even though you're not infected, the presence of the Recovery Console is a useful feature in case a computer won't boot anymore because of several other reasons. Read here what you can do with the Recovery Console.

Extra note: After you have installed the Recovery Console - if you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well.
Don't select to run the Recovery Console as we don't need it.
By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows.


Post the ComboFix log.

Edited by SifuMike, 28 February 2008 - 04:59 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 28 February 2008 - 05:49 PM

ComboFix 08-02-25.3 - HP_Administrator 2008-02-28 17:38:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.547 [GMT -5:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\yksgpkuvns.dat
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\yksgpkuvns.exe
c:\Documents and Settings\HP_Administrator\Local Settings\Application Data\yksgpkuvns_nav.dat
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\yksgpkuvns_navps.dat
C:\Program Files\PopsMedia Site Adviser
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\_000017_.tmp.dll
C:\WINDOWS\system32\_000018_.tmp.dll
C:\WINDOWS\system32\_000019_.tmp.dll
C:\WINDOWS\system32\_000021_.tmp.dll
C:\WINDOWS\system32\_000022_.tmp.dll
C:\WINDOWS\system32\_000023_.tmp.dll
C:\WINDOWS\system32\_000024_.tmp.dll
C:\WINDOWS\system32\pskill.exe
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.

2008-02-25 19:33 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-25 19:33 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-25 19:33 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-25 19:33 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-25 19:33 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-25 19:33 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-25 19:32 . 2007-12-04 08:04 837,496 --a--c--- C:\WINDOWS\system32\aswBoot.exe
2008-02-25 19:32 . 2004-01-09 04:13 380,928 --a--c--- C:\WINDOWS\system32\actskin4.ocx
2008-02-25 19:12 . 2008-02-25 19:14 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-25 19:05 . 2008-02-25 19:05 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-25 18:43 . 2008-02-25 18:43 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-25 18:38 . 2008-02-25 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-24 22:20 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-02-24 21:00 . 2008-02-24 21:00 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinBatch
2008-02-23 17:46 . 2008-02-23 17:47 <DIR> d-------- C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-02-23 17:46 . 2008-02-23 17:46 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 12:02 . 2008-02-25 20:28 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-23 11:26 . 2008-02-23 17:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Antispyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2008-02-21 20:11 . 2008-02-21 20:11 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-02-21 19:57 . 2008-02-23 23:38 <DIR> d-------- C:\Program Files\Rogers
2008-02-21 19:57 . 2001-10-11 11:26 65,536 --a------ C:\WINDOWS\system32\YCRWin32.dll
2008-02-19 20:24 . 2008-02-19 20:24 <DIR> d-------- C:\Program Files\Defraggler
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Program Files\BillP Studios
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinPatrol
2008-02-17 23:12 . 2008-02-17 23:19 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Winamp
2008-02-17 20:05 . 2008-02-17 20:05 34 --a------ C:\hpfsched.ini
2008-02-17 20:00 . 2008-02-17 20:00 <DIR> d-------- C:\Program Files\HP Photosmart 11
2008-02-17 19:26 . 2008-02-17 19:59 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-17 19:26 . 2006-01-06 14:07 348,160 --a------ C:\WINDOWS\system32\hphmon04.exe
2008-02-17 19:26 . 2006-01-06 14:07 249,856 --a------ C:\WINDOWS\system32\hphsav04.exe
2008-02-17 19:26 . 2006-01-06 14:07 50,896 --a------ C:\WINDOWS\system32\drivers\hphid411.sys
2008-02-17 19:26 . 2006-01-06 14:07 50,276 --a------ C:\WINDOWS\system32\drivers\hphs2k11.sys
2008-02-17 19:26 . 2006-01-06 14:07 36,864 --a------ C:\WINDOWS\hpfsched.exe
2008-02-17 19:26 . 2006-01-06 14:07 18,928 --a------ C:\WINDOWS\system32\drivers\hphius11.sys
2008-02-17 19:26 . 2006-01-06 14:07 16,112 --a------ C:\WINDOWS\system32\drivers\hphipr11.sys
2008-02-17 19:25 . 2006-01-06 14:07 356,352 --a------ C:\WINDOWS\system32\Hphc3204.dll
2008-02-17 19:25 . 2006-01-06 14:07 185,344 --a------ C:\WINDOWS\system32\hpfinst.dll
2008-02-17 19:25 . 2006-01-06 14:07 98,304 --------- C:\WINDOWS\system32\hphidr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 81,920 --------- C:\WINDOWS\system32\hphipr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 77,824 --------- C:\WINDOWS\system32\hphipm11.exe
2008-02-17 19:25 . 2006-01-06 14:07 4,760 --------- C:\WINDOWS\hphmdl11.dat
2008-02-17 18:42 . 2008-02-08 17:30 262,144 --a------ C:\Program Files\Uninstall Spy Blocker.dll
2008-02-17 15:35 . 2008-02-17 15:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-17 15:27 . 2008-02-17 15:27 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-17 13:44 . 2008-02-17 13:45 <DIR> d-------- C:\Program Files\CCleaner
2008-02-17 13:00 . 2008-02-28 16:02 3,064 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-17 12:32 . 2008-02-17 12:32 <DIR> d-------- C:\VundoFix Backups
2008-02-17 08:22 . 2008-02-17 12:30 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-15 15:57 . 2008-02-25 18:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-08 19:54 . 2008-02-24 21:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-08 17:28 . 2008-02-25 18:49 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 17:28 . 2008-02-08 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-08 17:28 . 2008-02-24 22:22 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-08 17:26 . 2008-02-25 18:47 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\Infogrames Interactive
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\directx
2008-02-02 08:09 . 1996-08-26 02:12 345,600 -ra------ C:\WINDOWS\system32\QTIM32.DLL
2008-01-31 20:44 . 2008-01-31 20:47 1,065 --a------ C:\WINDOWS\winamp.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 01:01 --------- d-----w C:\Program Files\Yahoo!
2008-02-26 03:30 --------- d-----w C:\Program Files\Windows Live
2008-02-26 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-26 03:11 --------- d-----w C:\Program Files\music_now
2008-02-25 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 04:34 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-24 04:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-23 18:49 7,042 -c--a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-02-22 01:13 805 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-22 01:13 10,740 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-22 01:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-22 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-21 21:57 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-20 00:25 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\objloud
2008-02-20 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\part dead amok eggs
2008-02-19 00:59 --------- d-----w C:\Program Files\ClocX
2008-02-18 04:13 --------- d-----w C:\Program Files\Winamp
2008-02-17 18:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 13:33 --------- d-----w C:\Program Files\AtmosphereDeluxe5.4
2008-02-09 01:13 --------- d-----w C:\Program Files\BearShare
2008-02-08 01:57 --------- d-----w C:\Program Files\Atmosphere Deluxe
2008-02-05 21:54 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-02 13:17 --------- d-----w C:\Program Files\Hasbro Interactive
2008-01-27 16:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-27 16:51 --------- d-----w C:\Program Files\Broderbund
2008-01-25 22:52 --------- d-----w C:\Program Files\Audacity
2008-01-22 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\IProt
2008-01-21 22:12 --------- d-----w C:\Program Files\objloud
2008-01-13 21:50 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Avanquest
2008-01-13 17:23 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VCOM
2008-01-13 17:18 --------- d-----w C:\Program Files\VCOM
2008-01-13 17:18 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\VCOM
2008-01-13 17:14 --------- d-----w C:\Program Files\AutoMz
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-11 00:33 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-08 02:42 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-08 02:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-08 02:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-08 01:57 --------- d-----w C:\Program Files\MSN Messenger
2008-01-08 00:22 --------- d-----w C:\Program Files\Guitar Speed Trainer
2008-01-06 19:41 --------- d-----w C:\Program Files\iolo
2008-01-02 00:53 --------- d-----w C:\Program Files\Fisher-Price
2008-01-01 23:43 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Ahead
2007-12-19 23:01 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-08 15:51 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
2007-11-29 21:50 38,567 -c--a-w C:\WINDOWS\system32\pcpbios.exe
2006-02-19 17:28 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2006-10-21 21:24 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 15:30 136504]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-21 14:19 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ftutil2"="rundll32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 11:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 00:14 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 00:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 08:11 49152]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 14:07 188416]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 00:18 57344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 14:07 348160]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 9f578c97-8925-4141-a593-db9f090e412b;9f578c97-8925-4141-a593-db9f090e412b;C:\WINDOWS\iprot\9f578c97-8925-4141-a593-db9f090e412b\PhysMem.sys [2008-01-31 21:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\Launcher.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 08:00:00 C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware.ex
- C:\Program Files\AntiSpywareApp
"2007-09-25 03:59:53 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml
"2007-12-04 02:25:31 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2007-07-19 22:08:11 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2008-02-28 22:25:21 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-28 06:00:00 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 17:40:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-28 17:40:53
ComboFix-quarantined-files.txt 2008-02-28 22:40:51
.
2008-02-28 20:52:26 --- E O F ---


I've seen this yksgpkuvns thing pop up in zone alarm before trying to access the internet and I'd always block it. I did a search on it but nothing came up.

#8 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 06:29 PM

Hi nielie,

Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

Folder:: 
C:\VundoFix Backups
C:\Documents and Settings\All Users\Application Data\part dead amok eggs

DirLook::
C:\Program Files\objloud


Name the Notepad file CFScript.txt and Save it to your desktop.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Still getting popups?
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 28 February 2008 - 07:12 PM

Actually since I ran combofix the first time I haven't noticed any popups. I think that might have done it, but I did run it again just to be sure.



ComboFix 08-02-25.3 - HP_Administrator 2008-02-28 18:59:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.527 [GMT -5:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\part dead amok eggs
C:\VundoFix Backups

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.

2008-02-25 19:33 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-25 19:33 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-25 19:33 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-25 19:33 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-25 19:33 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-25 19:33 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-25 19:32 . 2007-12-04 08:04 837,496 --a--c--- C:\WINDOWS\system32\aswBoot.exe
2008-02-25 19:32 . 2004-01-09 04:13 380,928 --a--c--- C:\WINDOWS\system32\actskin4.ocx
2008-02-25 19:12 . 2008-02-28 17:43 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-25 19:05 . 2008-02-25 19:05 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-25 18:43 . 2008-02-25 18:43 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-25 18:38 . 2008-02-25 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-24 22:20 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-02-24 21:00 . 2008-02-24 21:00 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinBatch
2008-02-23 17:46 . 2008-02-23 17:47 <DIR> d-------- C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-02-23 17:46 . 2008-02-23 17:46 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 12:02 . 2008-02-25 20:28 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-23 11:26 . 2008-02-23 17:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Antispyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2008-02-21 20:11 . 2008-02-21 20:11 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-02-21 19:57 . 2008-02-23 23:38 <DIR> d-------- C:\Program Files\Rogers
2008-02-21 19:57 . 2001-10-11 11:26 65,536 --a------ C:\WINDOWS\system32\YCRWin32.dll
2008-02-19 20:24 . 2008-02-19 20:24 <DIR> d-------- C:\Program Files\Defraggler
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Program Files\BillP Studios
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinPatrol
2008-02-17 23:12 . 2008-02-17 23:19 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Winamp
2008-02-17 20:05 . 2008-02-17 20:05 34 --a------ C:\hpfsched.ini
2008-02-17 20:00 . 2008-02-17 20:00 <DIR> d-------- C:\Program Files\HP Photosmart 11
2008-02-17 19:26 . 2008-02-17 19:59 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-17 19:26 . 2006-01-06 14:07 348,160 --a------ C:\WINDOWS\system32\hphmon04.exe
2008-02-17 19:26 . 2006-01-06 14:07 249,856 --a------ C:\WINDOWS\system32\hphsav04.exe
2008-02-17 19:26 . 2006-01-06 14:07 50,896 --a------ C:\WINDOWS\system32\drivers\hphid411.sys
2008-02-17 19:26 . 2006-01-06 14:07 50,276 --a------ C:\WINDOWS\system32\drivers\hphs2k11.sys
2008-02-17 19:26 . 2006-01-06 14:07 36,864 --a------ C:\WINDOWS\hpfsched.exe
2008-02-17 19:26 . 2006-01-06 14:07 18,928 --a------ C:\WINDOWS\system32\drivers\hphius11.sys
2008-02-17 19:26 . 2006-01-06 14:07 16,112 --a------ C:\WINDOWS\system32\drivers\hphipr11.sys
2008-02-17 19:25 . 2006-01-06 14:07 356,352 --a------ C:\WINDOWS\system32\Hphc3204.dll
2008-02-17 19:25 . 2006-01-06 14:07 185,344 --a------ C:\WINDOWS\system32\hpfinst.dll
2008-02-17 19:25 . 2006-01-06 14:07 98,304 --------- C:\WINDOWS\system32\hphidr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 81,920 --------- C:\WINDOWS\system32\hphipr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 77,824 --------- C:\WINDOWS\system32\hphipm11.exe
2008-02-17 19:25 . 2006-01-06 14:07 4,760 --------- C:\WINDOWS\hphmdl11.dat
2008-02-17 18:42 . 2008-02-08 17:30 262,144 --a------ C:\Program Files\Uninstall Spy Blocker.dll
2008-02-17 15:35 . 2008-02-17 15:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-17 15:27 . 2008-02-17 15:27 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-17 13:44 . 2008-02-17 13:45 <DIR> d-------- C:\Program Files\CCleaner
2008-02-17 13:00 . 2008-02-28 16:02 3,064 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-17 08:22 . 2008-02-17 12:30 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-15 15:57 . 2008-02-25 18:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-08 19:54 . 2008-02-24 21:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-08 17:28 . 2008-02-25 18:49 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 17:28 . 2008-02-08 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-08 17:28 . 2008-02-24 22:22 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-08 17:26 . 2008-02-25 18:47 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\Infogrames Interactive
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\directx
2008-02-02 08:09 . 1996-08-26 02:12 345,600 -ra------ C:\WINDOWS\system32\QTIM32.DLL
2008-01-31 20:44 . 2008-01-31 20:47 1,065 --a------ C:\WINDOWS\winamp.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 01:01 --------- d-----w C:\Program Files\Yahoo!
2008-02-26 03:30 --------- d-----w C:\Program Files\Windows Live
2008-02-26 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-26 03:11 --------- d-----w C:\Program Files\music_now
2008-02-25 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 04:34 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-24 04:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-23 18:49 7,042 -c--a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-02-22 01:13 805 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-22 01:13 10,740 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-22 01:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-22 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-21 21:57 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-20 00:25 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\objloud
2008-02-19 00:59 --------- d-----w C:\Program Files\ClocX
2008-02-18 04:13 --------- d-----w C:\Program Files\Winamp
2008-02-17 18:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 13:33 --------- d-----w C:\Program Files\AtmosphereDeluxe5.4
2008-02-09 01:13 --------- d-----w C:\Program Files\BearShare
2008-02-08 01:57 --------- d-----w C:\Program Files\Atmosphere Deluxe
2008-02-05 21:54 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-02 13:17 --------- d-----w C:\Program Files\Hasbro Interactive
2008-01-27 16:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-27 16:51 --------- d-----w C:\Program Files\Broderbund
2008-01-25 22:52 --------- d-----w C:\Program Files\Audacity
2008-01-22 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\IProt
2008-01-21 22:12 --------- d-----w C:\Program Files\objloud
2008-01-13 21:50 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Avanquest
2008-01-13 17:23 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VCOM
2008-01-13 17:18 --------- d-----w C:\Program Files\VCOM
2008-01-13 17:18 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\VCOM
2008-01-13 17:14 --------- d-----w C:\Program Files\AutoMz
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-11 00:33 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-08 02:42 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-08 02:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-08 02:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-08 01:57 --------- d-----w C:\Program Files\MSN Messenger
2008-01-08 00:22 --------- d-----w C:\Program Files\Guitar Speed Trainer
2008-01-06 19:41 --------- d-----w C:\Program Files\iolo
2008-01-02 00:53 --------- d-----w C:\Program Files\Fisher-Price
2008-01-01 23:43 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Ahead
2007-12-19 23:01 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-08 15:51 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
2007-11-29 21:50 38,567 -c--a-w C:\WINDOWS\system32\pcpbios.exe
2006-02-19 17:28 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2006-10-21 21:24 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Program Files\objloud ----



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 15:30 136504]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-21 14:19 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ftutil2"="rundll32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 11:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 00:14 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 00:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 08:11 49152]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 14:07 188416]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 00:18 57344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 14:07 348160]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 9f578c97-8925-4141-a593-db9f090e412b;9f578c97-8925-4141-a593-db9f090e412b;C:\WINDOWS\iprot\9f578c97-8925-4141-a593-db9f090e412b\PhysMem.sys [2008-01-31 21:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\Launcher.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 08:00:00 C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware.ex
- C:\Program Files\AntiSpywareApp
"2007-09-25 03:59:53 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml
"2007-12-04 02:25:31 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2007-07-19 22:08:11 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2008-02-28 22:25:21 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-28 06:00:00 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 19:01:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-28 19:01:40
ComboFix-quarantined-files.txt 2008-02-29 00:01:39
ComboFix2.txt 2008-02-28 22:40:53
.
2008-02-28 20:52:26 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:42 PM, on 28/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...wlscbase370.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe

--
End of file - 5299 bytes

#10 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 09:26 PM

Hi nielie,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 4.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language jre-6-windows-i586.exe and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Examples of older versions in Add or Remove Programs:
    Java 2 Runtime Environment, SE v1.4.2
    J2SE Runtime Environment 5.0
    J2SE Runtime Environment 5.0 Update 6
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.



Lets get rid of one folder.

Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

Folder:: 
C:\Program Files\objloud


Name the Notepad file CFScript.txt and Save it to your desktop.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt and a fresh Hijackthis log.

Edited by SifuMike, 28 February 2008 - 09:30 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 28 February 2008 - 10:06 PM

ComboFix 08-02-25.3 - HP_Administrator 2008-02-28 21:55:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.583 [GMT -5:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\objloud

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-28 21:50 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-25 19:33 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-25 19:33 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-25 19:33 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-25 19:33 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-25 19:33 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-25 19:33 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-25 19:32 . 2007-12-04 08:04 837,496 --a--c--- C:\WINDOWS\system32\aswBoot.exe
2008-02-25 19:32 . 2004-01-09 04:13 380,928 --a--c--- C:\WINDOWS\system32\actskin4.ocx
2008-02-25 19:12 . 2008-02-28 19:04 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-25 19:05 . 2008-02-25 19:05 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-25 18:43 . 2008-02-25 18:43 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-25 18:38 . 2008-02-25 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-24 22:20 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-02-24 21:00 . 2008-02-24 21:00 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinBatch
2008-02-23 17:46 . 2008-02-23 17:47 <DIR> d-------- C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-02-23 17:46 . 2008-02-23 17:46 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 12:02 . 2008-02-25 20:28 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-23 11:26 . 2008-02-23 17:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Antispyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-21 22:23 . 2008-02-25 20:29 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2008-02-21 20:11 . 2008-02-21 20:11 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-02-21 19:57 . 2008-02-23 23:38 <DIR> d-------- C:\Program Files\Rogers
2008-02-21 19:57 . 2001-10-11 11:26 65,536 --a------ C:\WINDOWS\system32\YCRWin32.dll
2008-02-19 20:24 . 2008-02-19 20:24 <DIR> d-------- C:\Program Files\Defraggler
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Program Files\BillP Studios
2008-02-18 19:40 . 2008-02-18 19:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WinPatrol
2008-02-17 23:12 . 2008-02-17 23:19 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Winamp
2008-02-17 20:05 . 2008-02-17 20:05 34 --a------ C:\hpfsched.ini
2008-02-17 20:00 . 2008-02-17 20:00 <DIR> d-------- C:\Program Files\HP Photosmart 11
2008-02-17 19:26 . 2008-02-17 19:59 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-17 19:26 . 2006-01-06 14:07 348,160 --a------ C:\WINDOWS\system32\hphmon04.exe
2008-02-17 19:26 . 2006-01-06 14:07 249,856 --a------ C:\WINDOWS\system32\hphsav04.exe
2008-02-17 19:26 . 2006-01-06 14:07 50,896 --a------ C:\WINDOWS\system32\drivers\hphid411.sys
2008-02-17 19:26 . 2006-01-06 14:07 50,276 --a------ C:\WINDOWS\system32\drivers\hphs2k11.sys
2008-02-17 19:26 . 2006-01-06 14:07 36,864 --a------ C:\WINDOWS\hpfsched.exe
2008-02-17 19:26 . 2006-01-06 14:07 18,928 --a------ C:\WINDOWS\system32\drivers\hphius11.sys
2008-02-17 19:26 . 2006-01-06 14:07 16,112 --a------ C:\WINDOWS\system32\drivers\hphipr11.sys
2008-02-17 19:25 . 2006-01-06 14:07 356,352 --a------ C:\WINDOWS\system32\Hphc3204.dll
2008-02-17 19:25 . 2006-01-06 14:07 185,344 --a------ C:\WINDOWS\system32\hpfinst.dll
2008-02-17 19:25 . 2006-01-06 14:07 98,304 --------- C:\WINDOWS\system32\hphidr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 81,920 --------- C:\WINDOWS\system32\hphipr11.dll
2008-02-17 19:25 . 2006-01-06 14:07 77,824 --------- C:\WINDOWS\system32\hphipm11.exe
2008-02-17 19:25 . 2006-01-06 14:07 4,760 --------- C:\WINDOWS\hphmdl11.dat
2008-02-17 18:42 . 2008-02-08 17:30 262,144 --a------ C:\Program Files\Uninstall Spy Blocker.dll
2008-02-17 15:35 . 2008-02-17 15:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-17 15:27 . 2008-02-17 15:27 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-17 13:44 . 2008-02-17 13:45 <DIR> d-------- C:\Program Files\CCleaner
2008-02-17 13:00 . 2008-02-28 16:02 3,064 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-17 08:22 . 2008-02-17 12:30 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-15 15:57 . 2008-02-25 18:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-08 19:54 . 2008-02-24 21:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-08 17:28 . 2008-02-25 18:49 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 17:28 . 2008-02-08 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-08 17:28 . 2008-02-24 22:22 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-08 17:26 . 2008-02-25 18:47 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\Infogrames Interactive
2008-02-02 20:38 . 2008-02-02 20:38 <DIR> d-------- C:\Program Files\directx
2008-02-02 08:09 . 1996-08-26 02:12 345,600 -ra------ C:\WINDOWS\system32\QTIM32.DLL
2008-01-31 20:44 . 2008-01-31 20:47 1,065 --a------ C:\WINDOWS\winamp.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 02:50 --------- d-----w C:\Program Files\Java
2008-02-27 01:01 --------- d-----w C:\Program Files\Yahoo!
2008-02-26 03:30 --------- d-----w C:\Program Files\Windows Live
2008-02-26 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-26 03:11 --------- d-----w C:\Program Files\music_now
2008-02-25 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 04:34 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-24 04:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-23 18:49 7,042 -c--a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-02-22 01:13 805 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-22 01:13 10,740 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-22 01:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-22 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-21 21:57 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-20 00:25 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\objloud
2008-02-19 00:59 --------- d-----w C:\Program Files\ClocX
2008-02-18 04:13 --------- d-----w C:\Program Files\Winamp
2008-02-17 18:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 13:33 --------- d-----w C:\Program Files\AtmosphereDeluxe5.4
2008-02-09 01:13 --------- d-----w C:\Program Files\BearShare
2008-02-08 01:57 --------- d-----w C:\Program Files\Atmosphere Deluxe
2008-02-05 21:54 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-02 13:17 --------- d-----w C:\Program Files\Hasbro Interactive
2008-01-27 16:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-27 16:51 --------- d-----w C:\Program Files\Broderbund
2008-01-25 22:52 --------- d-----w C:\Program Files\Audacity
2008-01-22 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\IProt
2008-01-13 21:50 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Avanquest
2008-01-13 17:23 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VCOM
2008-01-13 17:18 --------- d-----w C:\Program Files\VCOM
2008-01-13 17:18 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\VCOM
2008-01-13 17:14 --------- d-----w C:\Program Files\AutoMz
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-11 00:33 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-08 02:42 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-08 02:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-08 02:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-08 01:57 --------- d-----w C:\Program Files\MSN Messenger
2008-01-08 00:22 --------- d-----w C:\Program Files\Guitar Speed Trainer
2008-01-06 19:41 --------- d-----w C:\Program Files\iolo
2008-01-02 00:53 --------- d-----w C:\Program Files\Fisher-Price
2008-01-01 23:43 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Ahead
2007-12-19 23:01 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-08 15:51 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
2007-11-29 21:50 38,567 -c--a-w C:\WINDOWS\system32\pcpbios.exe
2006-02-19 17:28 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2006-10-21 21:24 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 15:30 136504]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-21 14:19 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ftutil2"="rundll32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 11:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 00:14 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 00:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 08:11 49152]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 14:07 188416]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 00:18 57344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 14:07 348160]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 9f578c97-8925-4141-a593-db9f090e412b;9f578c97-8925-4141-a593-db9f090e412b;C:\WINDOWS\iprot\9f578c97-8925-4141-a593-db9f090e412b\PhysMem.sys [2008-01-31 21:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\Launcher.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 08:00:00 C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware.ex
- C:\Program Files\AntiSpywareApp
"2007-09-25 03:59:53 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml
"2007-12-04 02:25:31 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2007-07-19 22:08:11 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2008-02-29 02:51:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-28 06:00:00 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 21:57:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-28 21:57:39
ComboFix-quarantined-files.txt 2008-02-29 02:57:37
ComboFix2.txt 2008-02-29 00:01:41
ComboFix3.txt 2008-02-28 22:40:53
.
2008-02-28 20:52:26 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:55 PM, on 28/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...wlscbase370.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe

--
End of file - 5523 bytes

#12 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 28 February 2008 - 10:58 PM

Hi nielie,

Your log looks clean! :thumbsup: Good job on the cleanup!

Uninstall ComboFix, go to to Start > Run & type in ComboFix /u
Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete any of its related folders and files (Qoobox
VundoFix Backups, Avenger, Deckard, _OTMoveIt), reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Please read and follow How did I get infected?, With steps so it does not happen again!
as well as
How to prevent Malware' by miekiemoes


If you want to improve speed/system performance after malware removal, take a look here.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 nielie

nielie
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:55 AM

Posted 29 February 2008 - 10:37 AM

Thank you so much for your help, up until a couple of weeks ago I never realized you could have problems like this that were so difficult to remove. I spent the last week and a half scanning with different antispyware and antivirus programs and couldn't find the problem. So I'll definitely be reading up on prevention and hopefully this won't happen again. So thanks again and I will recommend this site to anyone. :wacko: :blink: :thumbsup:

#14 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 29 February 2008 - 02:11 PM

Thank you for the kind words..
It's always nice to hear that someone appreciates the help we are giving. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:55 AM

Posted 07 March 2008 - 10:20 PM

Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users