Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack Log


  • This topic is locked This topic is locked
15 replies to this topic

#1 gembob

gembob

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 24 May 2008 - 01:13 AM

So I'm trying to fix my sisters computer. Can't browse any webpages, goes wherever it wants. Her background is all screwed up with ads and tons of pop ups. Any help would be apprecaited.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:11:32 PM, on 5/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: {da10c892-42d5-1448-2de4-4b80e83b6840} - {0486b38e-08b4-4ed2-8441-5d24298c01ad} - C:\WINDOWS\system32\crtaunjt.dll
O2 - BHO: (no name) - {416B76E2-74C1-42CB-BDEE-49D78A9B40E7} - C:\WINDOWS\system32\qoMdEVop.dll
O2 - BHO: (no name) - {6B5DE51F-FD43-455F-AB52-4D921CD1CE98} - C:\WINDOWS\system32\iiffFwtt.dll
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINDOWS\system32\geBuTKca.dll
O2 - BHO: (no name) - {CCD240AF-8143-A4E7-4293-D18F0F242E90} - C:\WINDOWS\system32\zqhe.dll
O2 - BHO: (no name) - {D24A5135-5D3C-4408-AEB0-A3A31D3520AE} - C:\WINDOWS\system32\qoMeDUNd.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [{33-3C-C0-0C-DW}] C:\windows\system32\rwwnw64d.exe DWram
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\tcntskdm.exe DWram
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [3c933ca3] rundll32.exe "C:\WINDOWS\system32\foyycssg.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O20 - Winlogon Notify: geBuTKca - C:\WINDOWS\SYSTEM32\geBuTKca.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 6691 bytes

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 24 May 2008 - 07:30 AM

Hi,

I understand that you need help in order to get rid of the malware that is present on your system - But you need to help us first..
I notice that you never scanned with an Antivirus previously before starting this thread - because you don't even have an Antivirus installed!
This is somewhat suicidal in today's digital world.
That's why I want you to install one first!!

* Please install Avira Antivirus: http://www.free-av.com/
This is a free Antivirus.

Perform a full scan with Avira and let it delete everything it is finding.
Then reboot.
After reboot, open your Avira and select "reports".
There doubleclick the report from the Full scan you have done. Click the "Report File" button and copy and paste this report in your next reply together with a new HijackThislog.
Then we'll start from there, because it really makes no sense otherwise that we clean this up manually if an Antivirusscan is not present which should be able to deal with most and prevent further reinfection.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 24 May 2008 - 03:34 PM

I actulaly did scan it with AVG, I have also used Spybot S&D, Ad-Aware, CW Shredder and Trojan Remover, Stinger, and the Netsky fixer tool

Edited by gembob, 24 May 2008 - 03:34 PM.


#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 24 May 2008 - 11:30 PM

Hi,

You are running AVG Antispyware - This is no Antivirus. That's why an active Antivirus is really needed.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 25 May 2008 - 04:52 PM

Okay I ran Avira and let it delete what it found, so here are the new logs from Avira and the new Hijack log:



Avira AntiVir Personal
Report file date: Sunday, May 25, 2008 14:33

Scanning for 1165085 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Administrator
Computer name: LINDSEYS

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 4/9/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 3/18/2008 17:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2/7/2008 16:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 2/28/2008 16:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 2/21/2008 16:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 18:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 3/7/2008 21:08:58
ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 3/21/2008 03:12:34
ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 3/25/2008 16:27:50
Engineversion : 8.1.0.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 17:58:21
AESCRIPT.DLL : 8.1.0.19 229754 Bytes 4/7/2008 23:34:44
AESCN.DLL : 8.1.0.12 115060 Bytes 4/7/2008 23:34:44
AERDL.DLL : 8.1.0.19 418164 Bytes 4/7/2008 23:34:44
AEPACK.DLL : 8.1.1.0 364918 Bytes 3/18/2008 19:20:42
AEOFFICE.DLL : 8.1.0.15 192889 Bytes 4/7/2008 23:34:44
AEHEUR.DLL : 8.1.0.15 1147253 Bytes 4/7/2008 23:34:44
AEHELP.DLL : 8.1.0.11 115061 Bytes 4/7/2008 23:34:43
AEGEN.DLL : 8.1.0.15 299379 Bytes 4/7/2008 23:34:43
AEEMU.DLL : 8.1.0.5 430450 Bytes 4/7/2008 23:34:43
AECORE.DLL : 8.1.0.25 168309 Bytes 4/8/2008 17:58:32
AVWINLL.DLL : 1.0.0.7 14593 Bytes 1/24/2008 01:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 2/18/2008 18:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 21:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 1/24/2008 01:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 16:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2/28/2008 16:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 01:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 1/24/2008 01:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 20:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 3/10/2008 22:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 3/6/2008 20:02:11

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: Sunday, May 25, 2008 14:33

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
15 processes with 15 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
C:\WINDOWS\SYSTEM32\rwwnw64d.exe
[DETECTION] Contains suspicious code HEUR/Malware
[NOTE] The fund was classified as suspicious.
[NOTE] HEUR/Malware:[HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN]:<{33-3C-C0-0C-DW}>=sz:rwwnw64d.exe
[NOTE] The file was moved to '48b0cdc6.qua'!
C:\WINDOWS\SYSTEM32\foyycssg.dll
[WARNING] The file could not be opened!
The registry was scanned ( '41' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\audiodev.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\blackbox.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\cewmdm.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\drmupgds.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\drmv2clt.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\laprxy.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\logagent.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mfplat.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mp43decd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mp43dmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mp4sdecd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mp4sdmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mpg4decd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mpg4dmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\msnetobj.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mspmsnsv.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mspmsp.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\msscp.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\mswmdm.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\portabledeviceapi.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\portabledeviceclassextension.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\portabledevicetypes.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\portabledevicewiacompat.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\portabledevicewmdrm.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\qasf.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\spuninst.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\spupdsvc.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\uwdf.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wdfapi.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wdfmgr.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmadmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmadmoe.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmasf.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmdmlog.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmdmps.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmdrmdev.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmdrmnet.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmdrmsdk.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmidx.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmnetmgr.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmsdmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmsdmoe2.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmsetsdk.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmspdmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmspdmoe.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvadvd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvadve.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvcore.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvdecod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvdmod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvdmoe2.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvencod.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvsdecd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvsencd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wmvxencd.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdconns.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdinstallutil.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdmtp.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdmtpdr.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdmtpus.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdshext.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdshextautoplay.exe
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdshserviceobj.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdsp.dll
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpdusb.sys
[WARNING] The file could not be opened!
C:\be3ed68a0ca6efdaf4da65a7fed053\wpd_ci.dll
[WARNING] The file could not be opened!
C:\WINDOWS\mrofinu1000106.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\mrofinu572.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\mrofinu72.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\SYSTEM32\bgjcrgal.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\bgjfijcf.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\bjesevwo.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\caexdxhv.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\cjxjdmpo.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\crtaunjt.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\csumwfhb.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\ctabnqbl.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\dxxjspis.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\foyycssg.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\hgqfolpw.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\jqwnw64k.exe
[DETECTION] Contains suspicious code HEUR/Malware
[NOTE] The fund was classified as suspicious.
[NOTE] The file was moved to '48b0db15.qua'!
C:\WINDOWS\SYSTEM32\jrwnw64l.exe
[DETECTION] Contains suspicious code HEUR/Malware
[NOTE] The fund was classified as suspicious.
[NOTE] The file was moved to '48b0db16.qua'!
C:\WINDOWS\SYSTEM32\lgscxnlr.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\nwimtaso.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\petrykoj.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\pvcbeqyr.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\pyuxayjn.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\qcbutmjo.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\qmkglewb.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\qxxntpmi.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\vovcqtlu.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\xqtroijf.dll
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\binR\Wvram13.exe
[DETECTION] Contains suspicious code HEUR/Malware
[NOTE] The fund was classified as suspicious.
[NOTE] The file was moved to '48abdb84.qua'!


End of the scan: Sunday, May 25, 2008 15:35
Used time: 1:01:21 min

The scan has been done completely.

3781 Scanning directories
278846 Files were scanned
3 viruses and/or unwanted programs were found
4 Files were classified as suspicious:
3 files were deleted
0 files were repaired
4 files were moved to quarantine
0 files were renamed
89 Files cannot be scanned
278843 Files not concerned
8325 Archives were scanned
89 Warnings
7 Notes


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:42:41 PM, on 5/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
c:\program files\avira\antivir personaledition classic\avscan.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0486b38e-08b4-4ed2-8441-5d24298c01ad} - C:\WINDOWS\system32\crtaunjt.dll
O2 - BHO: (no name) - {416B76E2-74C1-42CB-BDEE-49D78A9B40E7} - C:\WINDOWS\system32\qoMdEVop.dll
O2 - BHO: (no name) - {6B5DE51F-FD43-455F-AB52-4D921CD1CE98} - C:\WINDOWS\system32\iiffFwtt.dll
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINDOWS\system32\geBuTKca.dll
O2 - BHO: (no name) - {CCD240AF-8143-A4E7-4293-D18F0F242E90} - C:\WINDOWS\system32\zqhe.dll
O2 - BHO: (no name) - {D24A5135-5D3C-4408-AEB0-A3A31D3520AE} - C:\WINDOWS\system32\qoMeDUNd.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\tcntskdm.exe DWram
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [3c933ca3] rundll32.exe "C:\WINDOWS\system32\foyycssg.dll",b
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O20 - Winlogon Notify: geBuTKca - C:\WINDOWS\SYSTEM32\geBuTKca.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 8055 bytes

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 26 May 2008 - 12:57 AM

Hi,

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 26 May 2008 - 01:01 PM

Okay I have tried and tried and I can't get combofix to run. I've tried downloading it from different places, in safe mode and in regular mode. I've made sure that no firewall or other virus/spyware scanners are running, that the screen saver wasn't on and still nothing.

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 26 May 2008 - 01:06 PM

What errors are you getting?
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 26 May 2008 - 01:22 PM

Also, let me know if it works if you rename Combofix.exe to for example gembob.exe and run gembob.exe then.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#10 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 26 May 2008 - 07:54 PM

Okay I renamed it and it worked, the first time I ran ComboFix though I forgot to stop the other Anti-virus/malware programs and it froze up, but it created a log file when I restarted, so that is the first one posted (Combofix_Log1). I stopped them and reran it and that is the second posted log file (Combofix_Log2). I also reran Hijack this and that log is posted last.

Combofix_Log1

ComboFix 08-05-25.5 - Lindsey 2008-05-26 17:28:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.157 [GMT -6:00]
Running from: C:\Documents and Settings\Lindsey\Desktop\gembob.exe
Command switches used :: C:\Documents and Settings\Lindsey\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Lindsey\My Documents\SMANTE~1
C:\Documents and Settings\Lindsey\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Lindsey\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Lindsey\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\asks~1
C:\Program Files\BulletProofSoft.com
C:\Program Files\BulletProofSoft.com\SpywareRemover\errorlog.txt
C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyLog23-05-08-75368.txt
C:\Program Files\Common Files\system32.dll
C:\Program Files\Common Files\uninstall information
C:\Program Files\winvi
C:\Program Files\winvi\dsktp\AC_RunActiveContent.js
C:\Program Files\winvi\dsktp\desktop.html
C:\Program Files\winvi\dsktp\internetDetection.swf
C:\Program Files\winvi\dsktp\settings.sol
C:\Program Files\winvi\temp\version.ini
C:\Program Files\winvi\version.ini
C:\Program Files\winvi\wupda.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\BM3fa00f3f.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\000060.exe
C:\WINDOWS\SYSTEM32\000090.exe
C:\WINDOWS\system32\bgjcrgal.dll
C:\WINDOWS\system32\bgjfijcf.dll
C:\WINDOWS\system32\ccittjjy.ini
C:\WINDOWS\SYSTEM32\cdtxangt.ini
C:\WINDOWS\system32\cjxjdmpo.dll
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\SYSTEM32\dNUDeMoq.ini
C:\WINDOWS\SYSTEM32\dNUDeMoq.ini2
C:\WINDOWS\system32\drivers\CD20XRNTT.sys
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\geBuTKca.dll
C:\WINDOWS\system32\gsscyyof.ini
C:\WINDOWS\system32\hgqfolpw.dll
C:\WINDOWS\system32\iiffFwtt.dll
C:\WINDOWS\system32\iuqhaptg.ini
C:\WINDOWS\system32\lgscxnlr.dll
C:\WINDOWS\system32\mrucvxfr.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nweivuku.ini
C:\WINDOWS\system32\nxneyuvx.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\poVEdMoq.ini
C:\WINDOWS\SYSTEM32\poVEdMoq.ini2
C:\WINDOWS\system32\pxwcpwws.ini
C:\WINDOWS\system32\pyuxayjn.dll
C:\WINDOWS\system32\qcbutmjo.dll
C:\WINDOWS\system32\qoMdEVop.dll
C:\WINDOWS\system32\qoMeDUNd.dll
C:\WINDOWS\system32\siirxikt.ini
C:\WINDOWS\system32\tiahphuw.ini
C:\WINDOWS\SYSTEM32\ttwFffii.ini
C:\WINDOWS\SYSTEM32\ttwFffii.ini2
C:\WINDOWS\system32\ukuviewn.dll
C:\WINDOWS\system32\xqtroijf.dll
C:\WINDOWS\system32\yayyWNDw.dll
C:\WINDOWS\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CD20XRNTT
-------\Legacy_CLBDRIVER
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Service_CD20XRNTT


((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.

2008-05-26 11:00 . 2008-05-26 11:00 90,896 --a------ C:\WINDOWS\SYSTEM32\vrpcvmvc.dll
2008-05-26 02:04 . 2008-05-26 02:04 100,608 --a------ C:\WINDOWS\SYSTEM32\xqxvptcj.dll
2008-05-26 02:01 . 2008-05-26 02:01 2,560 --a------ C:\WINDOWS\SYSTEM32\lsylkjet.exe
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Program Files\Avira
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-24 00:04 . 2008-05-24 00:04 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-24 00:04 . 2008-05-24 00:09 <DIR> d-------- C:\Program Files\CCleaner
2008-05-23 23:32 . 2008-05-25 15:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 23:28 . 2008-05-23 23:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-05-23 23:11 . 2008-05-23 23:11 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 22:40 . 2008-05-23 22:41 100,608 --a------ C:\WINDOWS\SYSTEM32\crtaunjt.dll
2008-05-23 22:37 . 2008-05-23 22:37 2,560 --a------ C:\WINDOWS\SYSTEM32\ctabnqbl.exe
2008-05-23 22:32 . 2008-05-23 22:32 91,008 --a------ C:\WINDOWS\SYSTEM32\dxxjspis.dll
2008-05-23 22:30 . 2008-05-23 22:30 91,008 --a------ C:\WINDOWS\SYSTEM32\csumwfhb.dll
2008-05-23 22:24 . 2008-05-26 17:59 <DIR> d-------- C:\Documents and Settings\Lindsey\Application Data\uTorrent
2008-05-23 20:41 . 2008-05-23 20:41 100,608 --a------ C:\WINDOWS\SYSTEM32\caexdxhv.dll
2008-05-23 17:54 . 2008-05-23 17:56 <DIR> d-------- C:\Program Files\Internet Spy Hunter
2008-05-23 17:08 . 2008-05-23 17:08 200,774 --a------ C:\WINDOWS\SYSTEM32\lcntmkdm.exe
2008-05-23 17:08 . 2008-05-23 17:08 88,961 --a------ C:\WINDOWS\SYSTEM32\mysidesearch_sidebar_uninstall.exe
2008-05-23 17:07 . 2008-05-24 00:15 <DIR> d-------- C:\Program Files\Trojan Remover
2008-05-23 17:07 . 2008-05-23 17:07 100,608 --a------ C:\WINDOWS\SYSTEM32\petrykoj.dll
2008-05-23 17:07 . 2008-05-23 17:07 2,560 --a------ C:\WINDOWS\SYSTEM32\vovcqtlu.exe
2008-05-23 17:05 . 2008-05-23 17:05 91,008 --a------ C:\WINDOWS\SYSTEM32\qmkglewb.dll
2008-05-23 07:29 . 2008-05-23 07:29 223,805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
2008-05-22 23:02 . 2008-05-22 23:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-05-18 22:36 . 2008-05-18 22:36 9,662 --a------ C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
2008-05-18 22:36 . 2008-05-18 22:36 4,286 --a------ C:\WINDOWS\SYSTEM32\Jamster.ico
2008-05-18 22:26 . 2008-05-18 22:26 401,972 --a------ C:\WINDOWS\SYSTEM32\g89.exe
2008-05-18 22:26 . 2008-05-18 22:26 200,768 --a------ C:\WINDOWS\SYSTEM32\ocntrkdm.exe
2008-05-18 16:57 . 2008-05-18 16:58 401,964 --a------ C:\WINDOWS\SYSTEM32\g78.exe
2008-05-18 16:31 . 2008-05-18 16:31 2,048 --a------ C:\WINDOWS\SYSTEM32\qxxntpmi.exe
2008-05-18 13:04 . 2008-05-18 13:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\logXv01
2008-05-18 12:41 . 2008-05-18 12:41 2,048 --a------ C:\WINDOWS\SYSTEM32\pvcbeqyr.exe
2008-05-18 12:33 . 2008-05-18 12:33 <DIR> d-------- C:\Program Files\uTorrent
2008-05-18 12:33 . 2004-08-04 04:00 4,224 --a------ C:\WINDOWS\SYSTEM32\beep.sys
2008-05-18 12:33 . 2008-05-23 22:48 860 --a------ C:\WINDOWS\SYSTEM32\winpfz33.sys
2008-05-18 12:32 . 2008-05-18 18:22 <DIR> d--hs---- C:\WINDOWS\TGluZHNleQ
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\polX
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\logXv06
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\GUI2
2008-05-18 12:32 . 2008-05-25 15:33 <DIR> d-------- C:\WINDOWS\SYSTEM32\binR
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\3036a
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\Temp\dmpxp32
2008-05-18 12:32 . 2008-05-18 12:32 298,311 --a------ C:\WINDOWS\SYSTEM32\gside.exe
2008-05-18 12:32 . 2008-05-18 12:32 200,768 --a------ C:\WINDOWS\SYSTEM32\tcntskdm.exe
2008-05-18 12:31 . 2008-05-18 12:31 4 --a------ C:\WINDOWS\SYSTEM32\hljwugsf.bin

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 08:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-24 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-24 05:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-05-02 15:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 01:24 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Walgreens
2008-04-12 08:32 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Jasc Software Inc
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0486b38e-08b4-4ed2-8441-5d24298c01ad}]
2008-05-23 22:41 100608 --a------ C:\WINDOWS\system32\crtaunjt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fab72337-187c-4d3d-bddb-c7cecb1a3882}]
2008-05-26 02:04 100608 --a------ C:\WINDOWS\system32\xqxvptcj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"QdrModule16"="C:\Program Files\QdrModule\QdrModule16.exe" [ ]
"QdrPack16"="C:\Program Files\QdrPack\QdrPack16.exe" [ ]
"Microsoft Windows Installer"="C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe" [2008-05-22 21:43 121856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 10:33 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48 32881]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 19:15 290816]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-02-07 07:43 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 15:54 57344]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 00:01 110592]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2006-01-17 13:03 135168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-15 12:59 98304]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 00:05 127035]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 09:46 172032]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 11:55 49152]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 21:48 1392640]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 15:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 15:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 15:50 114688]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 13:03 53248]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2004-05-10 14:04 271872]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"ExploreUpdSched"="C:\WINDOWS\SYSTEM32\tcntskdm.exe" [2008-05-18 12:32 200768]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-04-15 12:47:21 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=


.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-26 18:09:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\system32\zxdnt3d.cfg 21 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\WLTRYSVC.EXE
C:\WINDOWS\SYSTEM32\BCMWLTRY.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Apoint\ApntEx.exe
C:\WINDOWS\SYSTEM32\igfxsrvc.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\IMAPI.EXE
.
**************************************************************************
.
Completion time: 2008-05-26 18:14:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-27 00:14:03

Pre-Run: 41,026,322,432 bytes free
Post-Run: 41,496,383,488 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

236 --- E O F --- 2008-05-18 18:23:24


Combofix_Log2


ComboFix 08-05-25.5 - Lindsey 2008-05-26 18:37:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.217 [GMT -6:00]
Running from: C:\Documents and Settings\Lindsey\Desktop\butthole.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Lindsey\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\Lindsey\Start Menu\Programs\Startup\DW_Start.lnk
C:\WINDOWS\system32\ctabnqbl.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\lsylkjet.exe
C:\WINDOWS\system32\pvcbeqyr.exe
C:\WINDOWS\system32\qxxntpmi.exe
C:\WINDOWS\system32\vovcqtlu.exe
C:\WINDOWS\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.

2008-05-26 18:32 . 2008-05-26 18:33 <DIR> d-------- C:\gembob
2008-05-26 11:00 . 2008-05-26 11:00 90,896 --a------ C:\WINDOWS\SYSTEM32\vrpcvmvc.dll
2008-05-26 02:04 . 2008-05-26 02:04 100,608 --a------ C:\WINDOWS\SYSTEM32\xqxvptcj.dll
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Program Files\Avira
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-24 00:04 . 2008-05-24 00:04 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-24 00:04 . 2008-05-24 00:09 <DIR> d-------- C:\Program Files\CCleaner
2008-05-23 23:32 . 2008-05-25 15:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 23:28 . 2008-05-23 23:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-05-23 23:11 . 2008-05-23 23:11 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 22:40 . 2008-05-23 22:41 100,608 --a------ C:\WINDOWS\SYSTEM32\crtaunjt.dll
2008-05-23 22:32 . 2008-05-23 22:32 91,008 --a------ C:\WINDOWS\SYSTEM32\dxxjspis.dll
2008-05-23 22:30 . 2008-05-23 22:30 91,008 --a------ C:\WINDOWS\SYSTEM32\csumwfhb.dll
2008-05-23 22:24 . 2008-05-26 18:27 <DIR> d-------- C:\Documents and Settings\Lindsey\Application Data\uTorrent
2008-05-23 20:41 . 2008-05-23 20:41 100,608 --a------ C:\WINDOWS\SYSTEM32\caexdxhv.dll
2008-05-23 17:54 . 2008-05-23 17:56 <DIR> d-------- C:\Program Files\Internet Spy Hunter
2008-05-23 17:08 . 2008-05-23 17:08 200,774 --a------ C:\WINDOWS\SYSTEM32\lcntmkdm.exe
2008-05-23 17:08 . 2008-05-23 17:08 88,961 --a------ C:\WINDOWS\SYSTEM32\mysidesearch_sidebar_uninstall.exe
2008-05-23 17:07 . 2008-05-26 18:17 <DIR> d-------- C:\Program Files\Trojan Remover
2008-05-23 17:07 . 2008-05-23 17:07 100,608 --a------ C:\WINDOWS\SYSTEM32\petrykoj.dll
2008-05-23 17:05 . 2008-05-23 17:05 91,008 --a------ C:\WINDOWS\SYSTEM32\qmkglewb.dll
2008-05-22 23:02 . 2008-05-22 23:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-05-18 22:36 . 2008-05-18 22:36 9,662 --a------ C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
2008-05-18 22:36 . 2008-05-18 22:36 4,286 --a------ C:\WINDOWS\SYSTEM32\Jamster.ico
2008-05-18 22:26 . 2008-05-18 22:26 401,972 --a------ C:\WINDOWS\SYSTEM32\g89.exe
2008-05-18 22:26 . 2008-05-18 22:26 200,768 --a------ C:\WINDOWS\SYSTEM32\ocntrkdm.exe
2008-05-18 16:57 . 2008-05-18 16:58 401,964 --a------ C:\WINDOWS\SYSTEM32\g78.exe
2008-05-18 13:04 . 2008-05-18 13:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\logXv01
2008-05-18 12:33 . 2008-05-18 12:33 <DIR> d-------- C:\Program Files\uTorrent
2008-05-18 12:33 . 2004-08-04 04:00 4,224 --a------ C:\WINDOWS\SYSTEM32\beep.sys
2008-05-18 12:33 . 2008-05-23 22:48 860 --a------ C:\WINDOWS\SYSTEM32\winpfz33.sys
2008-05-18 12:32 . 2008-05-18 18:22 <DIR> d--hs---- C:\WINDOWS\TGluZHNleQ
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\polX
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\logXv06
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\GUI2
2008-05-18 12:32 . 2008-05-25 15:33 <DIR> d-------- C:\WINDOWS\SYSTEM32\binR
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\3036a
2008-05-18 12:32 . 2008-05-18 12:32 <DIR> d-------- C:\Temp\dmpxp32
2008-05-18 12:32 . 2008-05-18 12:32 298,311 --a------ C:\WINDOWS\SYSTEM32\gside.exe
2008-05-18 12:32 . 2008-05-18 12:32 200,768 --a------ C:\WINDOWS\SYSTEM32\tcntskdm.exe
2008-05-18 12:31 . 2008-05-18 12:31 4 --a------ C:\WINDOWS\SYSTEM32\hljwugsf.bin

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 08:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-24 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-24 05:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-05-02 15:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 01:24 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Walgreens
2008-04-12 08:32 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Jasc Software Inc
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\SYSTEM32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-03-02 00:36 3,591,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
.

((((((((((((((((((((((((((((( snapshot@2008-05-26_18.13.40.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-27 00:08:31 2,048 --s-a-w C:\WINDOWS\BOOTSTAT.DAT
+ 2008-05-27 00:29:14 2,048 --s-a-w C:\WINDOWS\BOOTSTAT.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0486b38e-08b4-4ed2-8441-5d24298c01ad}]
2008-05-23 22:41 100608 --a------ C:\WINDOWS\system32\crtaunjt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fab72337-187c-4d3d-bddb-c7cecb1a3882}]
2008-05-26 02:04 100608 --a------ C:\WINDOWS\system32\xqxvptcj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"QdrModule16"="C:\Program Files\QdrModule\QdrModule16.exe" [ ]
"QdrPack16"="C:\Program Files\QdrPack\QdrPack16.exe" [ ]
"Microsoft Windows Installer"="C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe" [2008-05-22 21:43 121856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 10:33 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48 32881]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 19:15 290816]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-02-07 07:43 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 15:54 57344]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 00:01 110592]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2006-01-17 13:03 135168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-15 12:59 98304]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 00:05 127035]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 09:46 172032]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 11:55 49152]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 21:48 1392640]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 15:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 15:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 15:50 114688]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 13:03 53248]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-04-15 12:47:21 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=


*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-26 18:39:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-26 18:40:31
ComboFix-quarantined-files.txt 2008-05-27 00:40:15
ComboFix2.txt 2008-05-27 00:14:16

Pre-Run: 41,934,651,392 bytes free
Post-Run: 41,917,153,280 bytes free

150 --- E O F --- 2008-05-18 18:23:24


Hijack This


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:43:39 PM, on 5/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\SYSTEM32\tcntskdm.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Sonic\RecordNow!\RecordNow.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\imapi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: (no name) - {0486b38e-08b4-4ed2-8441-5d24298c01ad} - C:\WINDOWS\system32\crtaunjt.dll
O2 - BHO: {2883a1bc-ec7c-bddb-d3d4-c78173327baf} - {fab72337-187c-4d3d-bddb-c7cecb1a3882} - C:\WINDOWS\system32\xqxvptcj.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QdrModule16] "C:\Program Files\QdrModule\QdrModule16.exe"
O4 - HKCU\..\Run: [QdrPack16] "C:\Program Files\QdrPack\QdrPack16.exe"
O4 - HKCU\..\Run: [Microsoft Windows Installer] C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 7974 bytes

#11 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 27 May 2008 - 12:06 AM

Hi,

I assume that the last Combofix log is the latest one..

* Open notepad - don't use any other texteditor than notepad or the script will fail.
Copy/paste the text in the quotebox below into notepad:

File::
C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
C:\WINDOWS\SYSTEM32\gside.exe
C:\WINDOWS\SYSTEM32\tcntskdm.exe
C:\WINDOWS\SYSTEM32\hljwugsf.bin
C:\WINDOWS\SYSTEM32\winpfz33.sys
C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
C:\WINDOWS\SYSTEM32\Jamster.ico
C:\WINDOWS\SYSTEM32\g89.exe
C:\WINDOWS\SYSTEM32\ocntrkdm.exe
C:\WINDOWS\SYSTEM32\g78.exe
C:\WINDOWS\SYSTEM32\vrpcvmvc.dll
C:\WINDOWS\SYSTEM32\xqxvptcj.dll
C:\WINDOWS\SYSTEM32\crtaunjt.dll
C:\WINDOWS\SYSTEM32\dxxjspis.dll
C:\WINDOWS\SYSTEM32\csumwfhb.dll
C:\WINDOWS\SYSTEM32\caexdxhv.dll
C:\WINDOWS\SYSTEM32\lcntmkdm.exe
C:\WINDOWS\SYSTEM32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\SYSTEM32\petrykoj.dll
C:\WINDOWS\SYSTEM32\qmkglewb.dll
Folder::
C:\WINDOWS\SYSTEM32\logXv01
C:\WINDOWS\TGluZHNleQ
C:\WINDOWS\SYSTEM32\polX
C:\WINDOWS\SYSTEM32\logXv06
C:\WINDOWS\SYSTEM32\GUI2
C:\WINDOWS\SYSTEM32\binR
C:\WINDOWS\SYSTEM32\3036a
C:\Temp\dmpxp32
Dirlook::
C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0486b38e-08b4-4ed2-8441-5d24298c01ad}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fab72337-187c-4d3d-bddb-c7cecb1a3882}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"=-
"QdrModule16"=-
"QdrPack16"=-
"Microsoft Windows Installer"=-


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#12 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 28 May 2008 - 09:27 PM

Okay here is the latest Combofix log and hijack this log:

ComboFix 08-05-25.5 - Lindsey 2008-05-28 20:16:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.208 [GMT -6:00]
Running from: C:\Documents and Settings\Lindsey\Desktop\butthole.exe
Command switches used :: C:\Documents and Settings\Lindsey\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
C:\WINDOWS\SYSTEM32\caexdxhv.dll
C:\WINDOWS\SYSTEM32\crtaunjt.dll
C:\WINDOWS\SYSTEM32\csumwfhb.dll
C:\WINDOWS\SYSTEM32\dxxjspis.dll
C:\WINDOWS\SYSTEM32\g78.exe
C:\WINDOWS\SYSTEM32\g89.exe
C:\WINDOWS\SYSTEM32\gside.exe
C:\WINDOWS\SYSTEM32\hljwugsf.bin
C:\WINDOWS\SYSTEM32\Jamster.ico
C:\WINDOWS\SYSTEM32\lcntmkdm.exe
C:\WINDOWS\SYSTEM32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\SYSTEM32\ocntrkdm.exe
C:\WINDOWS\SYSTEM32\petrykoj.dll
C:\WINDOWS\SYSTEM32\qmkglewb.dll
C:\WINDOWS\SYSTEM32\tcntskdm.exe
C:\WINDOWS\SYSTEM32\vrpcvmvc.dll
C:\WINDOWS\SYSTEM32\winpfz33.sys
C:\WINDOWS\SYSTEM32\xqxvptcj.dll
C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
C:\Temp\dmpxp32
C:\Temp\dmpxp32\sakldsr.log
C:\WINDOWS\SYSTEM32\3036a
C:\WINDOWS\SYSTEM32\binR
C:\WINDOWS\SYSTEM32\caexdxhv.dll
C:\WINDOWS\SYSTEM32\crtaunjt.dll
C:\WINDOWS\SYSTEM32\csumwfhb.dll
C:\WINDOWS\SYSTEM32\dxxjspis.dll
C:\WINDOWS\SYSTEM32\g78.exe
C:\WINDOWS\SYSTEM32\g89.exe
C:\WINDOWS\SYSTEM32\gside.exe
C:\WINDOWS\SYSTEM32\GUI2
C:\WINDOWS\SYSTEM32\GUI2\FI-dt4x.exe
C:\WINDOWS\SYSTEM32\hljwugsf.bin
C:\WINDOWS\SYSTEM32\Jamster.ico
C:\WINDOWS\SYSTEM32\lcntmkdm.exe
C:\WINDOWS\SYSTEM32\logXv01
C:\WINDOWS\SYSTEM32\logXv01\logXv011065.exe
C:\WINDOWS\SYSTEM32\logXv06
C:\WINDOWS\SYSTEM32\logXv06\logXv061083.exe
C:\WINDOWS\SYSTEM32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\SYSTEM32\ocntrkdm.exe
C:\WINDOWS\SYSTEM32\petrykoj.dll
C:\WINDOWS\SYSTEM32\polX
C:\WINDOWS\SYSTEM32\polX\roEbdll2.exe
C:\WINDOWS\SYSTEM32\qmkglewb.dll
C:\WINDOWS\SYSTEM32\tcntskdm.exe
C:\WINDOWS\SYSTEM32\vrpcvmvc.dll
C:\WINDOWS\SYSTEM32\winpfz33.sys
C:\WINDOWS\SYSTEM32\xqxvptcj.dll
C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
C:\WINDOWS\TGluZHNleQ

.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.

2008-05-28 20:04 . 2008-05-28 20:04 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-26 18:32 . 2008-05-26 18:33 <DIR> d-------- C:\gembob
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Program Files\Avira
2008-05-25 14:25 . 2008-05-25 14:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-24 00:04 . 2008-05-24 00:04 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-24 00:04 . 2008-05-24 00:09 <DIR> d-------- C:\Program Files\CCleaner
2008-05-23 23:32 . 2008-05-25 15:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 23:28 . 2008-05-23 23:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-05-23 23:11 . 2008-05-23 23:11 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 22:24 . 2008-05-28 20:12 <DIR> d-------- C:\Documents and Settings\Lindsey\Application Data\uTorrent
2008-05-23 17:54 . 2008-05-23 17:56 <DIR> d-------- C:\Program Files\Internet Spy Hunter
2008-05-23 17:07 . 2008-05-26 18:17 <DIR> d-------- C:\Program Files\Trojan Remover
2008-05-22 23:02 . 2008-05-22 23:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-05-18 12:33 . 2008-05-18 12:33 <DIR> d-------- C:\Program Files\uTorrent
2008-05-18 12:33 . 2004-08-04 04:00 4,224 --a------ C:\WINDOWS\SYSTEM32\beep.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 02:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-26 08:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-24 05:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-05-02 15:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 01:24 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Walgreens
2008-04-12 08:32 --------- d-----w C:\Documents and Settings\Lindsey\Application Data\Jasc Software Inc
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\SYSTEM32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-03-02 00:36 3,591,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc ----

2008-05-22 21:43 121856 --a------ C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\25195.exe
2008-05-18 12:33 65536 --a------ C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\4303.dll
2008-05-18 12:33 57344 --a------ C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\6400.dll
2008-05-18 12:33 57344 --a------ C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\6211.dll
2008-05-18 12:33 128 --a------ C:\Documents and Settings\Lindsey\Application Data\Microsoft\dtsc\id


((((((((((((((((((((((((((((( snapshot@2008-05-26_18.13.40.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-27 00:08:31 2,048 --s-a-w C:\WINDOWS\BOOTSTAT.DAT
+ 2008-05-29 02:02:11 2,048 --s-a-w C:\WINDOWS\BOOTSTAT.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 10:33 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48 32881]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 19:15 290816]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-02-07 07:43 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 15:54 57344]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 00:01 110592]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2006-01-17 13:03 135168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-15 12:59 98304]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 00:05 127035]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 09:46 172032]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 11:55 49152]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 21:48 1392640]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 15:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 15:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 15:50 114688]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 13:03 53248]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-04-15 12:47:21 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=


.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-28 20:19:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-28 20:20:19
ComboFix-quarantined-files.txt 2008-05-29 02:20:03
ComboFix2.txt 2008-05-27 00:40:32
ComboFix3.txt 2008-05-27 00:14:16

Pre-Run: 41,873,346,560 bytes free
Post-Run: 41,853,644,800 bytes free

171 --- E O F --- 2008-05-18 18:23:24


and hijack this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:14 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 7256 bytes


I appreciate all the help so far.

#13 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 29 May 2008 - 12:00 AM

Hi,

This looks OK again.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 6".
  • Click the "Download" button to the right.
  • For Platform, select "Windows"
  • For language, select your language
  • Read the License agreement and then Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement".
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    • Java 2 Runtime Environment, SE v1.4.2
    • J2SE Runtime Environment 5.0
    • J2SE Runtime Environment 5.0 Update 6
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.
* Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#14 gembob

gembob
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 31 May 2008 - 01:15 PM

Things look like they're running correctly now. I really appreciate all the time you took to help miekiemoes, thanks.

#15 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:11:23 AM

Posted 31 May 2008 - 01:21 PM

Glad I could help. :thumbsup:

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users