Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Nothing Major...


  • This topic is locked This topic is locked
11 replies to this topic

#1 Powerman2442

Powerman2442

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 06 January 2009 - 01:35 PM

Hello I have nothing extremely wrong I am just unsure of which files I can delete or add to the ignore list. Some of them I know I can add but I am going to post the full log so you can see it.

Thanks,
Powerman2442

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:02 AM, on 1/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: REALTEK RTL8185 Wireless LAN Utility.lnk = C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 2523 bytes

In processes everything looks okay, just some basic windows processes, java, and hijackthis. As for the rest I am not sure if these are safe to delete or ignore.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

FYI I don't have AVG installed anymore. I'm pretty sure all the Java stuff is safe, as well as the Google Update (think that is for Google Chrome). Ad-Aware is safe, Realtek is safe (wirless nic hardware utility), and Windows Messenger is safe. Correct me if I am wrong and let me know about the others above.

Thanks again,

Edited by Powerman2442, 06 January 2009 - 01:37 PM.


BC AdBot (Login to Remove)

 


#2 Powerman2442

Powerman2442
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 08 January 2009 - 07:35 PM

Been a day or two, anyone got any information?

Thanks,

#3 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 20 January 2009 - 09:29 AM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#4 Powerman2442

Powerman2442
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 20 January 2009 - 03:36 PM

Logfile of random's system information tool 1.05 (written by random/random)
Run by User at 2009-01-20 15:33:34
Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (29%) free of 8 GB
Total RAM: 512 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:34:32 PM, on 1/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\distributed.net\dnetc.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\User.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

--
End of file - 1527 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-839522115-1957994488-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{111CAA23-6F4F-42AC-8555-B48C1D87BBAB}]
GigagetIEHelper Class - C:\WINDOWS\system32\gigagetbho_v10.dll [2006-01-09 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-22 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-22 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-22 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS\system32\SysTray.Exe [2004-08-03 3072]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-22 136600]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-26 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2
"avg8emc"=2
"sdCoreService"=3
"sdAuxService"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
REALTEK RTL8185 Wireless LAN Utility.lnk - C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe"="C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Walker\DrvInst\Bin\enable.exe"="C:\Program Files\Walker\DrvInst\Bin\enable.exe:*:Enabled:Enable.exe"
"C:\Documents and Settings\User\Desktop\edrvclienten.exe"="C:\Documents and Settings\User\Desktop\edrvclienten.exe:*:Enabled:DriverEngine.com Agent"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Giganology\Gigaget\Gigaget.exe"="C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IceChat7\IceChat7.exe"="C:\Program Files\IceChat7\IceChat7.exe:*:Enabled:Internet Relay Chat Client"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4dbca6d0-d261-11db-8679-b7072d4ba28f}]
shell\AutoRun\command - E:\LaunchU3.exe -a


======File associations======

.js - open - c:\Corel\Suite8\Programs\CCWin\Cscape.exe

======List of files/folders created in the last 1 months======

2009-01-20 15:33:34 ----D---- C:\rsit
2009-01-20 01:18:16 ----D---- C:\Documents and Settings\User\Application Data\WinRAR
2009-01-20 00:47:02 ----D---- C:\Program Files\Trillian
2009-01-20 00:46:30 ----D---- C:\Program Files\WinRAR
2009-01-19 01:49:24 ----D---- C:\Documents and Settings\User\Application Data\IceChat
2009-01-19 01:48:23 ----D---- C:\Program Files\IceChat7
2009-01-19 01:33:43 ----D---- C:\Program Files\distributed.net
2009-01-19 01:30:32 ----A---- C:\WINDOWS\system32\kbdkor.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd106.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd103.dll
2009-01-19 01:30:28 ----A---- C:\WINDOWS\system32\kbd101c.dll
2009-01-19 01:30:27 ----A---- C:\WINDOWS\system32\kbd101b.dll
2009-01-18 14:19:28 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools
2009-01-18 11:30:26 ----D---- C:\Program Files\uTorrent
2009-01-18 11:30:18 ----D---- C:\Documents and Settings\User\Application Data\uTorrent
2009-01-18 11:26:23 ----D---- C:\TDdownload
2009-01-18 11:06:44 ----A---- C:\WINDOWS\system32\gigagetbho_v10.dll
2009-01-18 11:06:28 ----D---- C:\Program Files\Giganology
2009-01-16 02:29:23 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-15 12:27:39 ----D---- C:\Program Files\Avira
2009-01-15 12:27:39 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-15 11:28:01 ----HD---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\ltefx13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfgif13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfcmp13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfbmp13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltkrn13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltimg13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltfil13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltdis13n.dll
2009-01-06 06:49:30 ----D---- C:\Program Files\Foxit Software
2009-01-06 06:49:30 ----D---- C:\Documents and Settings\User\Application Data\Foxit
2009-01-03 04:12:12 ----A---- C:\WINDOWS\system32\ptpusb.dll
2009-01-03 04:12:09 ----A---- C:\WINDOWS\system32\ptpusd.dll
2009-01-02 04:46:30 ----D---- C:\Program Files\AbiSuite2
2009-01-02 03:50:04 ----D---- C:\WINDOWS\system32\tempdir
2009-01-02 03:50:01 ----A---- C:\WINDOWS\system32\ptj.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\pdftk.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\office.exe
2009-01-02 03:49:54 ----D---- C:\Program Files\Image Convert Jpg Jpeg Bmp Tiff Gif Png Free
2009-01-01 20:25:24 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2009-01-01 20:25:12 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2009-01-01 20:25:11 ----D---- C:\Program Files\PDFCreator
2009-01-01 20:21:45 ----D---- C:\Text Mining Tool 1.1.42
2008-12-30 19:50:50 ----D---- C:\Program Files\winMd5Sum
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmps.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\mspmsnsv.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\CEWMDM.dll
2008-12-29 21:56:38 ----A---- C:\WINDOWS\system32\mswmdm.dll
2008-12-29 21:41:27 ----D---- C:\WINDOWS\RegisteredPackages
2008-12-28 07:07:36 ----D---- C:\Documents and Settings\User\Application Data\GetRightToGo
2008-12-27 20:47:46 ----D---- C:\Documents and Settings\User\Application Data\Help
2008-12-27 20:26:12 ----HD---- C:\WINDOWS\$NtUninstallKB929399$
2008-12-27 20:25:25 ----HD---- C:\WINDOWS\$NtUninstallKB939683$
2008-12-27 20:24:42 ----HD---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-12-27 20:24:10 ----HD---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-12-27 20:06:00 ----A---- C:\WINDOWS\system32\DEVLOAD.EXE
2008-12-27 20:05:33 ----A---- C:\WINDOWS\SKLANG.INI
2008-12-24 16:06:27 ----HD---- C:\WINDOWS\$NtUninstallKB926239$
2008-12-24 16:05:48 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-24 16:05:46 ----HD---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-12-24 16:04:37 ----D---- C:\Program Files\Windows Media Connect 2
2008-12-24 15:58:38 ----D---- C:\WINDOWS\system32\LogFiles
2008-12-24 15:58:22 ----HD---- C:\WINDOWS\$NtUninstallWudf01000$
2008-12-23 04:25:44 ----D---- C:\Program Files\Trend Micro
2008-12-22 02:48:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-22 02:48:25 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 1 months======

2009-01-19 23:14:34 ----A---- C:\WINDOWS\RTacDbg.txt
2009-01-19 23:07:22 ----A---- C:\WINDOWS\SchedLog.Txt
2009-01-19 22:59:38 ----SH---- C:\boot.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\win.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\system.ini
2009-01-16 02:30:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-27 20:26:24 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-12-15 21035]
R2 EAPPkt;Realtek EAPPkt Protocol; C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2007-10-09 38144]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 atirage;atirage; C:\WINDOWS\system32\DRIVERS\ati2mpah.sys [2000-03-24 74592]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ds1;Yamaha DS1 Audio Driver (WDM); C:\WINDOWS\system32\drivers\ds1wdm.sys [2001-08-17 334208]
R3 Edspport;EDSP Port Driver; C:\WINDOWS\system32\DRIVERS\es56tpi.sys [2001-08-17 347550]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2008-03-21 308480]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 NtApm;NT Apm/Legacy Interface Driver; C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 9344]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 ACPI;ACPI; C:\WINDOWS\system32\drivers\ACPI.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-03 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-06-25 611664]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-22 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-03 14336]

-----------------EOF-----------------

#5 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 20 January 2009 - 07:39 PM

Your log is very small. Please post the entire log. If you have placed items in whitelist section, please put them back. If you have removed items from startup, please add them. Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#6 Powerman2442

Powerman2442
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 20 January 2009 - 11:44 PM

Your log is very small. Please post the entire log. If you have placed items in whitelist section, please put them back. If you have removed items from startup, please add them. Thanks.


Logfile of random's system information tool 1.05 (written by random/random)
Run by User at 2009-01-20 23:40:45
Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (29%) free of 8 GB
Total RAM: 512 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:31 PM, on 1/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\distributed.net\dnetc.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\User.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

--
End of file - 1682 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-839522115-1957994488-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{111CAA23-6F4F-42AC-8555-B48C1D87BBAB}]
GigagetIEHelper Class - C:\WINDOWS\system32\gigagetbho_v10.dll [2006-01-09 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
C:\Program Files\AVG\AVG8\avgssie.dll [2008-09-06 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-22 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-22 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-22 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS\system32\SysTray.Exe [2004-08-03 3072]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-22 136600]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-26 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2
"avg8emc"=2
"sdCoreService"=3
"sdAuxService"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
REALTEK RTL8185 Wireless LAN Utility.lnk - C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe"="C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Walker\DrvInst\Bin\enable.exe"="C:\Program Files\Walker\DrvInst\Bin\enable.exe:*:Enabled:Enable.exe"
"C:\Documents and Settings\User\Desktop\edrvclienten.exe"="C:\Documents and Settings\User\Desktop\edrvclienten.exe:*:Enabled:DriverEngine.com Agent"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Giganology\Gigaget\Gigaget.exe"="C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IceChat7\IceChat7.exe"="C:\Program Files\IceChat7\IceChat7.exe:*:Enabled:Internet Relay Chat Client"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4dbca6d0-d261-11db-8679-b7072d4ba28f}]
shell\AutoRun\command - E:\LaunchU3.exe -a


======File associations======

.js - open - c:\Corel\Suite8\Programs\CCWin\Cscape.exe

======List of files/folders created in the last 1 months======

2009-01-20 15:33:34 ----D---- C:\rsit
2009-01-20 01:18:16 ----D---- C:\Documents and Settings\User\Application Data\WinRAR
2009-01-20 00:47:02 ----D---- C:\Program Files\Trillian
2009-01-20 00:46:30 ----D---- C:\Program Files\WinRAR
2009-01-19 01:49:24 ----D---- C:\Documents and Settings\User\Application Data\IceChat
2009-01-19 01:48:23 ----D---- C:\Program Files\IceChat7
2009-01-19 01:33:43 ----D---- C:\Program Files\distributed.net
2009-01-19 01:30:32 ----A---- C:\WINDOWS\system32\kbdkor.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd106.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd103.dll
2009-01-19 01:30:28 ----A---- C:\WINDOWS\system32\kbd101c.dll
2009-01-19 01:30:27 ----A---- C:\WINDOWS\system32\kbd101b.dll
2009-01-18 14:19:28 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools
2009-01-18 11:30:26 ----D---- C:\Program Files\uTorrent
2009-01-18 11:30:18 ----D---- C:\Documents and Settings\User\Application Data\uTorrent
2009-01-18 11:26:23 ----D---- C:\TDdownload
2009-01-18 11:06:44 ----A---- C:\WINDOWS\system32\gigagetbho_v10.dll
2009-01-18 11:06:28 ----D---- C:\Program Files\Giganology
2009-01-16 02:29:23 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-15 12:27:39 ----D---- C:\Program Files\Avira
2009-01-15 12:27:39 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-15 11:28:01 ----HD---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\ltefx13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfgif13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfcmp13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfbmp13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltkrn13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltimg13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltfil13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltdis13n.dll
2009-01-06 06:49:30 ----D---- C:\Program Files\Foxit Software
2009-01-06 06:49:30 ----D---- C:\Documents and Settings\User\Application Data\Foxit
2009-01-03 04:12:12 ----A---- C:\WINDOWS\system32\ptpusb.dll
2009-01-03 04:12:09 ----A---- C:\WINDOWS\system32\ptpusd.dll
2009-01-02 04:46:30 ----D---- C:\Program Files\AbiSuite2
2009-01-02 03:50:04 ----D---- C:\WINDOWS\system32\tempdir
2009-01-02 03:50:01 ----A---- C:\WINDOWS\system32\ptj.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\pdftk.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\office.exe
2009-01-02 03:49:54 ----D---- C:\Program Files\Image Convert Jpg Jpeg Bmp Tiff Gif Png Free
2009-01-01 20:25:24 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2009-01-01 20:25:12 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2009-01-01 20:25:11 ----D---- C:\Program Files\PDFCreator
2009-01-01 20:21:45 ----D---- C:\Text Mining Tool 1.1.42
2008-12-30 19:50:50 ----D---- C:\Program Files\winMd5Sum
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmps.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\mspmsnsv.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\CEWMDM.dll
2008-12-29 21:56:38 ----A---- C:\WINDOWS\system32\mswmdm.dll
2008-12-29 21:41:27 ----D---- C:\WINDOWS\RegisteredPackages
2008-12-28 07:07:36 ----D---- C:\Documents and Settings\User\Application Data\GetRightToGo
2008-12-27 20:47:46 ----D---- C:\Documents and Settings\User\Application Data\Help
2008-12-27 20:26:12 ----HD---- C:\WINDOWS\$NtUninstallKB929399$
2008-12-27 20:25:25 ----HD---- C:\WINDOWS\$NtUninstallKB939683$
2008-12-27 20:24:42 ----HD---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-12-27 20:24:10 ----HD---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-12-27 20:06:00 ----A---- C:\WINDOWS\system32\DEVLOAD.EXE
2008-12-27 20:05:33 ----A---- C:\WINDOWS\SKLANG.INI
2008-12-24 16:06:27 ----HD---- C:\WINDOWS\$NtUninstallKB926239$
2008-12-24 16:05:48 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-24 16:05:46 ----HD---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-12-24 16:04:37 ----D---- C:\Program Files\Windows Media Connect 2
2008-12-24 15:58:38 ----D---- C:\WINDOWS\system32\LogFiles
2008-12-24 15:58:22 ----HD---- C:\WINDOWS\$NtUninstallWudf01000$
2008-12-23 04:25:44 ----D---- C:\Program Files\Trend Micro
2008-12-22 02:48:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-22 02:48:25 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 1 months======

2009-01-19 23:14:34 ----A---- C:\WINDOWS\RTacDbg.txt
2009-01-19 23:07:22 ----A---- C:\WINDOWS\SchedLog.Txt
2009-01-19 22:59:38 ----SH---- C:\boot.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\win.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\system.ini
2009-01-16 02:30:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-27 20:26:24 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-12-15 21035]
R2 EAPPkt;Realtek EAPPkt Protocol; C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2007-10-09 38144]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 atirage;atirage; C:\WINDOWS\system32\DRIVERS\ati2mpah.sys [2000-03-24 74592]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ds1;Yamaha DS1 Audio Driver (WDM); C:\WINDOWS\system32\drivers\ds1wdm.sys [2001-08-17 334208]
R3 Edspport;EDSP Port Driver; C:\WINDOWS\system32\DRIVERS\es56tpi.sys [2001-08-17 347550]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2008-03-21 308480]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 NtApm;NT Apm/Legacy Interface Driver; C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 9344]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 ACPI;ACPI; C:\WINDOWS\system32\drivers\ACPI.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-03 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-06-25 611664]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-22 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-03 14336]

-----------------EOF-----------------

#7 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 21 January 2009 - 01:59 PM

  • Please download Trend Micro - HijackThis.
  • Double click HJTInstall.exe to begin installation.
  • Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse... button if you want to save it in another location.
  • Click Install.
  • A shortcut will be created on your Desktop and HijackThis will run automatically.
  • You will need to accept the EULA, if it appears, to be able to use the tool.
  • When HijackThis opens, click on the Do a system scan and save a log file button.
  • When HijackThis has finished scanning, a window entitled hijackthis.log will open. When you close this window, the log will be saved into the HijackThis folder.
  • If needed, see TrendMicro™ HijackThis™ Quick Start Guide
  • Copy and paste this log into your next reply.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#8 Powerman2442

Powerman2442
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 21 January 2009 - 10:41 PM

Okay did that earlier before being told to use RSIT, but here is an updated HiJackhis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:43 PM, on 1/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\distributed.net\dnetc.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - Global Startup: REALTEK RTL8185 Wireless LAN Utility.lnk = C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 3626 bytes

And here is another RSIT...

Logfile of random's system information tool 1.05 (written by random/random)
Run by User at 2009-01-21 22:40:21
Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (28%) free of 8 GB
Total RAM: 512 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:07 PM, on 1/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\distributed.net\dnetc.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\User\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\User.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - Global Startup: REALTEK RTL8185 Wireless LAN Utility.lnk = C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 3669 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-839522115-1957994488-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{111CAA23-6F4F-42AC-8555-B48C1D87BBAB}]
GigagetIEHelper Class - C:\WINDOWS\system32\gigagetbho_v10.dll [2006-01-09 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
C:\Program Files\AVG\AVG8\avgssie.dll [2008-09-06 455960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-22 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-22 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-22 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS\system32\SysTray.Exe [2004-08-03 3072]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-22 136600]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-26 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2
"avg8emc"=2
"sdCoreService"=3
"sdAuxService"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
REALTEK RTL8185 Wireless LAN Utility.lnk - C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtWLan.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe"="C:\Program Files\Java\jre1.6.0_07\BIN\javaw.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Walker\DrvInst\Bin\enable.exe"="C:\Program Files\Walker\DrvInst\Bin\enable.exe:*:Enabled:Enable.exe"
"C:\Documents and Settings\User\Desktop\edrvclienten.exe"="C:\Documents and Settings\User\Desktop\edrvclienten.exe:*:Enabled:DriverEngine.com Agent"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Giganology\Gigaget\Gigaget.exe"="C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IceChat7\IceChat7.exe"="C:\Program Files\IceChat7\IceChat7.exe:*:Enabled:Internet Relay Chat Client"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4dbca6d0-d261-11db-8679-b7072d4ba28f}]
shell\AutoRun\command - E:\LaunchU3.exe -a


======File associations======

.js - open - c:\Corel\Suite8\Programs\CCWin\Cscape.exe

======List of files/folders created in the last 1 months======

2009-01-20 15:33:34 ----D---- C:\rsit
2009-01-20 01:18:16 ----D---- C:\Documents and Settings\User\Application Data\WinRAR
2009-01-20 00:47:02 ----D---- C:\Program Files\Trillian
2009-01-20 00:46:30 ----D---- C:\Program Files\WinRAR
2009-01-19 01:49:24 ----D---- C:\Documents and Settings\User\Application Data\IceChat
2009-01-19 01:48:23 ----D---- C:\Program Files\IceChat7
2009-01-19 01:33:43 ----D---- C:\Program Files\distributed.net
2009-01-19 01:30:32 ----A---- C:\WINDOWS\system32\kbdkor.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd106.dll
2009-01-19 01:30:29 ----A---- C:\WINDOWS\system32\kbd103.dll
2009-01-19 01:30:28 ----A---- C:\WINDOWS\system32\kbd101c.dll
2009-01-19 01:30:27 ----A---- C:\WINDOWS\system32\kbd101b.dll
2009-01-18 14:19:28 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools
2009-01-18 11:30:26 ----D---- C:\Program Files\uTorrent
2009-01-18 11:30:18 ----D---- C:\Documents and Settings\User\Application Data\uTorrent
2009-01-18 11:26:23 ----D---- C:\TDdownload
2009-01-18 11:06:44 ----A---- C:\WINDOWS\system32\gigagetbho_v10.dll
2009-01-18 11:06:28 ----D---- C:\Program Files\Giganology
2009-01-16 02:29:23 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-15 12:27:39 ----D---- C:\Program Files\Avira
2009-01-15 12:27:39 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-15 11:28:01 ----HD---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\ltefx13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfgif13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfcmp13n.dll
2009-01-12 19:26:38 ----A---- C:\WINDOWS\system32\lfbmp13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltkrn13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltimg13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltfil13n.dll
2009-01-12 19:26:37 ----A---- C:\WINDOWS\system32\ltdis13n.dll
2009-01-06 06:49:30 ----D---- C:\Program Files\Foxit Software
2009-01-06 06:49:30 ----D---- C:\Documents and Settings\User\Application Data\Foxit
2009-01-03 04:12:12 ----A---- C:\WINDOWS\system32\ptpusb.dll
2009-01-03 04:12:09 ----A---- C:\WINDOWS\system32\ptpusd.dll
2009-01-02 04:46:30 ----D---- C:\Program Files\AbiSuite2
2009-01-02 03:50:04 ----D---- C:\WINDOWS\system32\tempdir
2009-01-02 03:50:01 ----A---- C:\WINDOWS\system32\ptj.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\pdftk.exe
2009-01-02 03:49:56 ----A---- C:\WINDOWS\system32\office.exe
2009-01-02 03:49:54 ----D---- C:\Program Files\Image Convert Jpg Jpeg Bmp Tiff Gif Png Free
2009-01-01 20:25:24 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2009-01-01 20:25:12 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2009-01-01 20:25:11 ----D---- C:\Program Files\PDFCreator
2009-01-01 20:21:45 ----D---- C:\Text Mining Tool 1.1.42
2008-12-30 19:50:50 ----D---- C:\Program Files\winMd5Sum
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmps.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\mspmsnsv.dll
2008-12-29 21:56:39 ----A---- C:\WINDOWS\system32\CEWMDM.dll
2008-12-29 21:56:38 ----A---- C:\WINDOWS\system32\mswmdm.dll
2008-12-29 21:41:27 ----D---- C:\WINDOWS\RegisteredPackages
2008-12-28 07:07:36 ----D---- C:\Documents and Settings\User\Application Data\GetRightToGo
2008-12-27 20:47:46 ----D---- C:\Documents and Settings\User\Application Data\Help
2008-12-27 20:26:12 ----HD---- C:\WINDOWS\$NtUninstallKB929399$
2008-12-27 20:25:25 ----HD---- C:\WINDOWS\$NtUninstallKB939683$
2008-12-27 20:24:42 ----HD---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-12-27 20:24:10 ----HD---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-12-27 20:06:00 ----A---- C:\WINDOWS\system32\DEVLOAD.EXE
2008-12-27 20:05:33 ----A---- C:\WINDOWS\SKLANG.INI
2008-12-24 16:06:27 ----HD---- C:\WINDOWS\$NtUninstallKB926239$
2008-12-24 16:05:48 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-24 16:05:46 ----HD---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-12-24 16:04:37 ----D---- C:\Program Files\Windows Media Connect 2
2008-12-24 15:58:38 ----D---- C:\WINDOWS\system32\LogFiles
2008-12-24 15:58:22 ----HD---- C:\WINDOWS\$NtUninstallWudf01000$
2008-12-23 04:25:44 ----D---- C:\Program Files\Trend Micro
2008-12-22 02:48:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-22 02:48:26 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-22 02:48:25 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 1 months======

2009-01-19 23:14:34 ----A---- C:\WINDOWS\RTacDbg.txt
2009-01-19 23:07:22 ----A---- C:\WINDOWS\SchedLog.Txt
2009-01-19 22:59:38 ----SH---- C:\boot.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\win.ini
2009-01-19 22:59:38 ----A---- C:\WINDOWS\system.ini
2009-01-16 02:30:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-27 20:26:24 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-12-15 21035]
R2 EAPPkt;Realtek EAPPkt Protocol; C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2007-10-09 38144]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 atirage;atirage; C:\WINDOWS\system32\DRIVERS\ati2mpah.sys [2000-03-24 74592]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ds1;Yamaha DS1 Audio Driver (WDM); C:\WINDOWS\system32\drivers\ds1wdm.sys [2001-08-17 334208]
R3 Edspport;EDSP Port Driver; C:\WINDOWS\system32\DRIVERS\es56tpi.sys [2001-08-17 347550]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2008-03-21 308480]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 NtApm;NT Apm/Legacy Interface Driver; C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 9344]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 ACPI;ACPI; C:\WINDOWS\system32\drivers\ACPI.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-03 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-06-25 611664]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-22 152984]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-03 14336]

-----------------EOF-----------------

Hope this helps.

#9 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 22 January 2009 - 08:59 PM

The entries below indicate that you may have two antivirus programs, AVG8 and AntiVir on your computer.

AVG8

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

AntiVir

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe


Multiple antivirus programs can interfere with one another and actually allow MORE viruses to get through. Running two antivirus programs at the same time could lead to both of them trying to scan the same file at the same time, scan the same email at the same time and so on which could lead to conflicts.

Most of the popular antivirus products, when running together, will "fight for control" over the user's machine. It is this conflict that will slow down the system speed and cause various serious compatibility problems. This can also create registry conflicts as well as causing false virus alerts - or worse, missing alerts entirely! Having more than one antivirus program running and "active in memory" will use more resources which will adversely affect your access to files and cause overall system slowdowns.

Symantec strongly recommends that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

See Should you run more than one antivirus program at the same time?

Kaspersky Lab experts do not recommend using more that one antivirus package on the computer as the co-work of two different Antivirus programs may lead to computer productivity and operating system fall. And to solve the problem of Antivirus applications you will need to reinstall the operating system.

See Co-use of Kaspersky AntiVirus 5.0 and Antivirus packages of other vendors

Ask Leo said:

Real time monitoring, on the other hand, is another story. When you install most anti-virus programs they often automatically install and enable their real-time monitors. Running two or more real-time anti-virus monitors at the same time is very likely to cause a conflict. That conflict could result in error messages, crashes of the anti-virus programs, or other types of failure.

See Can I run more than one anti-virus program? Anti-spyware program? Firewall? Should I?

Types Of Antivirus Programs:

There are basically two types of antivirus programs: On-Access and On-Demand

On-Access Scanners, as the name implies, run in the background all the time the PC is turned on and running. The main function of an on-access scanner is to monitor activity on your machine.

On-Demand Scanners, such as Online Scans and scanners that run on your machine but are not actively scanning your machine, as the name implies, are scanners that only run when you ask them to run.

Antivirus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two antivirus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash. I notice that you are using more than one antivirus program. This is very dangerous, as multiple antivirus programs can interfere with one another and actually allow MORE viruses to get through. Running two antivirus programs at the same time could lead to both of them trying to scan the same file at the same time, scan the same email at the same time and so on which could lead to conflicts.
I strongly suggest you do one of the following:
  • Configure only one antivirus program to enable automatic realtime scanning and leave the rest disabled most of the time.
  • Go to Start > Control Panel > Add or Remove Programs and uninstall all but one antivirus program.

Edited by suebaby41, 22 January 2009 - 09:01 PM.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#10 Powerman2442

Powerman2442
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:54 AM

Posted 23 January 2009 - 03:57 PM

Quoted from my very first post in this topic,

"FYI I don't have AVG installed anymore. I'm pretty sure all the Java stuff is safe, as well as the Google Update (think that is for Google Chrome). Ad-Aware is safe, Realtek is safe (wirless nic hardware utility), and Windows Messenger is safe. Correct me if I am wrong and let me know about the others above."

I hope you did not take the time finding all them quotes and such as I already know all of this. I am trying of figure out what these HiJackThis entries are.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Thanks,

#11 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 23 January 2009 - 06:01 PM

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm


You probably have your homepage set to a blank page.

"FYI I don't have AVG installed anymore. I'm pretty sure all the Java stuff is safe, as well as the Google Update (think that is for Google Chrome). Ad-Aware is safe, Realtek is safe (wirless nic hardware utility), and Windows Messenger is safe. Correct me if I am wrong and let me know about the others above."

I hope you did not take the time finding all them quotes and such as I already know all of this. I am trying of figure out what these HiJackThis entries are.


You still have an entry for AVG8 in your log so we will use HijackThis to get rid of it. I have those quotes about having two antivirus programs saved so that I can share them with you.

F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=

F2 entry in a HijackThis log also refers to the Userinit value in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and by default, Winlogon runs Userinit.exe, which is an application used to run a program before a shell starts. The service runs logon scripts, reestablishes network connections and starts the shell.

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

This was Yahoo Companion. It needs to be fixed by HijackThis.

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

That means your computer has experienced blue screen and memory dump. kernelfaultcheck is a process which is related to a 'dumprep' command and performs memory dumps and writes debugging information.
Step 10 will explain how to use HijackThis to get rid of the entries. The other steps will ensure your computer is clean and will teach you about some very good programs.
Step 1

You may want to print this page. Make sure to work through the fixes in the order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Step 2

In Normal Mode, run an online malware check from at least two and preferably three (one may catch something that another one may not) of the following sites
BitDefender
Computer Associates Online Virus Scan
Kaspersky Online Virus Scanner
McAfee FreeScan
Panda's ActiveScan
Trend Micro™ HouseCall
Windows Live Safety Center Free Online Scan
WindowSecurity.com TrojanScan
When you have completed the scans, if you get a report of files that cannot be cleaned / deleted, make a note of the file location of anything that cannot be cleaned / deleted. Please edit the log(s) and remove:
  • items listed as "Object is locked skipped"
  • items reported that are in a quarantine folder
Please post the edited list in your next reply.

Step 3

Please download Spybot-S&D©® and install Spybot-S&D©® .
  • Be sure to UNCHECK TeaTimer when presented with the option to install. You can enable it after you are clean.
  • Run Spybot-S&D©® , go to the Menu Bar at the top choose Mode and make certain that "Default mode" has a check mark beside it.
  • Click the button "Search for Updates".
  • If any updates are found, install them by placing a check mark next to each one and clicking "Download Updates".
  • If you encounter any error messages while downloading the updates, manually download them from here.
  • Click on "Immunize". When it detects what has or has not been blocked, block all remaining items by clicking the green plus sign next to immunize at the top.
  • Click the button "Check for Problems".
  • When Spybot-S&D©® is complete, it will be showing RED entries, bold BLACK entries and GREEN entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose "Fix Selected Problems" and allow Spybot-S&D©® to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
Note: After Windows loads, Spybot-S&D©® may run again to clean some files that it could not clean during the prior session. Follow the same procedure.

Step 4

I recommend using Spyware Blaster.
  • Please download SpywareBlaster and save it to your desktop.
  • Double click on it to install the program.
  • Follow the prompts and choose the default locations when installing the program.
  • When the program is installed, it will place an icon on your desktop.
  • Double click on the SpywareBlaster icon and you will be presented with a brief tutorial. On the first page of this tutorial, you will see some of the SpywareBlaster features
  • Click on the Next button to proceed to the second page of the tutorial.
  • If you want to purchase the software, then you should select Automatic Updating. If you do not plan on purchasing the software, then you should select the option for Manual Updating. Press the Next button.
  • At the next screen, click Finish.
  • At the next screen, Protection Status, click Enable All Protection.
  • Click Download Latest Protection Updates. This will ensure that SpywareBlaster has the latest definitions so that it can protect your browser more efficiently. You should update SpywareBlaster regularly, as much as every few days, in order to provide the best protection. Each time you update, be sure to click Enable All Protection.
Step 5

Malwarebytes' Anti-Malware is FREEWARE, however you may upgrade to the PRO version which contains realtime protection, scheduled scanning and updating.
  • Please download Malwarebytes Anti-Malware (MBAM). Alternate download link
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing scan. If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from the Malware Bytes Web site. Scroll down the page until you see Latest Database; click Download from GT500.org
  • Double-click on mbam-rules.exe to install.
  • On the Scanner tab, make sure the Perform Quick Scan option is selected.
  • Click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and Scan in progress will show at the top. It may take some time to complete; please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully.
  • At the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
  • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Step 6
  • Please download SUPERAntiSpyware (SAS) - SUPERAntiSpyware Free Version For Home Users
  • Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options, make sure the following are checked:
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
    • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
  • On the main screen, under Scan for Harmful Software, click Scan your computer.
  • On the left, check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
  • To retrieve the removal information, please do the following:
    • After reboot, double-click the SUPERAntispyware icon on your desktop.
    • Click Preferences. Click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • It will open in your default text editor (such as Notepad/Wordpad).
    • Please highlight everything in the notepad, then right-click and choose Copy.
    • Click Close and Close again to exit the program.
  • Please post that information with a new HijackThis log.
Step 7
  • Please download the ATF-Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Check the boxes to the left of:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch (Windows XP) only
    • Java Cache
  • The rest are optional - if you want to remove them all, check Select All.
  • Click the Empty Selected button.
  • When you get the Done Cleaning message, click OK.
  • Follow the same steps for Firefox or Opera. You have the option of checking No if you want to save your passwords.
  • Click Exit on the Main menu to close the program.
Do not run it yet.

Step 8
  • According to your Internet connection, please disconnect from the Internet. Close ALL browser windows (including this one).
    • Physically remove the cable for your broadband Internet service “Always On” Connection from your computer.
    • Turn your modem off.
    • Disconnect your modem cable from your computer.
  • Turn the device off for Hand-held wireless connections.
  • Exit all processes and items in your System tray.
Step 9

During the process of removing malware from your computer, there are times you may need to use specialized fix tools. Certain embedded files that are part of these specialized fix tools may be detected by your antivirus or anti-malware scanner as a RiskTool, Hacking tool, Potentially unwanted tool, a virus or a Trojan when that is not the case.
These tools have been carefully created and tested by security experts so if your antivirus or anti-malware program flags them as malware, then it is a False Positive. Antivirus scanners cannot distinguish between good and malicious use of such programs; therefore, they may alert you or even automatically remove them. In these cases, the removal of these files can have unpredictable results and unintentional results.
To avoid any problems while using a specialized fix tool, it is very important that you temporarily disable your antivirus and/or anti-malware programs before using the specialized fix tool.
When your system has been cleaned, it is important that you enable your security programs to avoid reinfection.
Please disable the following program(s):

SUPERAntiSpyware

We need to disable SUPERAntiSpyware as it may interfere with the fixes that we need to make.
  • Right click on the icon in your System Tray.
  • Click Exit
  • Make sure that the program, SUPERAntiSpyware itself, is also closed/not running.
Now we will address the HijackThis fixes.

Step 10

Please run HijackThis and click Scan. Place checks next to the following entries (make sure not to miss any):

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked.

Step 11

Optional Fixes is the name that we use for fixes for unnecessary programs that load during startup and run in the background. These programs are not required to start automatically as you can start them manually if you need them. You would be removing the program from your startup but you would not be removing the program itself.

Your computer may be sluggish due to the many programs loading during startup and running in the background that are not necessary. Windows has a facility for starting programs at startup time. Some of these programs are required for your computer and the applications installed on it to run correctly. A good example of such a program is a virus-checking application that must always run, constantly checking for and isolating or removing files with viruses. Other such programs are not strictly required, or are optional. In some cases, you can gain significant performance enhancements by disabling the automatic startup of these programs. In many cases, the functionality offered by the programs is still available by starting the programs manually by, for example, starting the program from the Windows Start->Programs menu. Media players and instant messaging programs often fall into this category. In fact, it is common for many modern software applications, when installed, to add programs at startup that add items to the system tray or shortcut (context) menus in Windows Explorer to provide quick access to the features and functions of these applications. While they may be useful, they do increase boot time and consume system resources. It is advised that you disable these programs so that they do not take up necessary resources or slow the boot time.

Other than ScanRegistry, SystemTray, StateMgr, antivirus program entries, and firewall program entries, very few others need to load and run.

Read the articles below to see if it applies to your computer problem with being slow to respond.
Slow_Computer_Check_here_first_it_may_not_be_malware.
Help! My computer is slow!
50 Tips for a Super Fast PC
4 Ways to Speed Up Your Computer's Performance
It's not always malware: How to fix the top 10 Internet Explorer issues

If you decide that you want to stop the Optional Fixes in your startup, let me know and I will give you a list with instructions. You would be removing the program from your startup but you would not be removing the program itself.

Step 12

Let’s run ATF-Cleaner to ensure no malware is hiding in temporary folders and for general computer cleanup to free space on your computer.

Step 13

Please run HijackThis in Normal Mode and post:
  • the list of file names and locations for any files that cannot be cleaned / deleted that were reported after you completed the online scans.
  • the log from MalwareBytes
  • the log from SUPERAntiSpyware
  • a new HijackThis log
Please advise me of any problems you still have.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#12 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:03:54 AM

Posted 02 February 2009 - 08:51 AM

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users