Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Problems with IE 7 running slow (includes a Hijack this log)


  • This topic is locked This topic is locked
16 replies to this topic

#1 JamesD7004

JamesD7004

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 10 March 2009 - 04:30 PM

We have been having problems with our IE 7 . As long as the Ie window is open it will continue to eat up resources. When we run an antivirus scanner it says that cabvie.dll is a bad file and then it either cant heal it or it comes back everytime. Here is a Hijack log.. Thanks for any help


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:30:24 PM, on 3/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1188286622\ee\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11326A43-DF7C-425E-A372-8D1B9C12BC46} - C:\WINDOWS\system32\cabvie.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {477840F3-BA52-44D9-8E41-38D61CAA010F} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {646EFCF2-01DD-4825-AF25-828DB6942EDB} - (no file)
O2 - BHO: (no name) - {6CEC3506-0B90-4580-81E2-5EC62E9FB08D} - (no file)
O2 - BHO: (no name) - {78986BC5-7A0B-4DE6-8855-7258B2939B09} - (no file)
O2 - BHO: (no name) - {7a6ded47-6912-408d-9888-c1200b89f6f7} - (no file)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - C:\WINDOWS\system32\hgggfcc.dll (file missing)
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\helper.dll (file missing)
O2 - BHO: (no name) - {E1F9FA41-41FF-397E-8B2A-4BE679F40FE1} - (no file)
O2 - BHO: (no name) - {FD445C51-2E37-4055-848D-DD545538137B} - C:\WINDOWS\system32\ddabc.dll (file missing)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {974281aa-3b5a-4fe5-8259-dceb5ea21722} - C:\WINDOWS\system32\mst120.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: hgggfcc - hgggfcc.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7191 bytes

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 11 March 2009 - 03:38 AM

Hi,

* Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 13 March 2009 - 03:13 PM

Thanks for all of your help in advance.

Here are the 2 log files

Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 2

3/13/2009 1:06:24 PM
mbam-log-2009-03-13 (13-06-24).txt

Scan type: Quick Scan
Objects scanned: 78047
Time elapsed: 13 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 40
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 69

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e3fbde2-7dbd-4040-85d9-29bbc559c129} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hgggfcc (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e3fbde2-7dbd-4040-85d9-29bbc559c129} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11326a43-df7c-425e-a372-8d1b9c12bc46} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{11326a43-df7c-425e-a372-8d1b9c12bc46} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\bndshell3.bho (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndshell3.bho.1 (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\egmulhxk.msdn_hlp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\main.bho (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fc6e3735-57b3-48b8-9002-54c155215632} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{4a9967ab-4c5c-4325-b8c9-4f2be9142c81} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{a0e1054b-01ee-4d57-a059-4d99f339709f} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d1c4e81-a32a-416b-bcdb-33b3ef3617d3} (Adware.Need2Find) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{343ce214-9998-4b21-a151-ffe970167297} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8b27cc68-110c-46a9-80d3-f3107de6eb98} (Trojan.Adware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{477840f3-ba52-44d9-8e41-38d61caa010f} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{8e3fbde2-7dbd-4040-85d9-29bbc559c129} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\hgggfcc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cabvie.dll (Trojan.BHO.H) -> Delete on reboot.
C:\WINDOWS\system32\KEGSBVCB.0LL (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SVQGNWPR.0LL (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\YDGQTVGQ.0LL (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\Microsoft Office\WINWORD.EXE (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM53526836.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM53526836.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ESHOPEE.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\din.ip (Malware.Trace) -> Quarantined and deleted successfully.
C:\RECYCLER\ADAPT_Installer.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\b148.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\blank.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\box_2.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\button_buynow.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\button_freescan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_footer.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_block.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_remove.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_scan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\detect.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\download_btn.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\download_now_btn.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\footer_back.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_1.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_2.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_3.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_4.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_free_scan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\infected.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\main_back.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_2_header.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_2_name_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_features.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\pt.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\rating.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\s_detect.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\screenshot.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\sep_hor.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\sep_vert.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\shadow.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\shadow_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\spacer.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_gray.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_gray_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\style.css (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\v.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\warning_icon.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\win_logo.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\x.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\764.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\aconti.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\hotporn.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sznf.ascii (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpqaqlqx.bin (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jpewocmz.ini (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Quarantined and deleted successfully.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:11:56 PM, on 3/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\AOL\1188286622\ee\aolsoftware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11326A43-DF7C-425E-A372-8D1B9C12BC46} - C:\WINDOWS\system32\cabvie.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {646EFCF2-01DD-4825-AF25-828DB6942EDB} - (no file)
O2 - BHO: (no name) - {6CEC3506-0B90-4580-81E2-5EC62E9FB08D} - (no file)
O2 - BHO: (no name) - {78986BC5-7A0B-4DE6-8855-7258B2939B09} - (no file)
O2 - BHO: (no name) - {7a6ded47-6912-408d-9888-c1200b89f6f7} - (no file)
O2 - BHO: (no name) - {E1F9FA41-41FF-397E-8B2A-4BE679F40FE1} - (no file)
O2 - BHO: (no name) - {FD445C51-2E37-4055-848D-DD545538137B} - C:\WINDOWS\system32\ddabc.dll (file missing)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {974281aa-3b5a-4fe5-8259-dceb5ea21722} - C:\WINDOWS\system32\mst120.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6658 bytes

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 13 March 2009 - 03:19 PM

Hi,

Database version: 1749

This one is way outdated. It's already dbversion=1845 now.. so, you have to run it again...
  • Start MalwareBytes and click the Update tab. There click "Check for updates"
  • Once the updates are downloaded, perform a full scan again.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log, then we'll proceed from there with new steps.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 13 March 2009 - 08:01 PM

Thanks again

I thought ui updated it when it installed sorry ..

here are the new ones



Malwarebytes' Anti-Malware 1.34
Database version: 1846
Windows 5.1.2600 Service Pack 2

3/13/2009 7:51:01 PM
mbam-log-2009-03-13 (19-51-01).txt

Scan type: Quick Scan
Objects scanned: 81207
Time elapsed: 10 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11326a43-df7c-425e-a372-8d1b9c12bc46} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{11326a43-df7c-425e-a372-8d1b9c12bc46} (Trojan.BHO.H) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\cabvie.dll (Trojan.BHO.H) -> Delete on reboot.
C:\WINDOWS\Temp\qxqnfwea.dat (Rootkit.Agent) -> Delete on reboot.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:56:41 PM, on 3/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11326A43-DF7C-425E-A372-8D1B9C12BC46} - C:\WINDOWS\system32\cabvie.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {646EFCF2-01DD-4825-AF25-828DB6942EDB} - (no file)
O2 - BHO: (no name) - {6CEC3506-0B90-4580-81E2-5EC62E9FB08D} - (no file)
O2 - BHO: (no name) - {78986BC5-7A0B-4DE6-8855-7258B2939B09} - (no file)
O2 - BHO: (no name) - {7a6ded47-6912-408d-9888-c1200b89f6f7} - (no file)
O2 - BHO: (no name) - {E1F9FA41-41FF-397E-8B2A-4BE679F40FE1} - (no file)
O2 - BHO: (no name) - {FD445C51-2E37-4055-848D-DD545538137B} - C:\WINDOWS\system32\ddabc.dll (file missing)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {974281aa-3b5a-4fe5-8259-dceb5ea21722} - C:\WINDOWS\system32\mst120.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6512 bytes

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 14 March 2009 - 01:13 AM

Hi,

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix in your next reply.

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 15 March 2009 - 02:40 PM

Combofix Log


ComboFix 09-03-14.02 - Whitney Eyres 2009-03-15 14:22:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.677 [GMT -7:00]
Running from: c:\documents and settings\Whitney Eyres\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\application data\Desktop_.ini
c:\application data\Microsoft\Desktop_.ini
c:\documents and settings\All Users\Documents\AOL Downloads\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\My Playlists\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Sample Music\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Sample Playlists\01D8FA17\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Sample Playlists\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Sync Playlists\3A75928\Desktop_.ini
c:\documents and settings\All Users\Documents\My Music\Sync Playlists\Desktop_.ini
c:\documents and settings\All Users\Documents\My Pictures\Desktop_.ini
c:\documents and settings\All Users\Documents\My Pictures\Sample Pictures\Desktop_.ini
c:\documents and settings\All Users\Documents\My Videos\Desktop_.ini
c:\documents and settings\Whitney Eyres\Application Data\DOBE~1
c:\extra files\Desktop_.ini
c:\install files\Ahead_Nero_v7.0_KeyGen_Only-PARADOX\Desktop_.ini
c:\install files\DAEMON TOOLS\Desktop_.ini
c:\install files\Desktop_.ini
c:\install files\Microsoft.Office.2003.SP2.AIO.DVD-XiSO\Desktop_.ini
c:\install files\NERO.7.ULTRA.EDITION.PROPER-ADDICTION\CD1\Desktop_.ini
c:\install files\NERO.7.ULTRA.EDITION.PROPER-ADDICTION\CD2\Desktop_.ini
c:\install files\NERO.7.ULTRA.EDITION.PROPER-ADDICTION\Desktop_.ini
c:\install files\Nero\Desktop_.ini
c:\install files\Power Dvd 4.0\Desktop_.ini
c:\install files\Win ISO\Desktop_.ini
c:\install files\Win ISO\WinISO_v5[1].3_by_ReaLIsTy\Desktop_.ini
c:\install files\Winace\Desktop_.ini
c:\install files\Winzip 70\Desktop_.ini
c:\install files\wrar2300\Desktop_.ini
c:\install files\wrar2300\tsrh-wrar3b6uni_crk\Desktop_.ini
c:\install files\wrar2300\wrar2300\Desktop_.ini
c:\music\Desktop_.ini
c:\music\Downloads\Desktop_.ini
c:\music\iTunes Music\3 Doors Down\Away from the Sun\Desktop_.ini
c:\music\iTunes Music\3 Doors Down\Desktop_.ini
c:\music\iTunes Music\Ashlee Simpson\Autobiography\Desktop_.ini
c:\music\iTunes Music\Ashlee Simpson\Desktop_.ini
c:\music\iTunes Music\Ashlee Simpson\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Avril Lavigne\Desktop_.ini
c:\music\iTunes Music\Avril Lavigne\My World\Desktop_.ini
c:\music\iTunes Music\Avril Lavigne\Under My Skin\Desktop_.ini
c:\music\iTunes Music\Avril Lavigne\Unknown Album (04_05_2002 5_22_32 PM)\Desktop_.ini
c:\music\iTunes Music\Avril Lavigne\Unknown Album (4_23_2002 6_59_32 PM)\Desktop_.ini
c:\music\iTunes Music\Barbra Streisand_Celine Dion\Desktop_.ini
c:\music\iTunes Music\Barbra Streisand_Celine Dion\Let's Talk About Love\Desktop_.ini
c:\music\iTunes Music\Bowling for soup\Desktop_.ini
c:\music\iTunes Music\Bowling for soup\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Britney Spears\Desktop_.ini
c:\music\iTunes Music\Britney Spears\In The Zone\Desktop_.ini
c:\music\iTunes Music\Britney Spears\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Busta Rhymes\Desktop_.ini
c:\music\iTunes Music\Busta Rhymes\It Aint Safe No More\Desktop_.ini
c:\music\iTunes Music\Celine Dion\Desktop_.ini
c:\music\iTunes Music\Celine Dion\DROP IT OFF\Desktop_.ini
c:\music\iTunes Music\Celine Dion\Let's Talk About Love\Desktop_.ini
c:\music\iTunes Music\Chingy\Desktop_.ini
c:\music\iTunes Music\Chingy\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Coldplay\Desktop_.ini
c:\music\iTunes Music\Coldplay\X&Y\Desktop_.ini
c:\music\iTunes Music\danger hardcore team\Desktop_.ini
c:\music\iTunes Music\danger hardcore team\Onbekend album (6_12_2003 14_25_23)\Desktop_.ini
c:\music\iTunes Music\Daniel Beddingfield\Desktop_.ini
c:\music\iTunes Music\Daniel Beddingfield\Gotta Get Thru This\Desktop_.ini
c:\music\iTunes Music\Dashboard Confessonials\Desktop_.ini
c:\music\iTunes Music\Dashboard Confessonials\Unknown Album (5_15_2002 12_32_13 AM)\Desktop_.ini
c:\music\iTunes Music\David Bowie Queen\Desktop_.ini
c:\music\iTunes Music\David Bowie Queen\Unknown Album\Desktop_.ini
c:\music\iTunes Music\David Bowie_Queen\Desktop_.ini
c:\music\iTunes Music\David Bowie_Queen\Grosse Pointe Blank\Desktop_.ini
c:\music\iTunes Music\Desktop_.ini
c:\music\iTunes Music\Dixie Chicks\Desktop_.ini
c:\music\iTunes Music\Dixie Chicks\Fly\Desktop_.ini
c:\music\iTunes Music\Dixie Chicks\Home\Desktop_.ini
c:\music\iTunes Music\Dolly Parton\Desktop_.ini
c:\music\iTunes Music\Dolly Parton\Halos & Horns\Desktop_.ini
c:\music\iTunes Music\Dolly Parton\The Best Of Dolly Parton\Desktop_.ini
c:\music\iTunes Music\Dolly Parton\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Elton John\Der König der Löwen\Desktop_.ini
c:\music\iTunes Music\Elton John\Desktop_.ini
c:\music\iTunes Music\elvis presley\Desktop_.ini
c:\music\iTunes Music\elvis presley\The 50 Greatest Love Songs [UK] Disc 2\Desktop_.ini
c:\music\iTunes Music\Evanescence\Desktop_.ini
c:\music\iTunes Music\Evanescence\Fallen\Desktop_.ini
c:\music\iTunes Music\Eve_Gwen Stefani\Desktop_.ini
c:\music\iTunes Music\Eve_Gwen Stefani\Love.Angel.Music.Baby [Deluxe Edition]\Desktop_.ini
c:\music\iTunes Music\Fountains of Wayne\Desktop_.ini
c:\music\iTunes Music\Fountains of Wayne\Welcome Interstate Managers\Desktop_.ini
c:\music\iTunes Music\Frank Sinatra\Desktop_.ini
c:\music\iTunes Music\Frank Sinatra\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Freeway\Desktop_.ini
c:\music\iTunes Music\Freeway\DJ Clue_ Show Me The Money 200\Desktop_.ini
c:\music\iTunes Music\Gavin DeGraw\Chariot\Desktop_.ini
c:\music\iTunes Music\Gavin DeGraw\Desktop_.ini
c:\music\iTunes Music\ghost Town DJs\Desktop_.ini
c:\music\iTunes Music\ghost Town DJs\Unknown Album (11_30_2003 10_40_11 PM)\Desktop_.ini
c:\music\iTunes Music\Goo Goo Dolls\Desktop_.ini
c:\music\iTunes Music\Goo Goo Dolls\Gutterflower\Desktop_.ini
c:\music\iTunes Music\Gwen Stefani\Desktop_.ini
c:\music\iTunes Music\Gwen Stefani\Love.Angel.Music.Baby\Desktop_.ini
c:\music\iTunes Music\Hermes House Band\Desktop_.ini
c:\music\iTunes Music\Hermes House Band\Live Is Life\Desktop_.ini
c:\music\iTunes Music\Hilary Duff\Desktop_.ini
c:\music\iTunes Music\Hilary Duff\Metamorphosis\Desktop_.ini
c:\music\iTunes Music\Hoobastank\Desktop_.ini
c:\music\iTunes Music\Hoobastank\The Reason\Desktop_.ini
c:\music\iTunes Music\Howie Day\Desktop_.ini
c:\music\iTunes Music\Howie Day\Stop All the World\Desktop_.ini
c:\music\iTunes Music\Ilse Delange\Desktop_.ini
c:\music\iTunes Music\Ilse Delange\Here I Am\Desktop_.ini
c:\music\iTunes Music\Jack Johnson\Como Uma Onda - Internacional\Desktop_.ini
c:\music\iTunes Music\Jack Johnson\Danilo\Desktop_.ini
c:\music\iTunes Music\Jack Johnson\Desktop_.ini
c:\music\iTunes Music\Jack Jonhson\Danilo\Desktop_.ini
c:\music\iTunes Music\Jack Jonhson\Desktop_.ini
c:\music\iTunes Music\Jesse McCartney\Beautiful Soul\Desktop_.ini
c:\music\iTunes Music\Jesse McCartney\Desktop_.ini
c:\music\iTunes Music\Jesse McCartney\The Princess Diaries 2_ Royal Engagement\Desktop_.ini
c:\music\iTunes Music\Joe Cocker\Desktop_.ini
c:\music\iTunes Music\Joe Cocker\The Best of Joe Cocker [Capitol]\Desktop_.ini
c:\music\iTunes Music\Jonathan Foreman, Mandy Moore\A Walk to Remember\Desktop_.ini
c:\music\iTunes Music\Jonathan Foreman, Mandy Moore\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Christ the King Anniversary Co\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Closer [Bonus Tracks] Disc 1\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Closer\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Josh Groban\Desktop_.ini
c:\music\iTunes Music\Josh Groban\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Kaci\Desktop_.ini
c:\music\iTunes Music\Kaci\I'm Not Anybodys Girl\Desktop_.ini
c:\music\iTunes Music\Kelly Clarkson\Breakaway\Desktop_.ini
c:\music\iTunes Music\Kelly Clarkson\Desktop_.ini
c:\music\iTunes Music\Kelly Clarkson\Thankful\Desktop_.ini
c:\music\iTunes Music\Kelly Clarkson_Tamyra Gray\Desktop_.ini
c:\music\iTunes Music\Kelly Clarkson_Tamyra Gray\Thankful\Desktop_.ini
c:\music\iTunes Music\Korn\Desktop_.ini
c:\music\iTunes Music\Korn\Greatest Hits, Vol. 1 Disc 1\Desktop_.ini
c:\music\iTunes Music\Korn\Unknown Album (3_10_2004 5_24_29 p.m.)\Desktop_.ini
c:\music\iTunes Music\Leann Rimes\Desktop_.ini
c:\music\iTunes Music\Leann Rimes\Greatest Hits\Desktop_.ini
c:\music\iTunes Music\Lil Jon_Ludacris_Usher\Desktop_.ini
c:\music\iTunes Music\Lil Jon_Ludacris_Usher\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Lillix\Desktop_.ini
c:\music\iTunes Music\Lillix\Falling Uphill\Desktop_.ini
c:\music\iTunes Music\Lillix\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Madagascar\Desktop_.ini
c:\music\iTunes Music\Madagascar\Kid's Dance Express_ Hip Hop Party Disc\Desktop_.ini
c:\music\iTunes Music\Mandy Moore\Desktop_.ini
c:\music\iTunes Music\Mandy Moore\Mandy Moore\Desktop_.ini
c:\music\iTunes Music\Mandy Moore\OST A Walk To Remember\Desktop_.ini
c:\music\iTunes Music\Mariah Carey\Desktop_.ini
c:\music\iTunes Music\Mariah Carey\We Belong Together\Desktop_.ini
c:\music\iTunes Music\Mark Hoppus, Simple Plan\Atticus_ Dragging the Lake\Desktop_.ini
c:\music\iTunes Music\Mark Hoppus, Simple Plan\Desktop_.ini
c:\music\iTunes Music\Maroon 5\Desktop_.ini
c:\music\iTunes Music\Maroon 5\Songs About Jane\Desktop_.ini
c:\music\iTunes Music\Michelle Branch\Desktop_.ini
c:\music\iTunes Music\Michelle Branch\Hotel Paper\Desktop_.ini
c:\music\iTunes Music\Nickelback\Desktop_.ini
c:\music\iTunes Music\Nickelback\The Long Road\Desktop_.ini
c:\music\iTunes Music\Original Soundtrack\Desktop_.ini
c:\music\iTunes Music\Original Soundtrack\Troy\Desktop_.ini
c:\music\iTunes Music\Pat Benatar\Best Shots\Desktop_.ini
c:\music\iTunes Music\Pat Benatar\Desktop_.ini
c:\music\iTunes Music\Phil Collins\Desktop_.ini
c:\music\iTunes Music\Phil Collins\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Queen\Desktop_.ini
c:\music\iTunes Music\Queen\Live Magic\Desktop_.ini
c:\music\iTunes Music\Rachael Lampa\A Walk to Remember\Desktop_.ini
c:\music\iTunes Music\Rachael Lampa\Desktop_.ini
c:\music\iTunes Music\Simple Plan\Desktop_.ini
c:\music\iTunes Music\Simple Plan\No Helmets, No Pads... Just Balls\Desktop_.ini
c:\music\iTunes Music\Simple Plan\No Pads, no Helmets ... Just B\Desktop_.ini
c:\music\iTunes Music\Simple Plan\Still Not Getting Any... [Bonus DVD] Dis\Desktop_.ini
c:\music\iTunes Music\Stacie Orrico\Desktop_.ini
c:\music\iTunes Music\Stacie Orrico\Stacie Orrico\Desktop_.ini
c:\music\iTunes Music\Sting\Desktop_.ini
c:\music\iTunes Music\Sting\Unknown Album (23_06_2003 16_25_42)\Desktop_.ini
c:\music\iTunes Music\The Killers\Desktop_.ini
c:\music\iTunes Music\The Killers\Unknown Album (19_03_2004 18_06_36)\Desktop_.ini
c:\music\iTunes Music\The Rolling Stones\Desktop_.ini
c:\music\iTunes Music\The Rolling Stones\Unknown Album\Desktop_.ini
c:\music\iTunes Music\The Supremes\Desktop_.ini
c:\music\iTunes Music\The Supremes\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Tiffany\Desktop_.ini
c:\music\iTunes Music\Tiffany\Tiffany\Desktop_.ini
c:\music\iTunes Music\Tim McGraw\Desktop_.ini
c:\music\iTunes Music\Tim McGraw\Live Like You Were Dying\Desktop_.ini
c:\music\iTunes Music\U2\Best of 1980-1990_B-Sides Disc 2\Desktop_.ini
c:\music\iTunes Music\U2\Desktop_.ini
c:\music\iTunes Music\U2\Threesome\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Álbum Desconhecido (04-03-2005 20_28_24)\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Great hit &fin Perfor\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Unknown Album (17_4_2004 11_33_56)\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Unknown Album (2_28_2004 3_50_09 PM)\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Unknown Album (8_16_2002 10_18_13 PM)\Desktop_.ini
c:\music\iTunes Music\Unknown Artist\Unknown Album\Desktop_.ini
c:\music\iTunes Music\Usher\8701\Desktop_.ini
c:\music\iTunes Music\Usher\Confessions\Desktop_.ini
c:\music\iTunes Music\Usher\Desktop_.ini
c:\music\iTunes Music\Various Artists\Desktop_.ini
c:\music\iTunes Music\Various Artists\T769\Desktop_.ini
c:\music\Kazaa MP3's\Desktop_.ini
c:\music\Shareaza Downloads\Desktop_.ini
c:\program files\curity~1
c:\recycler\Desktop_.ini
c:\temp\1cb
c:\temp\1cb\Desktop_.ini
c:\temp\1cb\syscheck.log
c:\temp\Desktop_.ini
c:\temp\tn3
c:\temp\tn3\Desktop_.ini
c:\temp\tpBe12
c:\temp\tpBe12\Desktop_.ini
c:\temp\tpBe12\etFr.log
c:\windows\system32\abc2
c:\windows\system32\ahyeqmug.ini
c:\windows\system32\bcvbsgek.ini
c:\windows\system32\bweyjvam.ini
c:\windows\system32\cbadd.ini
c:\windows\system32\cbadd.ini2
c:\windows\system32\ckoxxrnx.ini
c:\windows\system32\cmevdxet.ini
c:\windows\system32\cqcptoyi.ini
c:\windows\system32\csmnqpeq.ini
c:\windows\system32\cswxqnbf.ini
c:\windows\system32\cufvccin.ini
c:\windows\system32\dhnspiiu.ini
c:\windows\system32\doqikily.ini
c:\windows\system32\drvfcbfh.ini
c:\windows\system32\dssjenff.ini
c:\windows\system32\egboidft.ini
c:\windows\system32\ekknpmye.ini
c:\windows\system32\elpfxjvx.ini
c:\windows\system32\esgaaucc.ini
c:\windows\system32\ex1
c:\windows\system32\ffhjxkgp.ini
c:\windows\system32\fhuojpcm.ini
c:\windows\system32\forprsbk.ini
c:\windows\system32\fyvpisde.ini
c:\windows\system32\ghbdvovc.ini
c:\windows\system32\glhobpcw.ini
c:\windows\system32\gpsmtawt.ini
c:\windows\system32\gxqxsobn.ini
c:\windows\system32\haqeogtb.ini
c:\windows\system32\hospesew.ini
c:\windows\system32\ifknfopb.ini
c:\windows\system32\igayqbwd.ini
c:\windows\system32\iguvnfpx.ini
c:\windows\system32\ikxvdeax.ini
c:\windows\system32\ineWc01
c:\windows\system32\jfkqtbom.ini
c:\windows\system32\jhjgrnaj.ini
c:\windows\system32\jjjajfes.ini
c:\windows\system32\jxfuwvea.ini
c:\windows\system32\kfgsknov.ini
c:\windows\system32\kgaakbmm.ini
c:\windows\system32\kiqfqjpk.ini
c:\windows\system32\kmqhslve.ini
c:\windows\system32\lciakrlk.ini
c:\windows\system32\lgpxuila.ini
c:\windows\system32\loalivuk.ini
c:\windows\system32\mievughg.ini
c:\windows\system32\mrtxctlk.ini
c:\windows\system32\msjcprqt.ini
c:\windows\system32\msuduhoj.ini
c:\windows\system32\NSIS.Library.RegTool.v2.{19746A28-036E-48BC-90A2-5F0FA4CA3A20}.exe
c:\windows\system32\oc9
c:\windows\system32\ohorhbvj.ini
c:\windows\system32\ohtbhmsg.ini
c:\windows\system32\omqwbwxv.ini
c:\windows\system32\opvnklhq.ini
c:\windows\system32\oxtxqvty.ini
c:\windows\system32\oyeeecxj.ini
c:\windows\system32\pbfdipeb.ini
c:\windows\system32\pjeuhyym.ini
c:\windows\system32\ptnuwmla.ini
c:\windows\system32\pulrllmm.ini
c:\windows\system32\qarcqsme.ini
c:\windows\system32\qgvtqgdy.ini
c:\windows\system32\qieblqvb.ini
c:\windows\system32\qjnhohlf.ini
c:\windows\system32\qnvupbxs.ini
c:\windows\system32\qtlowwtn.ini
c:\windows\system32\rmxoiltp.ini
c:\windows\system32\rpcgqmgd.ini
c:\windows\system32\rpwngqvs.ini
c:\windows\system32\rsybykfq.ini
c:\windows\system32\rudqratq.ini
c:\windows\system32\rvwtuocc.ini
c:\windows\system32\sbulfhnd.ini
c:\windows\system32\sfjdmupe.ini
c:\windows\system32\shel9
c:\windows\system32\srhawhcl.ini
c:\windows\system32\tdbywleh.ini
c:\windows\system32\tisieoat.ini
c:\windows\system32\uagcrbds.ini
c:\windows\system32\ugbhhdxi.ini
c:\windows\system32\vegigfis.ini
c:\windows\system32\vtfrkwkx.ini
c:\windows\system32\vvjmmlun.ini
c:\windows\system32\vxatxvvu.ini
c:\windows\system32\winqlfgk.ini
c:\windows\system32\xpdlbdji.ini
c:\windows\system32\xyiscfds.ini
c:\windows\system32\ybhjcwsg.ini
c:\windows\system32\ygfmtrbd.ini
c:\windows\system32\ymmcrhve.ini
c:\windows\ymante~1

.
((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.

2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\documents and settings\Whitney Eyres\Application Data\Malwarebytes
2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-13 12:50 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-13 12:50 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-12 09:02 . 2009-03-12 09:02 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-12 09:02 . 2009-03-12 09:02 1,409 --a------ c:\windows\QTFont.for
2009-03-10 16:03 . 2009-03-10 16:03 <DIR> d-------- c:\program files\Uniblue
2009-03-09 13:26 . 2009-03-09 13:26 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-24 15:41 . 2009-03-11 03:00 1,374 --a------ c:\windows\imsins.BAK
2009-02-23 22:21 . 2009-03-15 10:56 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-23 22:18 . 2009-03-14 08:46 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-23 22:18 . 2009-02-23 22:18 <DIR> d-------- c:\program files\AVG
2009-02-23 22:18 . 2009-03-13 13:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-23 22:18 . 2009-02-23 22:18 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-23 22:18 . 2009-02-23 22:18 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-23 22:18 . 2009-02-23 22:18 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-23 21:56 . 2009-02-23 21:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-02-23 20:27 . 2009-02-23 20:27 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-09 20:27 609 ----a-w c:\program files\Shortcut to WINWORD.lnk
2009-02-24 07:07 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-24 05:40 --------- d-----w c:\program files\Common
2009-02-24 04:51 --------- d-----w c:\program files\CCleaner
2009-02-24 04:40 --------- d-----w c:\documents and settings\Whitney Eyres\Application Data\AntiSpyware
2009-02-24 04:20 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-24 03:27 --------- d-----w c:\program files\Lavasoft
2009-02-24 03:26 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-20 22:29 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11326A43-DF7C-425E-A372-8D1B9C12BC46}]
2004-08-04 00:56 84992 --a------ c:\windows\system32\cabvie.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-01 282624]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-23 1601304]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-23 22:18 10520 c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2007-04-17 23:49 50736 c:\program files\AOL 9.0\aol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 05:50 71216 c:\program files\Common Files\AOL\acs\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2002-09-24 12:43 73728 c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2006-08-01 12:28 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-10-10 06:49 1519616 c:\windows\system32\nwiz.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" -b
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" -tray
"Vstzfq"=c:\windows\?ymantec\r?gedit.exe
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"SfKg6w"=c:\documents and settings\Whitney Eyres\Application Data\Microsoft\Windows\wjqin.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"winshow"="c:\windows\winshow.exe"
"ProfileWatcher"=c:\program files\ProfileWatcher\profilewatcher.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"io43mvuiw4kj"=c:\windows\io43mvuiw4kj.exe
"HostManager"=c:\program files\Common Files\AOL\1188286622\ee\AOLSoftware.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"mezenoh"=c:\program files\Windows NT\mezenoh77798.exe
"BM53526836"=Rundll32.exe "c:\windows\system32\csljgpcp.dll",s
"50615baa"=rundll32.exe "c:\windows\system32\texdvemc.dll",b
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Common Files\\AOL\\1188286622\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 kenjnqde;kenjnqde;c:\windows\system32\drivers\trekqhaa.dat --> c:\windows\system32\drivers\trekqhaa.dat [?]
R0 St323dk;St323dk;c:\windows\system32\drivers\st323dk.sys [2002-10-13 88736]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-23 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-23 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-23 298264]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\WHITNE~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\WHITNE~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2007-12-26 44928]
.
- - - - ORPHANS REMOVED - - - -

BHO-{646EFCF2-01DD-4825-AF25-828DB6942EDB} - (no file)
BHO-{6CEC3506-0B90-4580-81E2-5EC62E9FB08D} - (no file)
BHO-{78986BC5-7A0B-4DE6-8855-7258B2939B09} - (no file)
BHO-{7a6ded47-6912-408d-9888-c1200b89f6f7} - (no file)
BHO-{E1F9FA41-41FF-397E-8B2A-4BE679F40FE1} - (no file)
BHO-{FD445C51-2E37-4055-848D-DD545538137B} - c:\windows\system32\ddabc.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ebay.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 14:31:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kenjnqde]
"ImagePath"="system32\drivers\trekqhaa.dat"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\AOL\acs\AOLacsd.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-03-15 14:34:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-15 21:34:17

Pre-Run: 166,482,915,328 bytes free
Post-Run: 166,609,342,464 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

486 --- E O F --- 2009-03-11 10:00:43

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 15 March 2009 - 05:22 PM

Hi,

* Open notepad - don't use any other texteditor than notepad or the script will fail.
Copy/paste the text in the quotebox below into notepad:

File::
c:\windows\system32\cabvie.dll
Collect::[8]
c:\windows\system32\drivers\trekqhaa.dat
Driver::
kenjnqde
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11326A43-DF7C-425E-A372-8D1B9C12BC46}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Vstzfq"=-
"SfKg6w"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"winshow"=-
"io43mvuiw4kj"=-
"mezenoh"=-
"BM53526836"=-
"50615baa"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again.
Then, please visit this site:
http://www.bleepingcomputer.com/submit-malware.php?channel=8
Where it says: "Browse to the file you want to submit", use the Browse button to navigate to the following file: C:\Qoobox\Quarantine\[8]-Submit_date_time.zip (date_time will be replaced with the date and time when this file was created)
Then click the "Send File" button below in order to upload it.

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 16 March 2009 - 01:39 AM

I really appreciate all of your help!



ComboFix 09-03-15.01 - Whitney Eyres 2009-03-15 13:30:59.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.604 [GMT -7:00]
Running from: c:\documents and settings\Whitney Eyres\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\cabvie.dll
c:\windows\system32\drivers\trekqhaa.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_KENJNQDE
-------\Service_kenjnqde


((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.

2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\documents and settings\Whitney Eyres\Application Data\Malwarebytes
2009-03-13 12:50 . 2009-03-13 12:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-13 12:50 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-13 12:50 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-12 09:02 . 2009-03-12 09:02 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-12 09:02 . 2009-03-12 09:02 1,409 --a------ c:\windows\QTFont.for
2009-03-10 16:03 . 2009-03-10 16:03 <DIR> d-------- c:\program files\Uniblue
2009-03-09 13:26 . 2009-03-09 13:26 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-24 15:41 . 2009-03-11 03:00 1,374 --a------ c:\windows\imsins.BAK
2009-02-23 22:21 . 2009-03-15 10:56 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-23 22:18 . 2009-03-15 18:20 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-23 22:18 . 2009-02-23 22:18 <DIR> d-------- c:\program files\AVG
2009-02-23 22:18 . 2009-03-13 13:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-23 22:18 . 2009-02-23 22:18 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-23 22:18 . 2009-02-23 22:18 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-23 22:18 . 2009-02-23 22:18 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-23 21:56 . 2009-02-23 21:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-02-23 20:27 . 2009-02-23 20:27 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-09 20:27 609 ----a-w c:\program files\Shortcut to WINWORD.lnk
2009-02-24 07:07 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-24 05:40 --------- d-----w c:\program files\Common
2009-02-24 04:51 --------- d-----w c:\program files\CCleaner
2009-02-24 04:40 --------- d-----w c:\documents and settings\Whitney Eyres\Application Data\AntiSpyware
2009-02-24 04:20 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-24 03:27 --------- d-----w c:\program files\Lavasoft
2009-02-24 03:26 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-20 22:29 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-01 282624]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-23 1601304]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-23 22:18 10520 c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2007-04-17 23:49 50736 c:\program files\AOL 9.0\aol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 05:50 71216 c:\program files\Common Files\AOL\acs\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2002-09-24 12:43 73728 c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2006-08-01 12:28 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-10-10 06:49 1519616 c:\windows\system32\nwiz.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" -b
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" -tray
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ProfileWatcher"=c:\program files\ProfileWatcher\profilewatcher.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"HostManager"=c:\program files\Common Files\AOL\1188286622\ee\AOLSoftware.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Common Files\\AOL\\1188286622\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 St323dk;St323dk;c:\windows\system32\drivers\st323dk.sys [2002-10-13 88736]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-23 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-23 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-23 298264]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\WHITNE~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\WHITNE~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2007-12-26 44928]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ebay.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 13:32:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-15 13:34:30
ComboFix-quarantined-files.txt 2009-03-15 20:34:12
ComboFix2.txt 2009-03-15 21:34:26

Pre-Run: 166,639,144,960 bytes free
Post-Run: 166,628,360,192 bytes free

148 --- E O F --- 2009-03-11 10:00:43

#10 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 16 March 2009 - 01:41 AM

Hi,

Can you also perform this step please?

Then, please visit this site:
http://www.bleepingcomputer.com/submit-malware.php?channel=8
Where it says: "Browse to the file you want to submit", use the Browse button to navigate to the following file: C:\Qoobox\Quarantine\[8]-Submit_date_time.zip (date_time will be replaced with the date and time when this file was created)
Then click the "Send File" button below in order to upload it.

Thanks. :thumbup2:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 16 March 2009 - 06:22 PM

I tried that step but there are no files located in that directory with a name like those. All I see is

C:\Qoobox\Quarantine\catchme.txt

there is also

C:\Qoobox\SanpShot@2009-03-15_14.33.30.45

and

C:\Qoobox\SanpShot@2009-03-15_14.33.30.45B


Should I submit one of those.. Its not in the same directory that you mentioned. Thanks

#12 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 17 March 2009 - 01:35 AM

Hi,

Can you look if the following file is present?

C:\Qoobox\quarantine\C\Windows\system32\drivers\trekqhaa.dat.vir

If so, submit that file.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 17 March 2009 - 08:23 PM

I sent the file .. thanks

#14 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:04:23 PM

Posted 17 March 2009 - 08:24 PM

Hi,

The file appears to be 0 bytes....
Anyway, no problem..

* Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 JamesD7004

JamesD7004
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:23 AM

Posted 17 March 2009 - 09:27 PM

It appears better..

Before when IExplore.exe ran in the task manager it would just eat up the resources and continue to use more of the memory usage.

Thanks again everything seems better.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users