Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspected Hijacker virus


  • This topic is locked This topic is locked
12 replies to this topic

#1 chadmc74

chadmc74

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 03 July 2009 - 07:14 PM

Im new to this forum thing so I hope someone out there can help with my hijacker problem. I was directed to this site by Hijackthis. My symptoms are beeping on startup, backspace disabled, auto erasing text, homepage disappears, and possibly others I havent discovered yet. Ive tried Advanced System Care, AVast, Windows live one care, and Spybot but found nothing. Here are the logs from DDS:

DDS (Ver_09-06-26.01) - NTFSx86
Run by User at 19:56:04.04 on Fri 07/03/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.643 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090703-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\DOCUME~1\User\LOCALS~1\Temp\clclean.0001
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\User\Application Data\U3\0000060501098311\LaunchPad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://patriots.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [CTSysVol] c:\program files\creative\sbaudigy\surround mixer\CTSysVol.exe /r
mRun: [MBMon] Rundll32 CTMBHA.DLL,MBMon
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: battle.net\us
Trusted Zone: live.com\login
Trusted Zone: live.com\mail
Trusted Zone: microsoft.com\windowsupdate
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232216022707
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
Notify: AtiExtEvent - Ati2evxx.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-17 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-17 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-17 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-17 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-17 352920]

=============== Created Last 30 ================

2009-07-03 18:53 <DIR> --d----- c:\windows\pss
2009-07-03 18:48 <DIR> --d----- c:\program files\Trend Micro
2009-07-03 10:02 <DIR> --dsh--- c:\documents and settings\user\PrivacIE
2009-07-03 10:00 <DIR> --dsh--- c:\documents and settings\user\IETldCache
2009-07-03 09:59 102,912 -------- c:\windows\system32\dllcache\iecompat.dll
2009-07-03 09:55 <DIR> -cd-h--- c:\windows\ie8
2009-06-29 18:38 43,689 a------- c:\windows\system32\dllcache\otceth5.sys
2009-06-29 18:37 60,480 a------- c:\windows\system32\dllcache\neo20xx.dll
2009-06-29 18:36 5,504 a------- c:\windows\system32\dllcache\mstee.sys
2009-06-29 18:35 320,384 a------- c:\windows\system32\dllcache\mgaum.sys
2009-06-29 18:34 15,744 a------- c:\windows\system32\dllcache\lit220p.sys
2009-06-29 18:33 45,632 a------- c:\windows\system32\dllcache\ip5515.sys
2009-06-29 18:32 9,216 a------- c:\windows\system32\dllcache\ibmsgnet.dll
2009-06-29 18:31 324,608 a------- c:\windows\system32\dllcache\hpojwia.dll
2009-06-29 18:30 454,912 a------- c:\windows\system32\dllcache\fxusbase.sys
2009-06-29 18:29 347,550 a------- c:\windows\system32\dllcache\es56tpi.sys
2009-06-29 18:28 20,992 a------- c:\windows\system32\dllcache\dshowext.ax
2009-06-29 18:27 110,592 a------- c:\windows\system32\dllcache\dc260usd.dll
2009-06-29 18:26 27,164 a------- c:\windows\system32\dllcache\ce3n5.sys
2009-06-29 18:25 49,920 a------- c:\windows\system32\dllcache\atirtcap.sys
2009-06-29 18:24 66,048 a------- c:\windows\system32\dllcache\s3legacy.dll
2009-06-29 15:12 <DIR> --d----- c:\program files\MSECache
2009-06-24 19:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\3DVIA
2009-06-24 19:50 3,727,720 a------- c:\windows\system32\d3dx9_35.dll
2009-06-24 19:50 <DIR> --d----- c:\program files\Virtools
2009-06-13 14:13 <DIR> --d----- c:\docume~1\user\applic~1\IObit
2009-06-13 14:13 <DIR> --d----- c:\program files\IObit
2009-06-13 13:46 <DIR> --d----- c:\windows\system32\wbem\Repository
2009-06-06 13:07 <DIR> --d----- c:\docume~1\user\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

==================== Find3M ====================

2009-05-23 15:19 3,766 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-05-13 01:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-13 01:15 5,936,128 -------- c:\windows\system32\dllcache\mshtml.dll
2009-05-13 01:15 915,456 -------- c:\windows\system32\dllcache\wininet.dll
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-07 11:32 345,600 a------- c:\windows\system32\dllcache\localspl.dll
2009-05-05 16:19 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-30 17:22 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-04-30 17:22 1,985,024 -------- c:\windows\system32\dllcache\iertutil.dll
2009-04-30 17:22 11,064,832 -------- c:\windows\system32\dllcache\ieframe.dll
2009-04-30 17:22 1,207,808 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-30 17:22 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-04-30 17:22 385,536 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-04-30 17:22 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-04-30 07:21 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-04-29 00:55 133,120 a------- c:\windows\system32\dllcache\extmgr.dll
2009-04-28 05:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-17 08:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-15 10:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll

============= FINISH: 19:56:40.70 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/17/2009 8:58:32 AM
System Uptime: 7/3/2009 5:52:57 PM (2 hours ago)

Motherboard: Dell Inc. | | 0XD720
Processor: Genuine Intel® CPU T1350 @ 1.86GHz | Microprocessor | 1862/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 39 GiB total, 2.696 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 0.58 GiB free.
E: is CDROM ()
F: is CDROM (CDFS)
G: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP96: 4/21/2009 11:52:45 PM - System Checkpoint
RP97: 4/23/2009 12:44:25 AM - System Checkpoint
RP98: 4/24/2009 3:20:25 AM - System Checkpoint
RP99: 4/25/2009 4:44:27 AM - System Checkpoint
RP100: 4/26/2009 6:03:41 AM - System Checkpoint
RP101: 4/27/2009 8:04:47 AM - System Checkpoint
RP102: 4/28/2009 10:03:40 AM - System Checkpoint
RP103: 4/29/2009 12:03:39 PM - System Checkpoint
RP104: 4/30/2009 12:04:40 PM - System Checkpoint
RP105: 5/1/2009 2:47:59 PM - System Checkpoint
RP106: 5/3/2009 1:59:07 AM - System Checkpoint
RP107: 5/4/2009 3:04:24 AM - System Checkpoint
RP108: 5/5/2009 4:03:41 AM - System Checkpoint
RP109: 5/6/2009 6:03:42 AM - System Checkpoint
RP110: 5/7/2009 8:03:40 AM - System Checkpoint
RP111: 5/8/2009 11:01:10 AM - System Checkpoint
RP112: 5/9/2009 1:30:11 PM - System Checkpoint
RP113: 5/10/2009 3:14:03 PM - System Checkpoint
RP114: 5/11/2009 6:57:02 PM - System Checkpoint
RP115: 5/12/2009 6:57:54 PM - System Checkpoint
RP116: 5/13/2009 3:00:17 AM - Software Distribution Service 3.0
RP117: 5/14/2009 3:04:08 AM - System Checkpoint
RP118: 5/15/2009 4:03:41 AM - System Checkpoint
RP119: 5/16/2009 6:03:41 AM - System Checkpoint
RP120: 5/17/2009 7:32:37 AM - System Checkpoint
RP121: 5/18/2009 7:53:51 AM - System Checkpoint
RP122: 5/19/2009 6:52:45 PM - System Checkpoint
RP123: 5/20/2009 8:04:44 PM - System Checkpoint
RP124: 5/21/2009 11:38:52 PM - System Checkpoint
RP125: 5/23/2009 3:21:49 AM - System Checkpoint
RP126: 5/23/2009 3:21:00 PM - Removed Corel Photo Album 6
RP127: 5/24/2009 4:59:37 PM - System Checkpoint
RP128: 5/25/2009 8:28:33 PM - System Checkpoint
RP129: 5/26/2009 11:25:03 PM - System Checkpoint
RP130: 5/28/2009 3:28:11 AM - System Checkpoint
RP131: 5/29/2009 4:03:43 AM - System Checkpoint
RP132: 5/30/2009 4:52:07 AM - System Checkpoint
RP133: 5/31/2009 5:33:19 AM - System Checkpoint
RP134: 6/1/2009 6:55:02 AM - System Checkpoint
RP135: 6/1/2009 5:35:53 PM - Installed DirectX
RP136: 6/2/2009 6:35:57 PM - System Checkpoint
RP137: 6/3/2009 7:45:13 PM - System Checkpoint
RP138: 6/4/2009 8:16:33 PM - System Checkpoint
RP139: 6/6/2009 1:11:55 AM - System Checkpoint
RP140: 6/7/2009 3:04:35 AM - System Checkpoint
RP141: 6/8/2009 4:03:43 AM - System Checkpoint
RP142: 6/9/2009 5:12:56 AM - System Checkpoint
RP143: 6/10/2009 3:00:20 AM - Software Distribution Service 3.0
RP144: 6/11/2009 3:54:59 AM - System Checkpoint
RP145: 6/12/2009 4:03:42 AM - System Checkpoint
RP146: 6/13/2009 6:03:40 AM - System Checkpoint
RP147: 6/13/2009 1:44:47 PM - Restore Operation
RP148: 6/13/2009 2:22:35 PM - Software Distribution Service 3.0
RP149: 6/14/2009 11:12:16 PM - System Checkpoint
RP150: 6/15/2009 11:58:25 PM - System Checkpoint
RP151: 6/17/2009 12:31:47 AM - System Checkpoint
RP152: 6/18/2009 12:53:33 AM - System Checkpoint
RP153: 6/19/2009 7:25:17 AM - System Checkpoint
RP154: 6/20/2009 11:10:05 AM - System Checkpoint
RP155: 6/21/2009 3:54:37 PM - System Checkpoint
RP156: 6/22/2009 4:02:38 PM - System Checkpoint
RP157: 6/23/2009 5:15:23 PM - System Checkpoint
RP158: 6/24/2009 7:50:41 PM - Installed 3DVIA player 5.0
RP159: 6/25/2009 9:00:44 PM - System Checkpoint
RP160: 6/28/2009 2:44:38 AM - System Checkpoint
RP161: 6/29/2009 3:13:03 PM - Installed Compatibility Pack for the 2007 Office system
RP162: 6/30/2009 4:19:19 PM - System Checkpoint
RP163: 7/1/2009 4:31:23 PM - System Checkpoint
RP164: 7/2/2009 6:24:40 PM - System Checkpoint
RP165: 7/3/2009 9:51:29 AM - Software Distribution Service 3.0

==== Installed Programs ======================

3DVIA player 5.0
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe Shockwave Player 11.5
Advanced SystemCare 3
AOLIcon
ATI Catalyst Control Center
ATI Display Driver
avast! Antivirus
Broadcom Management Programs
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Creative MediaSource
Dell Digital Jukebox Driver
Dell Media Experience
Dell Support 3.1
Dell System Restore
Dell Wireless WLAN Card
Digital Content Portal
Digital Line Detect
ELIcon
Free Realms Installer
Games, Music, & Photos Launcher
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 11
Learn2 Player (Uninstall Only)
LimeWire 5.1.2
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Modem Helper
MSXML 4.0 SP2 (KB954430)
PowerDVD 5.7
QuickSet
QuickTime
RealPlayer Basic
Search Assist
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sound Blaster ADVANCED MB Drivers
Sound Blaster Audigy ADVANCED MB
Sound Blaster Audigy ADVANCED MB Product Registration
Spybot - Search & Destroy
Stuart Little - His Adventures in Wordland
Synaptics Pointing Device Driver
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
URL Assistant
Ventrilo Client
Viewpoint Media Player
WebCyberCoach 3.2 Dell
WebFldrs XP
WIDCOMM Bluetooth Software
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
World of Warcraft
Zoo Tycoon: Complete Collection

==== Event Viewer Messages From Past Week ========

6/30/2009 8:05:23 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
6/29/2009 6:40:00 PM, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is User.
6/29/2009 6:24:28 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started.

==== End Of File ===========================
:thumbup2:

Attached Files



BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 04 July 2009 - 08:48 AM

Hello chadmc74,

Posted Image

Please download Malwarebytes' Anti-Malware from one of these places:
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/mbam/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 chadmc74

chadmc74
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 04 July 2009 - 10:50 AM

Hi Teacup,
I did as you said and it found no malicious ware. I also ran a full scan to be sure, still found nothing. Here are the logs from the quick scan, full scan and the latest Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:09 AM, on 7/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\DOCUME~1\User\LOCALS~1\Temp\clclean.0001
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\User\Application Data\U3\0000060501098311\LaunchPad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://patriots.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://mail.live.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1232216022707
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...r_installer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9123 bytes

Malwarebytes' Anti-Malware 1.38
Database version: 2372
Windows 5.1.2600 Service Pack 3

7/4/2009 10:52:10 AM
mbam-log-2009-07-04 (10-52-10).txt

Scan type: Quick Scan
Objects scanned: 92833
Time elapsed: 6 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Malwarebytes' Anti-Malware 1.38
Database version: 2372
Windows 5.1.2600 Service Pack 3

7/4/2009 11:41:02 AM
mbam-log-2009-07-04 (11-41-02).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 147074
Time elapsed: 35 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I really hope there is something in here that you or someone else can find wrong. Thank you.
Chadmc74

Attached Files



#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 04 July 2009 - 10:58 AM

Hello,

I'm starting to think this isn't malware related.....what makes you think that it is please? :thumbup2:

Please download F-Secure Blacklight (fsbl.exe) and save to your C:\ drive.
  • Open a command window by going to Start > Run and typing: cmd
  • Copy/paste or type the following in the command window: C:\fsbl.exe /expert
  • Hit "Enter" to start the program and then close the cmd box.
  • Accept the user agreement and click "Next".
  • Click "Scan".
  • After the scan is complete, click "Next", then "Exit".
  • BlackLight will create a log in C:\ drive named "fsbl-xxxxxxx.log" (the xxxxxxx will be the date and time of the scan).
  • The log will have a list of all items found. Do not choose to rename any yet!
    I want to see the log first because legitimate items can also be present...like "wbemtest.exe" and "tcptest.exe.
  • Exit Blacklight and post the contents of the log in your next reply.
Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 chadmc74

chadmc74
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 04 July 2009 - 12:02 PM

I suspected malware because of the weird things that were happening. Could it be hardware related? Or even other software related? Any more info you could provide would be very helpful. Here is the Blacklight Log you requested.

07/04/09 12:51:35 [Info]: BlackLight Engine 2.2.1092 initialized
07/04/09 12:51:35 [Info]: OS: 5.1 build 2600 (Service Pack 3)
07/04/09 12:51:35 [Note]: 7019 4
07/04/09 12:51:35 [Note]: 7005 0
07/04/09 12:51:40 [Note]: 7006 0
07/04/09 12:51:40 [Note]: 7011 1856
07/04/09 12:51:40 [Note]: 7035 0
07/04/09 12:51:40 [Note]: 7026 0
07/04/09 12:51:40 [Note]: 7026 0
07/04/09 12:51:43 [Note]: FSRAW library version 1.7.1024
07/04/09 12:54:56 [Note]: 2000 1012
07/04/09 12:54:56 [Note]: 2000 1012
07/04/09 12:55:24 [Note]: 7007 0

Attached Files



#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 04 July 2009 - 12:53 PM

Hello,

It could be a clash of programs/services.....Let's run one more really strong scan with this tool. If it doesn't find anything, then with the other things we've done I'd be willing to bet it isn't malware related.

I need for you to go offline completely and disable ALL your protective programs after you download ComboFix, but before you run it. Sometimes those programs interfere with it, and we don't want that! :thumbup2:

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#7 chadmc74

chadmc74
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 04 July 2009 - 01:49 PM

Here the log from Combofix. Hope there is something here you find wrong.

ComboFix 09-07-04.01 - User 07/04/2009 14:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.420 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090704-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\User\LOCALS~1\Temp\clclean.0001.dir.0000\~df394b.tmp
c:\documents and settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\avast! Antivirus.lnk
c:\documents and settings\User\Local Settings\Temp\clclean.0001.dir.0000\~df394b.tmp

.
((((((((((((((((((((((((( Files Created from 2009-06-04 to 2009-07-04 )))))))))))))))))))))))))))))))
.

2009-07-04 14:44 . 2009-07-04 14:44 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2009-07-04 14:44 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-04 14:44 . 2009-07-04 14:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-04 14:44 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-04 14:44 . 2009-07-04 14:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-03 22:48 . 2009-07-03 22:48 -------- d-----w- c:\program files\Trend Micro
2009-07-03 14:02 . 2009-07-03 14:02 -------- d-sh--w- c:\documents and settings\User\PrivacIE
2009-07-03 14:01 . 2009-07-03 14:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-07-03 14:00 . 2009-07-03 14:00 -------- d-sh--w- c:\documents and settings\User\IETldCache
2009-07-03 13:59 . 2009-06-02 10:12 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-07-03 13:58 . 2009-07-03 13:59 -------- d-----w- c:\windows\ie8updates
2009-07-03 13:58 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-07-03 13:58 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 13:55 . 2009-07-03 13:58 -------- dc-h--w- c:\windows\ie8
2009-06-29 22:38 . 2001-08-17 16:12 43689 ----a-w- c:\windows\system32\dllcache\otceth5.sys
2009-06-29 22:37 . 2001-08-18 02:36 60480 ----a-w- c:\windows\system32\dllcache\neo20xx.dll
2009-06-29 22:36 . 2008-04-13 17:39 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2009-06-29 22:36 . 2008-04-13 17:46 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2009-06-29 22:36 . 2001-08-17 17:48 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2009-06-29 22:36 . 2001-08-17 18:00 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2009-06-29 22:36 . 2008-04-13 17:54 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2009-06-29 22:36 . 2004-08-04 10:00 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2009-06-29 22:36 . 2001-08-17 18:02 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2009-06-29 22:36 . 2001-08-17 17:48 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2009-06-29 22:36 . 2008-04-13 17:46 51200 ----a-w- c:\windows\system32\dllcache\msdv.sys
2009-06-29 22:36 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\dllcache\mpe.sys
2009-06-29 22:36 . 2001-08-17 17:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2009-06-29 22:36 . 2001-08-17 17:52 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys
2009-06-29 22:36 . 2004-08-04 10:00 34304 ----a-w- c:\windows\system32\dllcache\migisol.exe
2009-06-29 22:34 . 2001-08-17 17:51 15744 ----a-w- c:\windows\system32\dllcache\lit220p.sys
2009-06-29 22:33 . 2001-08-17 16:12 45632 ----a-w- c:\windows\system32\dllcache\ip5515.sys
2009-06-29 22:32 . 2001-08-18 02:34 9216 ----a-w- c:\windows\system32\dllcache\ibmsgnet.dll
2009-06-29 22:31 . 2001-08-18 02:36 324608 ----a-w- c:\windows\system32\dllcache\hpojwia.dll
2009-06-29 22:30 . 2001-08-17 16:15 454912 ----a-w- c:\windows\system32\dllcache\fxusbase.sys
2009-06-29 22:29 . 2001-08-17 17:28 347550 ----a-w- c:\windows\system32\dllcache\es56tpi.sys
2009-06-29 22:28 . 2001-08-17 16:20 334208 ----a-w- c:\windows\system32\dllcache\ds1wdm.sys
2009-06-29 22:27 . 2001-08-18 02:36 110592 ----a-w- c:\windows\system32\dllcache\dc260usd.dll
2009-06-29 22:26 . 2001-08-17 16:13 27164 ----a-w- c:\windows\system32\dllcache\ce3n5.sys
2009-06-29 22:25 . 2001-08-17 16:49 26880 ----a-w- c:\windows\system32\dllcache\atirtsnd.sys
2009-06-29 22:24 . 2001-08-17 18:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-06-29 19:12 . 2009-06-29 19:12 -------- d-----w- c:\program files\MSECache
2009-06-24 23:51 . 2009-06-24 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\3DVIA
2009-06-24 23:50 . 2007-07-19 22:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-06-24 23:50 . 2009-06-24 23:50 -------- d-----w- c:\program files\Virtools
2009-06-13 18:13 . 2009-06-13 18:13 -------- d-----w- c:\documents and settings\User\Application Data\IObit
2009-06-13 18:13 . 2009-06-13 18:13 -------- d-----w- c:\program files\IObit
2009-06-13 17:46 . 2009-06-13 17:46 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-06 17:08 . 2009-06-06 17:08 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-06 17:07 . 2009-06-06 17:07 -------- d-----w- c:\documents and settings\User\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-04 15:51 . 2009-01-23 19:05 -------- d-----w- c:\documents and settings\User\Application Data\U3
2009-07-03 16:43 . 2009-06-01 21:35 -------- d-----w- c:\program files\Sony Online Entertainment
2009-06-05 23:56 . 2009-01-19 23:22 -------- d-----w- c:\program files\World of Warcraft
2009-05-30 19:51 . 2009-05-05 20:21 -------- d-----w- c:\documents and settings\User\Application Data\LimeWire
2009-05-23 19:19 . 2009-01-26 22:09 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-23 19:19 . 2009-01-26 22:09 88 --sh--r- c:\windows\system32\874EBF35E9.sys
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 17:35 . 2009-05-10 17:30 -------- d-----w- c:\documents and settings\User\Application Data\Creative
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 20:19 . 2009-05-05 20:20 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-05 20:19 . 2006-08-15 19:09 -------- d-----w- c:\program files\Java
2009-05-05 20:19 . 2009-05-05 20:19 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-06-22 1384448]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-15 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-05 136600]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624]
"MBMon"="CTMBHA.DLL" - c:\windows\system32\CTMBHA.DLL [2006-03-03 1355938]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-15 24576]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"d:\\Limewire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-04 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-04-17 19:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://patriots.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: battle.net\us
Trusted Zone: live.com\login
Trusted Zone: live.com\mail
Trusted Zone: microsoft.com\windowsupdate
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-04 14:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-07-04 14:36
ComboFix-quarantined-files.txt 2009-07-04 18:36

Pre-Run: 2,877,624,320 bytes free
Post-Run: 2,951,258,112 bytes free

162 --- E O F --- 2009-07-03 13:59

Thanks for all you do. :thumbup2:

Attached Files



#8 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 04 July 2009 - 08:43 PM

Hello,

You're welcome. :thumbup2:

Did that make any difference after a reboot?

When did all this start exactly?
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#9 chadmc74

chadmc74
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 04 July 2009 - 09:38 PM

No, it didnt change at all after reboot. This started about a month ago, but its a problem Ive had in the past year. One day it just started working normally so i thought the problem was gone. Then it showed its ugly head again about a month ago. One thing that does make a difference is if I set my security to High, then it works fine (which is odd). It might be time to either format the hardrive or put the computer in the shop. If you have any more suggestions, Im all ears. Thanks for your help and efforts.

#10 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 04 July 2009 - 09:46 PM

I don't find it odd since you have both Limewire and WOW going......either or both of those could cause problems. But since you've had it a year........it could be anything at this point.

I asked about an exact date because I see a hole bunch of .sys files on the 29th of June.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#11 chadmc74

chadmc74
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:09 PM

Posted 04 July 2009 - 10:14 PM

I dont know anything about .sys files. I see what youre talking about though. Do you see anything in those .sys files that could be causing a problem?

#12 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 09 July 2009 - 07:24 AM

Hello,

Download and scan with the free trial of Sunbelt's Counterspy:
http://www.sunbelt-software.com/CounterSpy.cfm
Save the report when it's finished:
1.Once Counterspy has done scanning,the 'Scan Results' box will appear.
2.Click on 'View Results'.
3.Under (Recommended Action),using the drop down menu arrows at the side of each entry found,set them ALL to 'Remove'.
4.Then click on 'Take Action'.
5.Once everything has been removed,click on 'View Details'.
6.Copy and Paste those details into a Word/Text document,then save it to your desktop.

This is a pretty long scan, and the report will be long as well, so please be patient. :thumbup2:

Regards,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#13 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:05:09 PM

Posted 14 July 2009 - 11:51 AM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users