Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System Integrity Scan Wizard Pop Up


  • This topic is locked This topic is locked
7 replies to this topic

#1 A1noah

A1noah

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:01 AM

Posted 28 November 2006 - 02:29 PM

Hello,
I have a persistent pop-up of System Integrity Scan Wizard. I also had ultimate cleaner pop up but I think I got rid of it. I believe they are connected. I have run multiple spyware removal programs and trend virus scan with no help. Any help you can provide would be much appreciated.


Here is the logfile. Thanks-


Logfile of HijackThis v1.99.1
Scan saved at 8:05:57 AM, on 11/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\mjcjh.BHC-NA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pharmatoday.us.bayer.cnb/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://business.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pharmanet.is.wh.bayer.com/config.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http-proxy:8080
R3 - URLSearchHook: (no name) - {B7128EB4-410E-4CAF-2215-1F7495A5799D} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B7128EB4-410E-4CAF-2215-1F7495A5799D} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell QuickSet] "C:\Program Files\Dell\QuickSet\quickset.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelAPMClient] "C:\LDClient\amclient.exe" /apm /s /ro /bw=WAN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [fpavigf.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\fpavigf.dll,ansarhg
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bayer VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Task Completion.LNK = C:\LDClient\AMCLIENT.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .vrd: C:\Program Files\Internet Explorer\Plugins\npvrd001.dll
O15 - Trusted Zone: http://www.bayer.com
O15 - Trusted Zone: http://www.dell.com
O15 - Trusted Zone: *.209.68.213.109 (HKLM)
O15 - Trusted Zone: *.advate.com (HKLM)
O15 - Trusted Zone: *.alignmark.com (HKLM)
O15 - Trusted Zone: *.alka-seltzer.com (HKLM)
O15 - Trusted Zone: *.americangreetings.com (HKLM)
O15 - Trusted Zone: *.appliedbiosystems.com (HKLM)
O15 - Trusted Zone: *.aralast.com (HKLM)
O15 - Trusted Zone: *.bayer-ag.com (HKLM)
O15 - Trusted Zone: *.bayer-hemophilia-awards.com (HKLM)
O15 - Trusted Zone: *.bayer.ca (HKLM)
O15 - Trusted Zone: *.bayer.cnb (HKLM)
O15 - Trusted Zone: http://*.bayer.cnb (HKLM)
O15 - Trusted Zone: *.bayer.co.jp (HKLM)
O15 - Trusted Zone: *.Bayer.com (HKLM)
O15 - Trusted Zone: http://*.Bayer.com (HKLM)
O15 - Trusted Zone: *.bayer.de (HKLM)
O15 - Trusted Zone: *.bayeralbumin.com (HKLM)
O15 - Trusted Zone: *.bayerbbs.com (HKLM)
O15 - Trusted Zone: *.bayerbiologicals.com (HKLM)
O15 - Trusted Zone: *.bayerbiologicalusa.com (HKLM)
O15 - Trusted Zone: *.bayerbiotech.com (HKLM)
O15 - Trusted Zone: *.bayercare.com (HKLM)
O15 - Trusted Zone: *.bayercropscience (HKLM)
O15 - Trusted Zone: http://*.bayercropscience.com (HKLM)
O15 - Trusted Zone: *.bayerdiagnostika.de (HKLM)
O15 - Trusted Zone: *.bayerdirect.com (HKLM)
O15 - Trusted Zone: *.bayerfcu.org (HKLM)
O15 - Trusted Zone: *.bayerhealth.com (HKLM)
O15 - Trusted Zone: *.bayerhealthcare.com (HKLM)
O15 - Trusted Zone: http://*.bayerhealthcare.com (HKLM)
O15 - Trusted Zone: *.bayerhealthcareperspectives.com (HKLM)
O15 - Trusted Zone: *.bayerhealthvillage.at (HKLM)
O15 - Trusted Zone: *.bayernet.com (HKLM)
O15 - Trusted Zone: *.bayerpolymers.com (HKLM)
O15 - Trusted Zone: *.bayerus.com (HKLM)
O15 - Trusted Zone: *.bayerweb.com (HKLM)
O15 - Trusted Zone: http://*.bayerweb.com (HKLM)
O15 - Trusted Zone: http://*.baykomm.bayer.de (HKLM)
O15 - Trusted Zone: *.baynet.ch (HKLM)
O15 - Trusted Zone: *.bioinformaticsonline.org (HKLM)
O15 - Trusted Zone: *.biological.com (HKLM)
O15 - Trusted Zone: *.boldfish.com (HKLM)
O15 - Trusted Zone: *.bprow.com (HKLM)
O15 - Trusted Zone: *.cateringworks.com (HKLM)
O15 - Trusted Zone: *.claritynet.com (HKLM)
O15 - Trusted Zone: *.compliancewire.com (HKLM)
O15 - Trusted Zone: *.dell.com (HKLM)
O15 - Trusted Zone: *.digene.com (HKLM)
O15 - Trusted Zone: *.disneymeetings.com (HKLM)
O15 - Trusted Zone: *.dmreztrak.com (HKLM)
O15 - Trusted Zone: *.dropcode.com (HKLM)
O15 - Trusted Zone: *.e-healthcaresolutions.com (HKLM)
O15 - Trusted Zone: http://*.e-healthcaresolutions.com (HKLM)
O15 - Trusted Zone: *.eduneering.com (HKLM)
O15 - Trusted Zone: *.elementk.com (HKLM)
O15 - Trusted Zone: http://*.emmofilia.it (HKLM)
O15 - Trusted Zone: *.emofilia.com (HKLM)
O15 - Trusted Zone: *.emofilia.it (HKLM)
O15 - Trusted Zone: *.Eudra.org (HKLM)
O15 - Trusted Zone: *.eurorscglife.ca (HKLM)
O15 - Trusted Zone: *.eurorscglife.com (HKLM)
O15 - Trusted Zone: http://*.eurorscglife.com (HKLM)
O15 - Trusted Zone: *.eway.com (HKLM)
O15 - Trusted Zone: http://*.eway.com (HKLM)
O15 - Trusted Zone: http://*.fedex.com (HKLM)
O15 - Trusted Zone: *.fourseasons.com (HKLM)
O15 - Trusted Zone: http://*.fourseasons.com (HKLM)
O15 - Trusted Zone: *.gamunex.com (HKLM)
O15 - Trusted Zone: *.getronics.com (HKLM)
O15 - Trusted Zone: *.gloverprinting.com (HKLM)
O15 - Trusted Zone: http://*.gtc-bio.com (HKLM)
O15 - Trusted Zone: *.healthvillage.org (HKLM)
O15 - Trusted Zone: *.heartbeatdigital.com (HKLM)
O15 - Trusted Zone: http://*.heartbeatdigital.com (HKLM)
O15 - Trusted Zone: *.hemophiliabayer.com (HKLM)
O15 - Trusted Zone: *.hemophiliagalaxy.com (HKLM)
O15 - Trusted Zone: http://*.hemophiliagalaxy.com (HKLM)
O15 - Trusted Zone: *.ifpma.org (HKLM)
O15 - Trusted Zone: http://*.ifpma.org (HKLM)
O15 - Trusted Zone: *.igivnext.com (HKLM)
O15 - Trusted Zone: http://*.igivnext.com (HKLM)
O15 - Trusted Zone: *.imageassociates.com (HKLM)
O15 - Trusted Zone: http://*.imageassociates.com (HKLM)
O15 - Trusted Zone: *.immune-globulin.com (HKLM)
O15 - Trusted Zone: *.intelliscope.com (HKLM)
O15 - Trusted Zone: http://*.intelliscope.com (HKLM)
O15 - Trusted Zone: *.kogeanatefsusa.com (HKLM)
O15 - Trusted Zone: *.kprny.com (HKLM)
O15 - Trusted Zone: http://*.kprny.com (HKLM)
O15 - Trusted Zone: *.macromedia.com (HKLM)
O15 - Trusted Zone: *.medsite.com (HKLM)
O15 - Trusted Zone: *.micvpt (HKLM)
O15 - Trusted Zone: *.micvpw (HKLM)
O15 - Trusted Zone: *.micvsw (HKLM)
O15 - Trusted Zone: http://*.miw0c5 (HKLM)
O15 - Trusted Zone: *.moxayi (HKLM)
O15 - Trusted Zone: http://*.mscdirect.com (HKLM)
O15 - Trusted Zone: *.mshow.com (HKLM)
O15 - Trusted Zone: *.mwzander.com (HKLM)
O15 - Trusted Zone: *.mymeetings.com (HKLM)
O15 - Trusted Zone: *.ncem.org (HKLM)
O15 - Trusted Zone: *.newmangasket.com (HKLM)
O15 - Trusted Zone: *.novonordisk.com (HKLM)
O15 - Trusted Zone: http://*.novonordisk.com (HKLM)
O15 - Trusted Zone: *.one-a-day.com (HKLM)
O15 - Trusted Zone: *.paliocommunications.com (HKLM)
O15 - Trusted Zone: *.pomeroy.com (HKLM)
O15 - Trusted Zone: *.pptaglobal.org (HKLM)
O15 - Trusted Zone: http://*.pptaglobal.org (HKLM)
O15 - Trusted Zone: *.prolastin.com (HKLM)
O15 - Trusted Zone: *.propoint.com (HKLM)
O15 - Trusted Zone: *.repsstudio.com (HKLM)
O15 - Trusted Zone: *.resassist.com (HKLM)
O15 - Trusted Zone: *.roche.com (HKLM)
O15 - Trusted Zone: http://*.shockwave.com (HKLM)
O15 - Trusted Zone: http://*.showtimeinc.com (HKLM)
O15 - Trusted Zone: http://*.sigmaaldrich.com (HKLM)
O15 - Trusted Zone: http://*.skillport.com (HKLM)
O15 - Trusted Zone: http://*.skillsoft.com (HKLM)
O15 - Trusted Zone: http://*.skire.com (HKLM)
O15 - Trusted Zone: *.smartforce.com (HKLM)
O15 - Trusted Zone: http://*.smartforce.com (HKLM)
O15 - Trusted Zone: *.stratagene.com (HKLM)
O15 - Trusted Zone: *.techtarget.com (HKLM)
O15 - Trusted Zone: *.thejlcompany.com (HKLM)
O15 - Trusted Zone: *.theljcompany.com (HKLM)
O15 - Trusted Zone: *.thromb-x.com (HKLM)
O15 - Trusted Zone: http://*.thromb-x.com (HKLM)
O15 - Trusted Zone: *.thrombogenics.com (HKLM)
O15 - Trusted Zone: http://*.thrombogenics.com (HKLM)
O15 - Trusted Zone: *.umuc.edu (HKLM)
O15 - Trusted Zone: http://*.umuc.edu (HKLM)
O15 - Trusted Zone: *.verizonwireless.com (HKLM)
O15 - Trusted Zone: *.webex.com (HKLM)
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://apps.pitts.bayer.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1162237429267
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\Software\..\Telephony: DomainName = na.healthcare.cnb
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.1 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: LANDesk® Management Agent (CBA8) - LANDesk® Development, Ltd - C:\Program Files\LANDesk\Shared Files\residentagent.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Disk Defragmenter - Unknown owner - c:\windows\system32\srvany.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel Local Scheduler Service - LANDesk Software Ltd. - C:\LDClient\LOCALSCH.EXE
O23 - Service: Intel PDS - Intel« Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Intel QIP Client Service - LANDesk Software Ltd. - C:\LDClient\QIPCLNT.EXE
O23 - Service: Intel Targeted Multicast - LANDesk Software Ltd. - C:\LDClient\tmcsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: OracleOUIHomeClientCache - Unknown owner - C:\OraNT\BIN\ONRSD.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: Intel Remote Control Service (Wuser32) - LANDesk Software Ltd. - C:\LDClient\wuser32.exe

BC AdBot (Login to Remove)

 


m

#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:02:01 PM

Posted 28 November 2006 - 05:56 PM

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. :thumbsup:

Please download ComboFix and save it to your desktop.
Double click combofix.exe and follow the prompts.
When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 A1noah

A1noah
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:01 AM

Posted 28 November 2006 - 06:57 PM

mjcjh - 06-11-28 15:51:05.75 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\mjcjh.BHC-NA\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Safety Bar
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{143F5450-031E-1033-0811-050504040001}
C:\Program Files\Common Files\{343F5450-031E-1033-0811-050504040001}

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\WINDOWS\SCURIT~1


((((((((((((((((((((((((((((((( Files Created from 2006-10-28 to 2006-11-28 ))))))))))))))))))))))))))))))))))


2006-11-28 08:10 <DIR> dr-h----- C:\Documents and Settings\mjcjh.BHC-NA\Recent
2006-11-19 13:16 <DIR> d-------- C:\THREE_BURIALS_MELQUIADES_ESTRA
2006-11-16 11:36 <DIR> d-------- C:\Program Files\CCleaner
2006-11-07 10:50 <DIR> d-------- C:\WINDOWS\Prefetch
2006-11-06 15:02 <DIR> d-------- C:\Program Files\clj2550pcl6
2006-11-06 14:41 23,808 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Dot4usb.sys
2006-11-06 14:41 207,360 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Dot4.sys
2006-11-06 14:41 12,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Dot4Prt.sys
2006-11-05 09:36 <DIR> d-------- C:\INDIANAJONES_TOD_169
2006-11-03 18:34 684,032 --a------ C:\WINDOWS\SYSTEM32\libeay32.dll
2006-11-03 18:34 20,544 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SSFS0509.sys
2006-11-03 18:34 155,648 --a------ C:\WINDOWS\SYSTEM32\ssleay32.dll
2006-11-02 15:42 <DIR> d-------- C:\WINDOWS\WBEM
2006-11-02 15:42 <DIR> d-------- C:\WINDOWS\SYSTEM32\en-US
2006-11-02 15:35 121,856 --------- C:\WINDOWS\SYSTEM32\xmllite.dll
2006-11-02 14:52 20,480 --a------ C:\WINDOWS\Paluninsr.dll
2006-10-30 12:35 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2006-10-28 12:10 21,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sshrmd.sys
2006-10-28 12:10 21,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys
2006-10-28 12:10 128,064 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ssidrv.sys
2006-10-28 12:10 <DIR> d-------- C:\Program Files\Webroot
2006-10-28 12:10 <DIR> d-------- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\Webroot
2006-10-28 12:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-28 15:51 -------- d-------- C:\Program Files\Common Files
2006-11-24 18:02 -------- d-------- C:\Program Files\Picasa2
2006-11-03 18:19 -------- d-------- C:\Program Files\Internet Explorer
2006-11-03 18:08 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-30 12:09 -------- d-------- C:\Program Files\Outlook Express
2006-10-30 12:09 -------- d-------- C:\Program Files\Common Files\System
2006-10-23 09:54 -------- d-------- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\Mozilla
2006-10-21 14:33 -------- d-------- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\Ódobe
2006-10-21 09:06 -------- d-------- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\WinPatrol
2006-10-21 09:05 -------- d-------- C:\Program Files\BillP Studios
2006-10-20 16:11 94208 --a------ C:\WINDOWS\SYSTEM32\fpavigf.dll
2006-10-20 16:11 72192 --a------ C:\WINDOWS\SYSTEM32\qpfjfkc.dll
2006-10-20 16:11 2 --a------ C:\WINDOWS\SYSTEM32\wnscpsv.exe
2006-10-20 16:11 -------- d---s---- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\Microsoft
2006-10-17 13:01 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-10-02 14:18 -------- d-------- C:\Program Files\Lavasoft
2006-10-02 14:18 -------- d-------- C:\Documents and Settings\mjcjh.BHC-NA\Application Data\Lavasoft
2006-09-12 21:01 1084416 --a------ C:\WINDOWS\SYSTEM32\msxml3.dll
2006-09-06 17:43 22752 --a------ C:\WINDOWS\SYSTEM32\spupdsvc.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"Apoint"="\"C:\\Program Files\\Apoint\\Apoint.exe\""
"bascstray"="BascsTray.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"Dell QuickSet"="\"C:\\Program Files\\Dell\\QuickSet\\quickset.exe\""
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"Dell Wireless Manager UI"="C:\\WINDOWS\\System32\\WLTRAY"
"OfficeScanNT Monitor"="\"C:\\OfficeScan NT\\Pccntmon.exe\" -HideWindow"
"IntelAPMClient"="\"C:\\LDClient\\amclient.exe\" /apm /s /ro /bw=WAN"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"fpavigf.dll"="\"C:\\WINDOWS\\system32\\rundll32.exe\" C:\\WINDOWS\\system32\\fpavigf.dll,ansarhg"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,2c,01,00,00,00,00,00,00,d4,03,00,00,e4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,e1,00,00,00,00,00,00,00,1f,04,00,00,e4,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,e1,00,00,00,00,00,00,00,1f,04,00,00,e4,03,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000001
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"RunLogonScriptSync"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.LNK]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.LNK"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.LNKCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sgtray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1139844412.job

Completion time: 06-11-28 15:52:14.60
C:\ComboFix.txt ... 06-11-28 15:52

#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:02:01 PM

Posted 28 November 2006 - 10:26 PM

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):



    C:\WINDOWS\SYSTEM32\fpavigf.dll
    C:\WINDOWS\SYSTEM32\qpfjfkc.dll



  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

    If your computer does not restart automatically, please restart it manually.

  • After rebooting, open up Killbox again. Click File -> Logs -> Actions History Log
  • Post this log in your next reply.
===============



Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report along with a new hijackthis log.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 A1noah

A1noah
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:01 AM

Posted 29 November 2006 - 10:18 AM

Thank you so much for your help.
Here is the kill box log. I will post the activescan report and a new hijackthis log soon.

Pocket Killbox version 2.0.0.648
Running on Windows XP as mjcjh(Administrator)
was started @ Wednesday, November 29, 2006, 6:44 AM

# 1 [Delete on Reboot]
Path = C:\WINDOWS\SYSTEM32\fpavigf.dll


# 2 [Delete on Reboot]
Path = C:\WINDOWS\SYSTEM32\qpfjfkc.dll


I Rebooted @ 6:49:57 AM
Killbox Closed(Exit) @ 6:50:28 AM
__________________________________________________

Pocket Killbox version 2.0.0.648
Running on Windows XP as mjcjh(Administrator)
was started @ Wednesday, November 29, 2006, 6:54 AM

#6 A1noah

A1noah
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:01 AM

Posted 29 November 2006 - 02:16 PM

Here is the logfile. I cant download the panda software through my work firewall I will try from home.
Im also geting an Error on startup. It states: Error loading C:\windows\system32\fpavigf.dll The specified module could not be found

Thanks for your help!

Logfile of HijackThis v1.99.1
Scan saved at 11:07:18 AM, on 11/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\LANDesk\Shared Files\residentagent.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\LDClient\LOCALSCH.EXE
C:\WINDOWS\system32\cba\pds.exe
C:\LDClient\QIPCLNT.EXE
C:\LDClient\tmcsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\OfficeScan NT\tmlisten.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\LDClient\wuser32.exe
C:\OfficeScan NT\OfcPfwSvc.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\TEMP\AN8B10.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\WLTRAY.exe
C:\OfficeScan NT\Pccntmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\mjcjh.BHC-NA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pharmatoday.us.bayer.cnb/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://business.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pharmanet.is.wh.bayer.com/config.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http-proxy:8080
R3 - URLSearchHook: (no name) - {B7128EB4-410E-4CAF-2215-1F7495A5799D} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B7128EB4-410E-4CAF-2215-1F7495A5799D} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell QuickSet] "C:\Program Files\Dell\QuickSet\quickset.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelAPMClient] "C:\LDClient\amclient.exe" /apm /s /ro /bw=WAN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [fpavigf.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\fpavigf.dll,ansarhg
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bayer VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Task Completion.LNK = C:\LDClient\AMCLIENT.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .vrd: C:\Program Files\Internet Explorer\Plugins\npvrd001.dll
O15 - Trusted Zone: http://www.bayer.com
O15 - Trusted Zone: http://www.dell.com
O15 - Trusted Zone: *.209.68.213.109 (HKLM)
O15 - Trusted Zone: *.advate.com (HKLM)
O15 - Trusted Zone: *.alignmark.com (HKLM)
O15 - Trusted Zone: *.alka-seltzer.com (HKLM)
O15 - Trusted Zone: *.americangreetings.com (HKLM)
O15 - Trusted Zone: *.appliedbiosystems.com (HKLM)
O15 - Trusted Zone: *.aralast.com (HKLM)
O15 - Trusted Zone: *.bayer-ag.com (HKLM)
O15 - Trusted Zone: *.bayer-hemophilia-awards.com (HKLM)
O15 - Trusted Zone: *.bayer.ca (HKLM)
O15 - Trusted Zone: *.bayer.cnb (HKLM)
O15 - Trusted Zone: http://*.bayer.cnb (HKLM)
O15 - Trusted Zone: *.bayer.co.jp (HKLM)
O15 - Trusted Zone: *.Bayer.com (HKLM)
O15 - Trusted Zone: http://*.Bayer.com (HKLM)
O15 - Trusted Zone: *.bayer.de (HKLM)
O15 - Trusted Zone: *.bayeralbumin.com (HKLM)
O15 - Trusted Zone: *.bayerbbs.com (HKLM)
O15 - Trusted Zone: *.bayerbiologicals.com (HKLM)
O15 - Trusted Zone: *.bayerbiologicalusa.com (HKLM)
O15 - Trusted Zone: *.bayerbiotech.com (HKLM)
O15 - Trusted Zone: *.bayercare.com (HKLM)
O15 - Trusted Zone: *.bayercropscience (HKLM)
O15 - Trusted Zone: http://*.bayercropscience.com (HKLM)
O15 - Trusted Zone: *.bayerdiagnostika.de (HKLM)
O15 - Trusted Zone: *.bayerdirect.com (HKLM)
O15 - Trusted Zone: *.bayerfcu.org (HKLM)
O15 - Trusted Zone: *.bayerhealth.com (HKLM)
O15 - Trusted Zone: *.bayerhealthcare.com (HKLM)
O15 - Trusted Zone: http://*.bayerhealthcare.com (HKLM)
O15 - Trusted Zone: *.bayerhealthcareperspectives.com (HKLM)
O15 - Trusted Zone: *.bayerhealthvillage.at (HKLM)
O15 - Trusted Zone: *.bayernet.com (HKLM)
O15 - Trusted Zone: *.bayerpolymers.com (HKLM)
O15 - Trusted Zone: *.bayerus.com (HKLM)
O15 - Trusted Zone: *.bayerweb.com (HKLM)
O15 - Trusted Zone: http://*.bayerweb.com (HKLM)
O15 - Trusted Zone: http://*.baykomm.bayer.de (HKLM)
O15 - Trusted Zone: *.baynet.ch (HKLM)
O15 - Trusted Zone: *.bioinformaticsonline.org (HKLM)
O15 - Trusted Zone: *.biological.com (HKLM)
O15 - Trusted Zone: *.boldfish.com (HKLM)
O15 - Trusted Zone: *.bprow.com (HKLM)
O15 - Trusted Zone: *.cateringworks.com (HKLM)
O15 - Trusted Zone: *.claritynet.com (HKLM)
O15 - Trusted Zone: *.compliancewire.com (HKLM)
O15 - Trusted Zone: *.dell.com (HKLM)
O15 - Trusted Zone: *.digene.com (HKLM)
O15 - Trusted Zone: *.disneymeetings.com (HKLM)
O15 - Trusted Zone: *.dmreztrak.com (HKLM)
O15 - Trusted Zone: *.dropcode.com (HKLM)
O15 - Trusted Zone: *.e-healthcaresolutions.com (HKLM)
O15 - Trusted Zone: http://*.e-healthcaresolutions.com (HKLM)
O15 - Trusted Zone: *.eduneering.com (HKLM)
O15 - Trusted Zone: *.elementk.com (HKLM)
O15 - Trusted Zone: http://*.emmofilia.it (HKLM)
O15 - Trusted Zone: *.emofilia.com (HKLM)
O15 - Trusted Zone: *.emofilia.it (HKLM)
O15 - Trusted Zone: *.Eudra.org (HKLM)
O15 - Trusted Zone: *.eurorscglife.ca (HKLM)
O15 - Trusted Zone: *.eurorscglife.com (HKLM)
O15 - Trusted Zone: http://*.eurorscglife.com (HKLM)
O15 - Trusted Zone: *.eway.com (HKLM)
O15 - Trusted Zone: http://*.eway.com (HKLM)
O15 - Trusted Zone: http://*.fedex.com (HKLM)
O15 - Trusted Zone: *.fourseasons.com (HKLM)
O15 - Trusted Zone: http://*.fourseasons.com (HKLM)
O15 - Trusted Zone: *.gamunex.com (HKLM)
O15 - Trusted Zone: *.getronics.com (HKLM)
O15 - Trusted Zone: *.gloverprinting.com (HKLM)
O15 - Trusted Zone: http://*.gtc-bio.com (HKLM)
O15 - Trusted Zone: *.healthvillage.org (HKLM)
O15 - Trusted Zone: *.heartbeatdigital.com (HKLM)
O15 - Trusted Zone: http://*.heartbeatdigital.com (HKLM)
O15 - Trusted Zone: *.hemophiliabayer.com (HKLM)
O15 - Trusted Zone: *.hemophiliagalaxy.com (HKLM)
O15 - Trusted Zone: http://*.hemophiliagalaxy.com (HKLM)
O15 - Trusted Zone: *.ifpma.org (HKLM)
O15 - Trusted Zone: http://*.ifpma.org (HKLM)
O15 - Trusted Zone: *.igivnext.com (HKLM)
O15 - Trusted Zone: http://*.igivnext.com (HKLM)
O15 - Trusted Zone: *.imageassociates.com (HKLM)
O15 - Trusted Zone: http://*.imageassociates.com (HKLM)
O15 - Trusted Zone: *.immune-globulin.com (HKLM)
O15 - Trusted Zone: *.intelliscope.com (HKLM)
O15 - Trusted Zone: http://*.intelliscope.com (HKLM)
O15 - Trusted Zone: *.kogeanatefsusa.com (HKLM)
O15 - Trusted Zone: *.kprny.com (HKLM)
O15 - Trusted Zone: http://*.kprny.com (HKLM)
O15 - Trusted Zone: *.macromedia.com (HKLM)
O15 - Trusted Zone: *.medsite.com (HKLM)
O15 - Trusted Zone: *.micvpt (HKLM)
O15 - Trusted Zone: *.micvpw (HKLM)
O15 - Trusted Zone: *.micvsw (HKLM)
O15 - Trusted Zone: http://*.miw0c5 (HKLM)
O15 - Trusted Zone: *.moxayi (HKLM)
O15 - Trusted Zone: http://*.mscdirect.com (HKLM)
O15 - Trusted Zone: *.mshow.com (HKLM)
O15 - Trusted Zone: *.mwzander.com (HKLM)
O15 - Trusted Zone: *.mymeetings.com (HKLM)
O15 - Trusted Zone: *.ncem.org (HKLM)
O15 - Trusted Zone: *.newmangasket.com (HKLM)
O15 - Trusted Zone: *.novonordisk.com (HKLM)
O15 - Trusted Zone: http://*.novonordisk.com (HKLM)
O15 - Trusted Zone: *.one-a-day.com (HKLM)
O15 - Trusted Zone: *.paliocommunications.com (HKLM)
O15 - Trusted Zone: *.pomeroy.com (HKLM)
O15 - Trusted Zone: *.pptaglobal.org (HKLM)
O15 - Trusted Zone: http://*.pptaglobal.org (HKLM)
O15 - Trusted Zone: *.prolastin.com (HKLM)
O15 - Trusted Zone: *.propoint.com (HKLM)
O15 - Trusted Zone: *.repsstudio.com (HKLM)
O15 - Trusted Zone: *.resassist.com (HKLM)
O15 - Trusted Zone: *.roche.com (HKLM)
O15 - Trusted Zone: http://*.shockwave.com (HKLM)
O15 - Trusted Zone: http://*.showtimeinc.com (HKLM)
O15 - Trusted Zone: http://*.sigmaaldrich.com (HKLM)
O15 - Trusted Zone: http://*.skillport.com (HKLM)
O15 - Trusted Zone: http://*.skillsoft.com (HKLM)
O15 - Trusted Zone: http://*.skire.com (HKLM)
O15 - Trusted Zone: *.smartforce.com (HKLM)
O15 - Trusted Zone: http://*.smartforce.com (HKLM)
O15 - Trusted Zone: *.stratagene.com (HKLM)
O15 - Trusted Zone: *.techtarget.com (HKLM)
O15 - Trusted Zone: *.thejlcompany.com (HKLM)
O15 - Trusted Zone: *.theljcompany.com (HKLM)
O15 - Trusted Zone: *.thromb-x.com (HKLM)
O15 - Trusted Zone: http://*.thromb-x.com (HKLM)
O15 - Trusted Zone: *.thrombogenics.com (HKLM)
O15 - Trusted Zone: http://*.thrombogenics.com (HKLM)
O15 - Trusted Zone: *.umuc.edu (HKLM)
O15 - Trusted Zone: http://*.umuc.edu (HKLM)
O15 - Trusted Zone: *.verizonwireless.com (HKLM)
O15 - Trusted Zone: *.webex.com (HKLM)
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://apps.pitts.bayer.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1162237429267
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\Software\..\Telephony: DomainName = na.healthcare.cnb
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.healthcare.cnb
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = brkl.bayer.com,pitts.bayer.com,us.bayer.cnb
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.1 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: LANDesk« Management Agent (CBA8) - LANDesk« Development, Ltd - C:\Program Files\LANDesk\Shared Files\residentagent.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Disk Defragmenter - Unknown owner - c:\windows\system32\srvany.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel Local Scheduler Service - LANDesk Software Ltd. - C:\LDClient\LOCALSCH.EXE
O23 - Service: Intel PDS - Intel« Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Intel QIP Client Service - LANDesk Software Ltd. - C:\LDClient\QIPCLNT.EXE
O23 - Service: Intel Targeted Multicast - LANDesk Software Ltd. - C:\LDClient\tmcsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: OracleOUIHomeClientCache - Unknown owner - C:\OraNT\BIN\ONRSD.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: Intel Remote Control Service (Wuser32) - LANDesk Software Ltd. - C:\LDClient\wuser32.exe

Edited by A1noah, 29 November 2006 - 02:27 PM.


#7 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:02:01 PM

Posted 29 November 2006 - 08:53 PM

Run Hijackthis again, click scan, and Put a checkmark next to each of the lines listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R3 - URLSearchHook: (no name) - {B7128EB4-410E-4CAF-2215-1F7495A5799D} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [fpavigf.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\fpavigf.dll,ansarhg
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\



Reboot your computer and post a new hijackthis log.

If you can't get through to Panda let me know. We can work around it, but it would be good to get that scan in.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:02:01 PM

Posted 14 December 2006 - 08:32 PM

Unfortunately there has been no response. :thumbsup:
This thread will now be closed.

If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users