Welcome! Register for a free account (or login) > How does it work?
|
|


Oct 13 2009, 04:44 AM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:29:49, on 13/10/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\Ati2evxx.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\mom.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\csrcs.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.rd.yahoo.com/customize/ycomp/def.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101764&l=dis R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe F2 - REG:system.ini: UserInit=userinit.exe,bar311.exe O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file) O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE -- End of file - 9251 bytes |
|
|
|
![]() |
Oct 13 2009, 05:11 AM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Please download DDS from either of these links LINK 1 LINK 2 and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. NEXT ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Oct 13 2009, 08:25 AM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
hi it's me again attached is the following dds, attach, and gmer.txt
off topic my avg antivirus just detected 2 files i forgot what are they since i immediately removed them... thanks again hoping to hear from you soon
Attached File(s)
DDS.txt ( 10.07K )
Number of downloads: 20
Attach.txt ( 11.26K )
Number of downloads: 128
gmer.txt ( 18.79K )
Number of downloads: 143 |
|
|
|
Oct 13 2009, 08:30 AM
Post
#4
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Note: It is extremely important to disable AVG8 and teatimer before proceeding with combofix Download Combofix from either of the links below but rename it to Combo.exe before saving it to your desktop. Link 1 Link 2 -------------------------------------------------------------------- Double click on the renamed ComboFix.exe & follow the prompts.
NOTE: If combofix requests to install the Recovery Console - please ALLOW it to do so. |
|
|
|
Oct 13 2009, 09:02 AM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
first of all thank you for the fast response, attached is the log of the combofix
thank you hoping to hear from you soon
Attached File(s)
|
|
|
|
Oct 13 2009, 10:40 AM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
is there anything wrong in it? just now my avg detected game.exe etc
|
|
|
|
Oct 13 2009, 12:45 PM
Post
#7
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following:
Copy/paste the text inside the Codebox below into notepad: Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') CODE http://forums.whatthetech.com/can_anyone_check_my_hijackfile_t107585.html&view=findpost&p=602653#entry602653 Collect:: c:\windows\system32\lojhjog.dll Driver:: gfmwudys qhuxikbxp NetSvc:: gfmwudys qhuxikbxp Registry:: [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gfmwudys] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qhuxikbxp] Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste') Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. |
|
|
|
Oct 13 2009, 09:35 PM
Post
#8
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
good day this is the log of the latest combofix , i've already uninstalled the avg8 and teatimer... thanks
ComboFix 09-10-13.01 - dell 14/10/2009 11:20.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.894.428 [GMT 8:00] Running from: c:\documents and settings\dell\Desktop\Combo.exe.exe Command switches used :: c:\documents and settings\dell\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_GFMWUDYS -------\Legacy_QHUXIKBXP -------\Service_gfmwudys -------\Service_qhuxikbxp ((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 ))))))))))))))))))))))))))))))) . 2009-10-13 14:45 . 2009-10-13 14:59 -------- dc----w- C:\Combo.exe 2009-10-13 13:18 . 2009-10-13 13:18 -------- d--h--w- c:\windows\PIF 2009-10-13 10:29 . 2009-10-13 10:29 396288 -c--a-w- C:\HijackThis.exe 2009-10-12 04:51 . 2009-10-12 04:51 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-10-12 02:49 . 2009-10-12 02:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-10-09 08:22 . 2009-10-09 08:22 -------- d-----w- c:\windows\Sun 2009-10-06 06:06 . 2009-10-06 06:06 -------- d-----w- c:\documents and settings\dell\Application Data\Office Genuine Advantage 2009-09-27 06:48 . 2009-10-11 14:05 25 ----a-w- c:\windows\popcinfot.dat 2009-09-24 11:06 . 2009-09-24 11:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Go Go Gourmet 2009-09-24 11:06 . 2009-09-24 11:06 -------- d-----w- c:\windows\Go-Go Gourmet 2009-09-23 13:08 . 2009-09-23 13:08 -------- d-----w- c:\documents and settings\dell\Application Data\Valusoft 2009-09-23 13:08 . 2009-09-23 13:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Valusoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-14 02:49 . 2008-09-30 14:14 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-10-14 02:49 . 2008-09-30 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-10-12 14:28 . 2008-08-07 14:36 -------- d-----w- c:\documents and settings\dell\Application Data\LimeWire 2009-10-12 11:04 . 2009-09-10 14:16 -------- d-----w- c:\program files\LimeWire 2009-09-22 08:51 . 2009-05-29 03:14 -------- d-----w- c:\program files\BitTorrent 2009-09-17 11:57 . 2008-01-09 19:42 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-09-13 04:01 . 2008-10-09 14:00 -------- d-----w- c:\documents and settings\dell\Application Data\Skype 2009-09-12 17:15 . 2008-01-11 18:10 -------- d-----w- c:\documents and settings\dell\Application Data\skypePM 2009-09-10 09:01 . 2008-09-05 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-08-22 17:37 . 2009-08-22 17:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Questtracers 2009-08-18 10:27 . 2009-05-30 14:42 -------- d-----w- c:\documents and settings\dell\Application Data\PlayFirst 2009-08-18 10:27 . 2009-05-30 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst 2009-08-10 10:54 . 2008-01-06 00:31 120344 -c--a-w- c:\documents and settings\dell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-06 11:24 . 2008-01-06 00:24 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-06 11:24 . 2008-01-06 00:24 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-06 11:24 . 2008-01-06 00:24 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-06 11:24 . 2007-07-31 03:19 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-06 11:24 . 2008-01-06 00:24 53472 ------w- c:\windows\system32\wuauclt.exe 2009-08-06 11:24 . 2004-08-04 10:00 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-06 11:23 . 2008-01-06 00:24 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-06 11:23 . 2008-04-05 14:25 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-08-06 11:23 . 2008-04-05 14:25 215920 ----a-w- c:\windows\system32\muweb.dll 2009-08-06 11:23 . 2008-01-06 00:24 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-03 07:07 . 2009-08-03 07:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll 2009-08-03 07:07 . 2009-08-03 07:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll 2009-08-03 07:07 . 2009-08-03 07:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe 2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll 2009-01-29 07:06 . 2009-01-29 07:06 608 -csha-w- c:\windows\system32\winzvprt5.sys . ((((((((((((((((((((((((((((( SnapShot@2009-10-13_14.55.10 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-14 03:26 . 2009-10-14 03:26 16384 c:\windows\Temp\Perflib_Perfdata_574.dat - 2009-10-13 14:55 . 2009-10-13 14:55 53248 c:\windows\Temp\catchme.dll + 2009-10-14 03:26 . 2009-10-14 03:26 53248 c:\windows\Temp\catchme.dll - 2004-08-04 10:00 . 2009-10-13 10:29 73942 c:\windows\system32\perfc009.dat + 2004-08-04 10:00 . 2009-10-14 03:17 73942 c:\windows\system32\perfc009.dat - 2008-01-06 00:30 . 2009-10-13 10:24 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2008-01-06 00:30 . 2009-10-14 03:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - 2008-01-06 00:30 . 2009-10-13 10:24 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2008-01-06 00:30 . 2009-10-14 03:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2008-01-07 22:04 . 2009-10-14 03:26 13405 c:\windows\system32\config\systemprofile\Local Settings\Application Data\ATI\ACE\Manifest.Bin - 2008-01-07 22:04 . 2009-10-13 10:24 13405 c:\windows\system32\config\systemprofile\Local Settings\Application Data\ATI\ACE\Manifest.Bin - 2008-01-06 00:30 . 2009-10-13 10:24 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2008-01-06 00:30 . 2009-10-14 03:26 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-08-04 10:00 . 2009-10-14 03:17 447428 c:\windows\system32\perfh009.dat - 2004-08-04 10:00 . 2009-10-13 10:29 447428 c:\windows\system32\perfh009.dat - 2009-06-24 05:38 . 2009-10-13 10:24 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat + 2009-06-24 05:38 . 2009-10-14 03:26 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 c:\documents and settings\All Users\Start Menu\Programs\Startup\ Post-itr Software Notes Lite.lnk - c:\program files\3M\PSNLite\PsnLite.exe [2004-10-15 2080768] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "Lavasoft Ad-Aware Service"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\WINDOWS\\system32\\dxdiag.exe"= "c:\\WINDOWS\\system32\\dpnsvr.exe"= "d:\\C\\Phone\\Skype.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/02/2009 10:49 64160] S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?] S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?] S3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;c:\windows\system32\drivers\cmusbser.sys [27/01/2009 20:33 97408] S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?] S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 05:34 1028432] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-10-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:49] 2009-10-14 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 07:07] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.ask.com/?o=101764&l=dis uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll FF - ProfilePath - c:\documents and settings\dell\Application Data\Mozilla\Firefox\Profiles\drusl8kn.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q= FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - Notify-avgrsstarter - avgrsstx.dll ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-14 11:26 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1516) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2184) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Roxio\Drag-to-Disc\Shellex.dll c:\windows\system32\DLAAPI_W.DLL c:\program files\Roxio\Drag-to-Disc\ShellRes.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\BCMWLTRY.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\progra~1\3M\PSNLite\PSNGive.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE . ************************************************************************** . Completion time: 2009-10-14 11:30 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-14 03:30 ComboFix2.txt 2009-10-13 14:58 Pre-Run: 10,704,814,080 bytes free Post-Run: 10,563,469,312 bytes free 209 --- E O F --- 2009-10-06 02:40
Attached File(s)
|
|
|
|
Oct 13 2009, 09:40 PM
Post
#9
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
You can reinstall AVG and Spybot now. Please do the following: Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Oct 14 2009, 02:54 AM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
included is the logs of Kaspersky report, and MBAM log
thanks
Attached File(s)
mbam_log_2009_10_14__12_22_21_.txt ( 967bytes )
Number of downloads: 13
Kaspersky_report.txt ( 1.04K )
Number of downloads: 14 |
|
|
|
Oct 14 2009, 03:04 AM
Post
#11
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
You are clean, the items found by Kaspersky are in quarantine or old restore points, which we will clean up now. Please do the following: Java™ 6 Update 13 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; > follow the prompts. NEXT You can delete the DDS and GMER folders from your desktop. NEXT Follow these steps to uninstall Combofix
![]() NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Oct 14 2009, 05:26 AM
Post
#12
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
thank you for the help.. i think im going to make a new thread for my pc at home...
thank you so much for the time spent for our problem |
|
|
|
Oct 14 2009, 05:38 AM
Post
#13
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
post a dds log, Attach.txt and GMER log for the 2nd computer here
|
|
|
|
Oct 14 2009, 12:34 PM
Post
#14
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 13-October 09 Member No.: 88,354 Operating System: windows xp |
hi this is the hijackfile , dds , attach and gmer log of my pc... this one usually has a certain period slowdown and programs often freeze whenever i use this computer
thank you
Attached File(s)
gmer.txt ( 48.96K )
Number of downloads: 70
hijackthis.txt ( 5.89K )
Number of downloads: 25
DDS.txt ( 9.46K )
Number of downloads: 67
Attach.txt ( 9.81K )
Number of downloads: 18 |
|
|
|
Oct 14 2009, 12:57 PM
Post
#15
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,682 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following:
NEXT Download TFC to your desktop
NEXT Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so. NEXT It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course: Using Internet Explorer or Firefox, visit Kaspersky Online Scanner: 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
8 | Alyaz | 141 | Today, 03:57 AM Last post by: CatByte |
|||
![]() |
7 | shawnav | 185 | Today, 02:06 AM Last post by: ken545 |
|||
![]() |
17 | massierick | 520 | Yesterday, 02:14 PM Last post by: extremeboy |
|||
![]() |
2 | KristyK | 72 | Yesterday, 06:32 AM Last post by: CatByte |
|||
|
Time is now: 22nd March 2010 - 07:21 AM |