This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Brought to you by TQ!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Tomk! Good Day.. The combofix program saved on my desktop disappeared after i saved the CF Script.txt. How can i retrieve it. I did not uninstall the comboix program previously. Please advise. MasterOfDisaster :huh:
MasterOfDisaster,

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here
Tomk,

I have draged the CF Script yet. It hasn't scanned my PC.

All the same, here is what the ComboFix.txt file contained.


ComboFix 09-02-24.02 - Alvin Osana 2009-02-25 16:22:07.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.238.77 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alvin Osana\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 080920-0] *On-access scanning disabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ALVINO~1\LOCALS~1\Temp\tmp1.tmp
c:\documents and settings\Alvin Osana\ravmonlog
c:\documents and settings\Madeleen Osana\ravmonlog
c:\documents and settings\Mommy\ravmonlog
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Shared\002C7BDB.dat
c:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.

2009-02-25 08:57 . 2009-02-25 08:57 d——– c:\windows\LastGood
2009-02-24 11:51 . 2009-02-24 11:51 d——– c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 13:53 ——— d—–w c:\documents and settings\Mommy\Application Data\GetRightToGo
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\dllcache\srv.sys
2008-02-03 16:51 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 15:20 279944 –a—— c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-04 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 532480]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2004-07-14 151552]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2004-09-01 2876416]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2004-07-30 319488]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 45056]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-14 34880]

c:\documents and settings\Alvin Osana\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AttuneClientEngine]
–a—— 2000-07-24 23:47 356728 c:\progra~1\Aveo\Attune\bin\attune_ce.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a—— 2007-03-23 13:20 227328 c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus]
–a—— 2006-07-12 23:10 0 c:\documents and settings\Alvin Osana\Local Settings\Application Data\smss.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2008-11-05 21:59 4347120 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16757:TCP"= 16757:TCP:NortonAV
"18956:TCP"= 18956:TCP:NortonAV
"18172:TCP"= 18172:TCP:NortonAV
"15998:TCP"= 15998:TCP:NortonAV
"14877:TCP"= 14877:TCP:NortonAV
"16666:TCP"= 16666:TCP:NortonAV
"17119:TCP"= 17119:TCP:NortonAV
"14950:TCP"= 14950:TCP:NortonAV
"18323:TCP"= 18323:TCP:NortonAV
"14496:TCP"= 14496:TCP:NortonAV
"14292:TCP"= 14292:TCP:NortonAV
"13345:TCP"= 13345:TCP:NortonAV
"14842:TCP"= 14842:TCP:NortonAV
"12293:TCP"= 12293:TCP:NortonAV
"15490:TCP"= 15490:TCP:NortonAV
"13291:TCP"= 13291:TCP:NortonAV
"12944:TCP"= 12944:TCP:NortonAV
"15616:TCP"= 15616:TCP:NortonAV
"13346:TCP"= 13346:TCP:NortonAV
"14037:TCP"= 14037:TCP:NortonAV
"16436:TCP"= 16436:TCP:NortonAV
"13789:TCP"= 13789:TCP:NortonAV
"14565:TCP"= 14565:TCP:NortonAV
"16744:TCP"= 16744:TCP:NortonAV
"18712:TCP"= 18712:TCP:NortonAV
"14205:TCP"= 14205:TCP:NortonAV

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-28 78416]
R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\drivers\smbhc.sys [2004-08-30 6784]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-08-28 20560]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-12-27 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2004-12-27 78208]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-21 53248]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2004-06-01 10594]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-06-01 4054]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1980-01-01 140288]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\drivers\smbbatt.sys [2004-08-30 16128]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-21 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-21 77824]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\Auto\command - F:\AdobeR.exe e
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
.
Contents of the 'Scheduled Tasks' folder

2009-02-18 c:\windows\Tasks\At1.job
- c:\documents and settings\Mommy\Templates\WowTumpeh.com []

2009-02-25 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDetect.exe []

2009-02-25 c:\windows\Tasks\User_Feed_Synchronization-{7F7830BF-DBE3-4406-877D-B08A57D64E7F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
HKU-Default-Run-Tok-Cirrhatus - c:\documents and settings\NetworkService\Local Settings\Application Data\smss.exe
MSConfigStartUp-RavAV - c:\windows\AdobeR.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://global.acer.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://ph.yahoo.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 16:24:46
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-25 16:26:32
ComboFix-quarantined-files.txt 2009-02-25 08:26:30

Pre-Run: 78,151,680 bytes free
Post-Run: 1,476,591,616 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

180 — E O F — 2009-02-18 09:39:14



MasteOfDisaster
MasterOfDisaster, Sorry about that. I misunderstood what you were looking for. :blush: You just need to download it again from one of the links in post #8. Once you have it back on your desktop, drag the script and continue.
Hi tomk,

This is the result of the ComboFix scanning.

ComboFix 09-03-03.01 - Alvin Osana 2009-03-04 14:34:49.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.238.75 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alvin Osana\Desktop\CFScript.txt.txt
* Created a new restore point

FILE ::
c:\documents and settings\Mommy\Templates\WowTumpeh.com
c:\documents and settings\NetworkService\Local Settings\Application Data\smss.exe
c:\windows\Tasks\Symantec NetDetect.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\At1.job

.
((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.

2009-03-03 15:23 . 2009-03-03 15:23 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-01 21:45 . 2003-01-03 16:12 113,728 –a—— c:\windows\system32\drivers\ino_fltr.sys
2009-03-01 21:45 . 2003-02-10 14:48 36,864 –a—— c:\windows\RmvDir.exe
2009-03-01 21:45 . 2003-02-14 05:50 28,441 –a—— c:\windows\inoc6.icf
2009-03-01 21:45 . 2003-01-03 14:08 19,776 –a—— c:\windows\system32\drivers\ino_flpy.sys
2009-03-01 21:45 . 2009-03-01 21:45 47 –a—— c:\windows\InoSetup.ini
2009-02-24 11:51 . 2009-02-24 11:51 d——– c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 13:35 3,594,752 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-19 09:10 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 —-a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\dllcache\srv.sys
2008-02-03 16:51 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-02-25_16.25.37.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-26 07:24:28 124,928 ——w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 ——w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 ——w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 ——w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 ——w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-08-25 08:38:00 70,656 ——w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 ——w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 ——w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-08-23 05:54:52 161,792 ——w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 ——w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-08-26 07:24:30 384,512 ——w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-03 17:41:16 6,066,176 ——w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-08-26 07:24:30 267,776 ——w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 ——w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ——w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 ——w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 ——w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 ——w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 ——w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 ——w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 ——w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 ——w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 ——w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:42 213,216 ——w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ——w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 ——w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-08-26 07:24:32 1,159,680 ——w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-08-26 07:24:32 233,472 ——w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-08-26 07:24:32 826,368 ——w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 2007-07-19 01:41:14 3,640 —-a-r c:\windows\Installer\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}\ARPPRODUCTICON.exe
+ 2009-03-01 13:46:34 3,640 —-a-r c:\windows\Installer\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}\ARPPRODUCTICON.exe
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:12 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:12 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:14 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
- 2008-08-26 07:24:28 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:14 63,488 ——w c:\windows\system32\dllcache\icardie.dll
- 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-26 07:24:28 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:30 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:16 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 ——w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:22 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:30 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
- 2008-08-26 07:24:30 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:32 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-26 03:36:52 8,454,656 —-a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:16:58 8,454,656 —-a-w c:\windows\system32\dllcache\shell32.dll
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:40 105,984 —-a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:32 1,159,680 —-a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:32 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:32 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:42 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
- 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:14 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:14 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:38:00 70,656 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:16 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:52 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:30 384,512 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:16 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:22 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:30 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:16 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2009-01-16 13:35:14 3,594,752 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:32 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\occache.dll
- 2007-10-22 16:59:34 42,520 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-01 13:45:06 43,130 —-a-w c:\windows\system32\perfc009.dat
- 2007-10-22 16:59:34 317,028 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-01 13:45:06 317,638 —-a-w c:\windows\system32\perfh009.dat
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2007-10-26 03:36:52 8,454,656 —-a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:16:58 8,454,656 —-a-w c:\windows\system32\shell32.dll
- 2007-07-27 01:41:40 16,760 ——w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w c:\windows\system32\spmsg.dll
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:40 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:32 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:32 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-08-26 07:24:32 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:42 826,368 —-a-w c:\windows\system32\wininet.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-04 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 532480]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2004-07-14 151552]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2004-09-01 2876416]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2004-07-30 319488]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 45056]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2003-02-13 493024]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-14 34880]

c:\documents and settings\Alvin Osana\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AttuneClientEngine]
–a—— 2000-07-24 23:47 356728 c:\progra~1\Aveo\Attune\bin\attune_ce.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2008-11-05 21:59 4347120 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16757:TCP"= 16757:TCP:NortonAV
"18956:TCP"= 18956:TCP:NortonAV
"18172:TCP"= 18172:TCP:NortonAV
"15998:TCP"= 15998:TCP:NortonAV
"14877:TCP"= 14877:TCP:NortonAV
"16666:TCP"= 16666:TCP:NortonAV
"17119:TCP"= 17119:TCP:NortonAV
"14950:TCP"= 14950:TCP:NortonAV
"18323:TCP"= 18323:TCP:NortonAV
"14496:TCP"= 14496:TCP:NortonAV
"14292:TCP"= 14292:TCP:NortonAV
"13345:TCP"= 13345:TCP:NortonAV
"14842:TCP"= 14842:TCP:NortonAV
"12293:TCP"= 12293:TCP:NortonAV
"15490:TCP"= 15490:TCP:NortonAV
"13291:TCP"= 13291:TCP:NortonAV
"12944:TCP"= 12944:TCP:NortonAV
"15616:TCP"= 15616:TCP:NortonAV
"13346:TCP"= 13346:TCP:NortonAV
"14037:TCP"= 14037:TCP:NortonAV
"16436:TCP"= 16436:TCP:NortonAV
"13789:TCP"= 13789:TCP:NortonAV
"14565:TCP"= 14565:TCP:NortonAV
"16744:TCP"= 16744:TCP:NortonAV
"18712:TCP"= 18712:TCP:NortonAV
"14205:TCP"= 14205:TCP:NortonAV

R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\drivers\smbhc.sys [2004-08-30 6784]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-12-27 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2004-12-27 78208]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-21 53248]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2004-06-01 10594]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-06-01 4054]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1980-01-01 140288]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\drivers\smbbatt.sys [2004-08-30 16128]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-21 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-21 77824]
.
Contents of the 'Scheduled Tasks' folder

2009-03-04 c:\windows\Tasks\User_Feed_Synchronization-{7F7830BF-DBE3-4406-877D-B08A57D64E7F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-PCSuiteTrayApplication - c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://global.acer.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://ph.yahoo.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 14:36:48
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-04 14:38:16
ComboFix-quarantined-files.txt 2009-03-04 06:38:14
ComboFix2.txt 2009-02-25 08:26:34

Pre-Run: 2,535,374,848 bytes free
Post-Run: 2,595,487,744 bytes free

305 — E O F — 2009-02-25 09:43:50



UNlike the first time, the taskbar appeared after the scan.
Shall i proceed with the other scans?

MasterOfDisaster
Dear Tomk, I tried running the Kaspersky antivirus but i need to download the Java version 1.5. Can you provide me with a secure site for this? I tried checking the link on the kaspersky site but it gave me the Java Version 6. After installing the Jave, i still could NOT accept the kaspersky information. Please advise. MasterOfDisaster
MasterOfDisaster,

Version 6 is the one you want.

Once you have it installed, reboot your computer and try to run the scan again. If it still won't run, the do the following:

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Dear Tomk, Hello.. I'm using a different computer again. I will update you next week. Thanks a biggie… MasterOfDisaster
Hi tomk… The Kaspersky scan report is posted below. KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, March 10, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Tuesday, March 10, 2009 05:22:59 Records in database: 1884518 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 72232 Threat name: 1 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:10:18 File name / Threat name / Threats count C:\Documents and Settings\Alvin Osana\Desktop\seagate\mirc616.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1 C:\Temporary\mirc616.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1 The selected area was scanned. I will the te Hijackthis scan next. Update you. Thanks
Hi tomk,

Posted is the result of the HijackThis scan.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:50 PM, on 3/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ph.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1104261282272
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

–
End of file - 10063 bytes

What is our next move, Sir?

Thank you and sorry for the delay.


MasterOfDisaster
MasterOfDisaster,

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

With that done, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.
Please delete any other tools we used.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Hi tomk, I did the procedure that you asked on the HijackThis program.. after selectingand clicking fix checked, the HijackThis list cleared. I dont know if it did fix the problems. Did it actually fix the problems? Also, I had to reinstall the ComboFix program by the Post # 8 link for the third time. After typing the ComoFix /u on the run box, Combofix uninstalled. It didnt give me any confirmation of either Implement some cleanup procedures or Reset System Restore. It just said ComboFix is now uninstalled. Are these supposed to happen? Thanks again MasterOfDisaster
MasterOfDisaster, Yep. Probably. :P No confirmation from HJT. Those were just "clean-up" issues. Nothing dangerous. The only confirmation you'll get from ComboFix is the notice that it is uninstalled. At that point, ComboFix should have disappeared from your desktop. Your clock should have returned to normal settings. If these things happened, everything happened that was supposed to. Make sense?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI