This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser Search Hijacker + Blocked AV Sites. What Malwa

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

This forum was a great help to me a couple years back when I was a bit less cautious than I am now. :)

Unfortunately, my browser has been hijacked again despite running Ad-Aware Aniv edition (current profiles) and McAfee AV (current profiles).

They're unable to remove/detect whatever the source is, though they are removing all the carp** it tries to load through redirections.

As something of a techie, I'm not really being terribly inconvenienced as I can swap in another HD as soon as I'm fed up, but my curiousity is piqued as to how this stuff is affecting the OS. So I'm more interesting in the more manual options if possible rather than the brute force wipe/restore the OS or run some automated tool. Maybe this stuff has become too sophisticated since I last dealt with it but I can't hurt to ask I guess… :)

So here's the symptoms:

1) Typing in the web addresses of major AV sites directly into the address bar responds with a 404 error. Typing in the IP works. So no http://www.mcafee.com but 216.xx.xx.xx works. Even www.whatthetech.com is gives 404. Congrats, you're famous enough spyware hates you! I thought maybe DNS was being hijacked, and maybe it us, but setting up my TCP/IP client to force AT&T's DNS server did not help. How is the spyware hijacking/blocking my address window?

2) Generic.dx is being regenerated constantly. Ad-Aware misses it. McAfee removes it every time I run a scan manually, but doesn't block it from getting installed with its always on protection.

3) Search data in IE6 and Firefox 3 is faked or redirected somehow. The actual results of the search look fine, but clicking on the links starts the process of redirecting to a different "search" site like webreadon.com, search2.com, live.search.com or similar and then the behind the scenes process of downloading piles of spyware carp** and popups that give fake warnings like my machine is infected to trigger even more spyware. Mcafee is able to remove this stuff, but again isn't preventing it from getting on the machine with realtime scanning which I find strange.

Despite the situation with McAfee not detecting this stuff, they want $89 to even let me talk to someone in their virus removal support team.

Anyway, maybe the stuff is too complex now and I have to give up on satisfying my curiousity and just go with some automated tool or a OS restore rather than learn about what it's doing, but if the above symptoms have some known source malware or general manual solutions I'd be interested in a reference to the info.
Hi NickName, :welcome:

My name is SpySentinel and I will be helping you with your malware problem.


Please visit the Self Help Thread and follow the instructions, then post a HJT log here in a reply.
Hi, I'll try. The obstacle is that due to item #1 it's difficult to even visit this site from the infected machine. Right now I'm at work on a different PC and it'll probably be a very slow back and forth for the most part if I can't find some workaround or solution to #1 so I can get to these forums and the sites with AV tools directly from the infected system.
Edited out the HJT version number to avoid your clever little redirector. :) The infected machine can't get to the site to download it as the malware is blocking it. I'll bring a copy home of HJT2 tonight and see if it'll install okay. Hopefully this log from 1.99 is an acceptable starting point.

(I'm a bit suspicious of the Java stuff and maybe those weird browser helper object entries, but we'll see how my layman's guess stacks up. :P)

Scan saved at 10:13:31 AM, on 2/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\MDM.EXE
C:\Downloads\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,
O2 - BHO: (no name) - {#06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Skype add-on (mastermind) - {#22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
O2 - BHO: (no name) - {#761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: scriptproxy - {#7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
O2 - BHO: (no name) - {#B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
O2 - BHO: (no name) - {#C9C42510-9B21-41c1-9DCD-8382A2D07C61} - (no file)
O2 - BHO: (no name) - {#DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {#E7E6F031-17CE-4C07-BC86-EABFE594F69C} - (no file)
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.the-holocron.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1176313003984
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A876265-EA61-4452-9EFF-8E8E80FC6F69}: NameServer = 68.94.156.1,68.94.157.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Nice job tricking the malware ;)


Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
hey hey, able to access whatthetech.com from the (formerly?) infected machine which means the address bar malware is gone at minimum. The two logs follow. I'm not going to try a browser search (which previously restarted the malware downloads) until you give the go ahead.



ComboFix 09-02-17.02 - Jason Tanner 2009-02-19 0:39:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1136 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\ihjmpo.ini
c:\windows\system32\drivers\UACqpqbfooe.sys
c:\windows\system32\mdm.exe
c:\windows\system32\twain32
c:\windows\system32\twain32\local.ds
c:\windows\system32\twain32\user.ds
c:\windows\system32\UACfubqabyr.dll
c:\windows\system32\UACfvmpvitc.log
c:\windows\system32\UACfwbmeeec.dll
c:\windows\system32\UACilcpxiyr.log
c:\windows\system32\UACjpijcyxu.dll
c:\windows\system32\UACqhxnsxiy.log
c:\windows\system32\UACqxewbjeu.dll
c:\windows\system32\UACshmfdbwr.dat
c:\windows\system32\wpv911233967690.cpx
c:\windows\wiaserviv.log
c:\windows\winhelp.ini
c:\windows\yxxyyb.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-01-19 to 2009-02-19 )))))))))))))))))))))))))))))))
.

2009-02-14 14:07 . 2009-02-14 14:07 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_14_07_38.dmp
2009-02-14 14:06 . 2009-02-14 14:06 d——– c:\program files\MSXML 4.0
2009-02-14 01:11 . 2009-02-14 01:11 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_01_11_02.dmp
2009-02-14 00:19 . 2009-02-14 00:19 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_00_19_24.dmp
2009-02-13 23:22 . 2009-02-13 23:22 24,899 –a—— c:\windows\system32\AAWService_2009_02_13_23_22_52.dmp
2009-02-13 23:09 . 2009-02-13 22:28 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-13 22:29 . 2009-02-13 22:29 d—-c— c:\windows\system32\DRVSTORE
2009-02-13 22:29 . 2009-02-13 22:28 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-13 22:25 . 2009-02-13 22:25 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-13 22:24 . 2009-02-13 22:28 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-13 20:32 . 2009-02-13 20:32 775,168 –a—— c:\windows\isRS-000.tmp
2009-02-13 20:31 . 2009-02-13 20:31 d——– C:\Binaries
2009-02-13 20:28 . 2009-02-13 20:28 164 –a—— C:\install.dat
2009-02-13 19:58 . 2009-02-16 18:37 d——– c:\documents and settings\LocalService\Application Data\SACore
2009-02-13 18:13 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-13 18:13 . 2009-02-19 00:38 8,805 –a—— c:\windows\system32\Config.MPF
2009-02-13 18:08 . 2009-02-13 18:08 d——– c:\program files\McAfee.com
2009-02-13 18:08 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-02-13 18:08 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-02-13 18:08 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-02-13 18:08 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-02-13 18:08 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-02-13 18:08 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-02-13 18:07 . 2009-02-16 12:01 d——– c:\program files\McAfee
2009-02-13 18:07 . 2009-02-13 18:08 d——– c:\program files\Common Files\McAfee
2009-02-13 17:20 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-02-13 00:57 . 2009-02-18 08:43 5,541 –a—— c:\windows\system32\uacinit.dll
2009-02-13 00:56 . 2009-02-13 00:56 22,016 –a—— c:\windows\system32\#digeste.dll
2009-02-13 00:39 . 2009-02-13 00:39 d——– c:\program files\uTorrent
2009-02-13 00:39 . 2009-02-13 01:15 d——– c:\documents and settings\Jason Tanner\Application Data\uTorrent
2009-02-03 00:02 . 2009-02-13 20:39 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-03 00:02 . 2009-02-03 00:02 1,409 –a—— c:\windows\QTFont.for
2009-01-30 01:53 . 2009-02-18 09:53 d——– C:\Incomplete
2009-01-30 01:52 . 2009-02-18 10:04 d——– c:\documents and settings\Jason Tanner\Application Data\LimeWire
2009-01-30 01:51 . 2009-01-30 01:52 d——– c:\program files\LimeWire
2009-01-19 23:11 . 2009-02-19 00:23 d——– c:\documents and settings\Jason Tanner\Application Data\skypePM
2009-01-19 23:11 . 2009-01-19 23:11 48 –ah—– c:\windows\system32\ezsidmv.dat
2009-01-19 23:07 . 2009-02-19 00:24 d——– c:\documents and settings\Jason Tanner\Application Data\Skype
2009-01-19 22:53 . 2009-01-19 22:53 d——– c:\program files\Skype
2009-01-19 22:53 . 2009-01-19 22:53 d——– c:\program files\Common Files\Skype
2009-01-19 22:53 . 2009-01-19 22:53 d——– c:\documents and settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 06:24 ——— d—–w c:\program files\Lavasoft
2009-02-03 08:31 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\ArcSoft
2009-02-03 08:30 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 08:30 ——— d—–w c:\program files\ArcSoft
2009-01-06 05:38 ——— d—–w c:\program files\Common Files\Adobe
2009-01-06 05:38 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\AdobeUM
2009-01-02 02:34 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-01-02 02:34 ——— d—–w c:\program files\Java
2005-06-06 06:05 90,702 —-a-w c:\documents and settings\Jason Tanner\BlindTop.zip
2005-06-06 06:05 74,052 —-a-w c:\documents and settings\Jason Tanner\ZapWars.zip
2005-06-06 06:05 255,840 —-a-w c:\documents and settings\Jason Tanner\Raj.zip
2005-05-14 01:12 217,073 –sha-r c:\windows\meta4.exe
2005-10-24 19:13 66,560 –sha-r c:\windows\MOTA113.exe
2005-10-14 05:27 422,400 –sha-r c:\windows\x2.64.exe
2005-10-08 03:14 308,224 –sha-r c:\windows\system32\avisynth.dll
2005-07-14 20:31 27,648 –sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 23:32 616,448 –sha-r c:\windows\system32\cygwin1.dll
2005-06-22 06:37 45,568 –sha-r c:\windows\system32\cygz.dll
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\i420vfw.dll
2006-04-27 18:24 2,945,024 –sha-r c:\windows\system32\Smab.dll
2005-02-28 21:16 240,128 –sha-r c:\windows\system32\x.264.exe
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-r 49,152 2002-12-17 18:40:22 c:\program files\Hewlett-Packard\HP Software Update\bak\HPWuSchd.exe

—-a-w 184,320 2003-12-18 21:37:58 c:\program files\HP DVD\Umbrella\bak\DVDBitSet.exe

—-a-w 69,632 2003-07-23 17:42:04 c:\program files\HP DVD\Umbrella\bak\DVDTray.exe

—-a-w 32,881 2004-02-23 06:44:44 c:\program files\Java\j2re1.4.2_04\bin\bak\jusched.exe

—-a-w 458,752 2004-06-01 19:09:50 c:\program files\Logitech\Video\bak\ISStart.exe

—-a-w 217,088 2004-06-01 19:03:18 c:\program files\Logitech\Video\bak\LogiTray.exe

—-a-w 196,608 2004-06-01 10:46:37 c:\program files\Logitech\Video\bak\ManifestEngine.exe

—-a-w 155,648 2005-12-16 18:10:10 c:\program files\QuickTime\bak\qttask.exe

—-a-w 991,232 2006-03-18 17:18:00 c:\program files\Real\RealPlayer\bak\realplay.exe

—-a-w 1,269,760 2007-01-09 07:07:43 c:\program files\Valve\Steam\bak\Steam.exe

—-a-w 3,084,288 2005-08-20 02:34:02 c:\program files\Yahoo!\Messenger\bak\ypager.exe

—-a-w 221,184 2004-05-22 03:11:22 c:\windows\system32\bak\LVCOMSX.EXE

—-a-w 99,840 2003-06-04 10:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_S4I2F1.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [N/A]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-13 509784]
"C-Media Mixer"="Mixer.exe" [2001-12-07 c:\windows\Mixer.exe]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"SENTINEL"= snti386.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-13 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-13 203280]
S3 adxapie;adxapie;\??\c:\docume~1\JASONT~1\LOCALS~1\Temp\adxapie.sys –> c:\docume~1\JASONT~1\LOCALS~1\Temp\adxapie.sys [?]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2004-05-31 759050]
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\drivers\CamDrL20.sys [2005-03-12 245760]
.
Contents of the 'Scheduled Tasks' folder

2009-02-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-13 22:28]

2009-02-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-02-14 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -

BHO-{#06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
BHO-{#22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
BHO-{#761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
BHO-{#7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
BHO-{#B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
BHO-{#C9C42510-9B21-41c1-9DCD-8382A2D07C61} - (no file)
BHO-{#DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
BHO-{#E7E6F031-17CE-4C07-BC86-EABFE594F69C} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: aol.com\free
Trusted Zone: the-holocron.com
Trusted Zone: turbotax.com
TCP: {9A876265-EA61-4452-9EFF-8E8E80FC6F69} = 68.94.156.1,68.94.157.1
FF - ProfilePath - c:\documents and settings\Jason Tanner\Application Data\Mozilla\Firefox\Profiles\ddmn4gtn.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Jason Tanner\Application Data\Real\RhapsodyPlayerEngine\nprhapengine.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-19 00:45:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-19 0:47:59
ComboFix-quarantined-files.txt 2009-02-19 08:47:17

Pre-Run: 10,815,483,904 bytes free
Post-Run: 10,893,590,528 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

220 — E O F — 2009-02-14 22:07:03




=================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:53 AM, on 2/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.the-holocron.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1176313003984
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A876265-EA61-4452-9EFF-8E8E80FC6F69}: NameServer = 68.94.156.1,68.94.157.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 6107 bytes
Glad to hear we are hitting this infection head on.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\uacinit.dll
c:\windows\system32\#digeste.dll

Folder::
c:\program files\uTorrent
c:\documents and settings\Jason Tanner\Application Data\uTorrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire
c:\program files\LimeWire

Driver::
Lbd
adxapie


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 09-02-19.01 - Jason Tanner 2009-02-20 8:57:43.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1156 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Jason Tanner\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\system32\#digeste.dll
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\uacinit.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jason Tanner\Application Data\LimeWire
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar Galactica.S04.E13.VOSTFR.XviD.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E11.HDTV.XviD-aAF.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E12.A.Disquiet.Follows.My.Soul.HDTV.XviD-FQM.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E14.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Lost S05E04 VOSTFR XviD.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Lost.S05E05.HDTV,XviD.SWESUB-KickFoot.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Jason Tanner\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\downloads.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Jason Tanner\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\filters.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\gnutella.net
c:\documents and settings\Jason Tanner\Application Data\LimeWire\installation.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\library.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\limewire.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\mojito.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Jason Tanner\Application Data\LimeWire\questions.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\responses.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\simpp.xml
c:\documents and settings\Jason Tanner\Application Data\LimeWire\spam.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\tables.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\version.xml
c:\documents and settings\Jason Tanner\Application Data\LimeWire\versions.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Jason Tanner\Application Data\uTorrent
c:\documents and settings\Jason Tanner\Application Data\uTorrent\dht.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\resume.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Jason Tanner\Application Data\uTorrent\rss.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\settings.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\settings.dat.old
c:\program files\LimeWire
c:\program files\LimeWire\.NetworkShare\LimeWireWin4.18.8.exe
c:\program files\LimeWire\Buy LimeWire PRO.url
c:\program files\LimeWire\COPYING
c:\program files\LimeWire\data.ser
c:\program files\LimeWire\inspection.props
c:\program files\LimeWire\install.log
c:\program files\LimeWire\language.prop
c:\program files\LimeWire\lib\aopalliance.jar
c:\program files\LimeWire\lib\clink.jar
c:\program files\LimeWire\lib\commons-codec-1.3.jar
c:\program files\LimeWire\lib\commons-logging.jar
c:\program files\LimeWire\lib\commons-net.jar
c:\program files\LimeWire\lib\daap.jar
c:\program files\LimeWire\lib\dnsjava.jar
c:\program files\LimeWire\lib\forms.jar
c:\program files\LimeWire\lib\foxtrot.jar
c:\program files\LimeWire\lib\gettext-commons.jar
c:\program files\LimeWire\lib\guice-1.0.jar
c:\program files\LimeWire\lib\hashes
c:\program files\LimeWire\lib\hsqldb.jar
c:\program files\LimeWire\lib\httpclient-4.0-alpha5-20080522.192134-5.jar
c:\program files\LimeWire\lib\httpcore-4.0-beta2-20080510.140437-10.jar
c:\program files\LimeWire\lib\httpcore-nio-4.0-beta2-20080510.140437-10.jar
c:\program files\LimeWire\lib\icu4j.jar
c:\program files\LimeWire\lib\jaudiotagger.jar
c:\program files\LimeWire\lib\jcraft.jar
c:\program files\LimeWire\lib\jdic.dll
c:\program files\LimeWire\lib\jdic.jar
c:\program files\LimeWire\lib\jdic_stub.jar
c:\program files\LimeWire\lib\jflac.jar
c:\program files\LimeWire\lib\jl.jar
c:\program files\LimeWire\lib\jmdns.jar
c:\program files\LimeWire\lib\jogg.jar
c:\program files\LimeWire\lib\jorbis.jar
c:\program files\LimeWire\lib\LimeWire.ico
c:\program files\LimeWire\lib\LimeWire.jar
c:\program files\LimeWire\lib\log4j.jar
c:\program files\LimeWire\lib\log4j.properties
c:\program files\LimeWire\lib\looks.jar
c:\program files\LimeWire\lib\messages.jar
c:\program files\LimeWire\lib\mp3spi.jar
c:\program files\LimeWire\lib\onion-common.jar
c:\program files\LimeWire\lib\onion-fec.jar
c:\program files\LimeWire\lib\ProgressTabs.jar
c:\program files\LimeWire\lib\swt.jar
c:\program files\LimeWire\lib\SystemUtilities.dll
c:\program files\LimeWire\lib\SystemUtilitiesA.dll
c:\program files\LimeWire\lib\themes.jar
c:\program files\LimeWire\lib\tray.dll
c:\program files\LimeWire\lib\tritonus.jar
c:\program files\LimeWire\lib\vorbisspi.jar
c:\program files\LimeWire\LimeWire On Startup.lnk
c:\program files\LimeWire\LimeWire.exe
c:\program files\LimeWire\LimeWire.ico
c:\program files\LimeWire\pmf.ico
c:\program files\LimeWire\root\magnet10\badge.img
c:\program files\LimeWire\root\magnet10\canHandle.img
c:\program files\LimeWire\root\magnet10\limewire.gif
c:\program files\LimeWire\root\magnet10\options.js
c:\program files\LimeWire\root\magnet10\silentdetect.js
c:\program files\LimeWire\SOURCE
c:\program files\LimeWire\spacer.gif
c:\program files\LimeWire\uninstall.exe
c:\program files\LimeWire\unpack.log
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\uacinit.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ADXAPIE
——-\Legacy_LBD
——-\Service_adxapie
——-\Service_Lbd


((((((((((((((((((((((((( Files Created from 2009-01-20 to 2009-02-20 )))))))))))))))))))))))))))))))
.

2009-02-19 00:55 . 2009-02-19 00:55 d——– c:\program files\Trend Micro
2009-02-14 14:07 . 2009-02-14 14:07 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_14_07_38.dmp
2009-02-14 14:06 . 2009-02-14 14:06 d——– c:\program files\MSXML 4.0
2009-02-14 01:11 . 2009-02-14 01:11 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_01_11_02.dmp
2009-02-14 00:19 . 2009-02-14 00:19 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_00_19_24.dmp
2009-02-13 23:22 . 2009-02-13 23:22 24,899 –a—— c:\windows\system32\AAWService_2009_02_13_23_22_52.dmp
2009-02-13 23:09 . 2009-02-13 22:28 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-13 22:29 . 2009-02-13 22:29 d—-c— c:\windows\system32\DRVSTORE
2009-02-13 22:25 . 2009-02-13 22:25 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-13 22:24 . 2009-02-13 22:28 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-13 20:32 . 2009-02-13 20:32 775,168 –a—— c:\windows\isRS-000.tmp
2009-02-13 20:31 . 2009-02-13 20:31 d——– C:\Binaries
2009-02-13 20:28 . 2009-02-13 20:28 164 –a—— C:\install.dat
2009-02-13 19:58 . 2009-02-16 18:37 d——– c:\documents and settings\LocalService\Application Data\SACore
2009-02-13 18:13 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-13 18:13 . 2009-02-20 09:03 8,965 –a—— c:\windows\system32\Config.MPF
2009-02-13 18:08 . 2009-02-13 18:08 d——– c:\program files\McAfee.com
2009-02-13 18:08 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-02-13 18:08 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-02-13 18:08 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-02-13 18:08 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-02-13 18:08 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-02-13 18:08 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-02-13 18:07 . 2009-02-16 12:01 d——– c:\program files\McAfee
2009-02-13 18:07 . 2009-02-13 18:08 d——– c:\program files\Common Files\McAfee
2009-02-13 17:20 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-02-03 00:02 . 2009-02-13 20:39 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-03 00:02 . 2009-02-03 00:02 1,409 –a—— c:\windows\QTFont.for
2009-01-30 01:53 . 2009-02-18 09:53 d——– C:\Incomplete

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 17:04 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\Skype
2009-02-20 16:45 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\skypePM
2009-02-14 06:24 ——— d—–w c:\program files\Lavasoft
2009-02-03 08:31 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\ArcSoft
2009-02-03 08:30 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 08:30 ——— d—–w c:\program files\ArcSoft
2009-01-20 06:53 ——— d—–w c:\program files\Skype
2009-01-20 06:53 ——— d—–w c:\program files\Common Files\Skype
2009-01-20 06:53 ——— d—–w c:\documents and settings\All Users\Application Data\Skype
2009-01-06 05:38 ——— d—–w c:\program files\Common Files\Adobe
2009-01-06 05:38 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\AdobeUM
2009-01-02 02:34 ——— d—–w c:\program files\Java
2005-06-06 06:05 90,702 —-a-w c:\documents and settings\Jason Tanner\BlindTop.zip
2005-06-06 06:05 74,052 —-a-w c:\documents and settings\Jason Tanner\ZapWars.zip
2005-06-06 06:05 255,840 —-a-w c:\documents and settings\Jason Tanner\Raj.zip
2005-05-14 01:12 217,073 –sha-r c:\windows\meta4.exe
2005-10-24 19:13 66,560 –sha-r c:\windows\MOTA113.exe
2005-10-14 05:27 422,400 –sha-r c:\windows\x2.64.exe
2005-10-08 03:14 308,224 –sha-r c:\windows\system32\avisynth.dll
2005-07-14 20:31 27,648 –sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 23:32 616,448 –sha-r c:\windows\system32\cygwin1.dll
2005-06-22 06:37 45,568 –sha-r c:\windows\system32\cygz.dll
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\i420vfw.dll
2006-04-27 18:24 2,945,024 –sha-r c:\windows\system32\Smab.dll
2005-02-28 21:16 240,128 –sha-r c:\windows\system32\x.264.exe
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-02-19_ 0.45.38.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 04:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-19 08:28:32 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-20 16:53:00 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-19 08:28:32 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-20 16:53:00 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-20 17:02:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_254.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-r 49,152 2002-12-17 18:40:22 c:\program files\Hewlett-Packard\HP Software Update\bak\HPWuSchd.exe

—-a-w 184,320 2003-12-18 21:37:58 c:\program files\HP DVD\Umbrella\bak\DVDBitSet.exe

—-a-w 69,632 2003-07-23 17:42:04 c:\program files\HP DVD\Umbrella\bak\DVDTray.exe

—-a-w 32,881 2004-02-23 06:44:44 c:\program files\Java\j2re1.4.2_04\bin\bak\jusched.exe

—-a-w 458,752 2004-06-01 19:09:50 c:\program files\Logitech\Video\bak\ISStart.exe

—-a-w 217,088 2004-06-01 19:03:18 c:\program files\Logitech\Video\bak\LogiTray.exe

—-a-w 196,608 2004-06-01 10:46:37 c:\program files\Logitech\Video\bak\ManifestEngine.exe

—-a-w 155,648 2005-12-16 18:10:10 c:\program files\QuickTime\bak\qttask.exe

—-a-w 991,232 2006-03-18 17:18:00 c:\program files\Real\RealPlayer\bak\realplay.exe

—-a-w 1,269,760 2007-01-09 07:07:43 c:\program files\Valve\Steam\bak\Steam.exe

—-a-w 3,084,288 2005-08-20 02:34:02 c:\program files\Yahoo!\Messenger\bak\ypager.exe

—-a-w 221,184 2004-05-22 03:11:22 c:\windows\system32\bak\LVCOMSX.EXE

—-a-w 99,840 2003-06-04 10:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_S4I2F1.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [N/A]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-13 509784]
"C-Media Mixer"="Mixer.exe" [2001-12-07 c:\windows\Mixer.exe]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"SENTINEL"= snti386.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-13 203280]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2004-05-31 759050]
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\drivers\CamDrL20.sys [2005-03-12 245760]
.
Contents of the 'Scheduled Tasks' folder

2009-02-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-13 22:28]

2009-02-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-02-14 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: aol.com\free
Trusted Zone: the-holocron.com
Trusted Zone: turbotax.com
TCP: {9A876265-EA61-4452-9EFF-8E8E80FC6F69} = 68.94.156.1,68.94.157.1
FF - ProfilePath - c:\documents and settings\Jason Tanner\Application Data\Mozilla\Firefox\Profiles\ddmn4gtn.default\
FF - plugin: c:\documents and settings\Jason Tanner\Application Data\Real\RhapsodyPlayerEngine\nprhapengine.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-20 09:04:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-02-20 9:11:44 - machine was rebooted [Jason Tanner]
ComboFix-quarantined-files.txt 2009-02-20 17:11:38
ComboFix2.txt 2009-02-19 08:48:01

Pre-Run: 10,833,260,544 bytes free
Post-Run: 10,755,223,552 bytes free

337 — E O F — 2009-02-14 22:07:03
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.




Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Here's the logs. The Kaspersky tool behaved rather oddly. It just ended at 58% and wouldn't continue. It detected a legitmate program (CuteFTP) which has an ad banner module that I really use so I marked to skip it. It's been on my machine for 5+ years without a problem and even Kasperky notes it's not a virus. I like the tool, so I don't mind the banner ads. But it just got in a loop where it would detect the first file, then I'd skip it, it then detected the others which I'd also skip and it would go back again to the first. Eventually I used Remove from List. The end report also doesn't seem to have the other virus files it found. The were related to packed.win32.tdss.c. And finally, when I couldn't do anything else but close it at 58% complete, when it uninstalled and tried to restart the system Windows noted this odd file as unable to properly shut down AB4GB.EXE. ========= Malwarebytes' Anti-Malware 1.34 Database version: 1783 Windows 5.1.2600 Service Pack 3 2/20/2009 11:33:28 PM mbam-log-2009-02-20 (23-33-28).txt Scan type: Quick Scan Objects scanned: 60016 Time elapsed: 4 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ============== ============== 58% - Scan ———- Scanned: 800681 Detected: 8 Untreated: 3 Start time: 2/20/2009 11:56:44 PM Duration: 08:50:01 Finish time: 2/21/2009 3:03:53 PM Detected ——– Status Object —— —— detected: adware not-a-virus:AdWare.Win32.Aureate.a File: C:\Downloads\cute3032.exe//WISE0011.BIN/advert.dll detected: adware not-a-virus:AdWare.Win32.Aureate.a File: C:\Program Files\GlobalSCAPE\CuteFTP\advert.dll detected: adware not-a-virus:AdWare.Win32.Aureate.a File: C:\WINDOWS\system32\advert.dll Events —— Time Name Status Reason —- —- —— —— 2/20/2009 11:56:58 PM Running module: smss.exe\smss.exe ok scanned Statistics ———- Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted —— ——- ——– ——— ——- ——————- ——– ———— —————— ——— Settings ——– Parameter Value ——— —– Security Level Custom Action Prompt for action when the scan is complete Run mode Manually File types Scan all files Scan only new and changed files No Scan archives All Scan embedded OLE objects All Skip if object is larger than No Skip if scan takes longer than No Parse email formats No Scan password-protected archives No Enable iChecker technology No Enable iSwift technology No Show detected threats on "Detected" tab Yes Rootkits search Yes Deep rootkits search Yes Use heuristic analyzer Yes Quarantine ———- Status Object Size Added —— —— —- —– Backup —— Status Object Size —— —— —-
Hm that is odd, never had that happen with Kaspersky before. Lets try this instead:

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
Here's the superantispyware log. The instructions didn't mention shutting down other AV and I didn't notice McAfee was running at the start. McAfee also detected and removed some stuff from the _RESTORE folder during the SAS scan. Can't find a McAfee log that will cut/paste, but here's what was found and says it successfully removed. If you need more info let me know.

Generic.dx
Adware-abetterintrnt
Adware-GameSpyArcade.lnk
Adware-WurldMedia

=========

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/23/2009 at 09:28 AM

Application Version : 4.25.1012

Core Rules Database Version : 3770
Trace Rules Database Version: 1729

Scan type : Complete Scan
Total Scan Time : 00:30:05

Memory items scanned : 429
Memory threats detected : 0
Registry items scanned : 5091
Registry threats detected : 0
File items scanned : 22701
File threats detected : 25

Adware.Tracking Cookie
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@adlegend[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@adrevolver[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@specificclick[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@doubleclick[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@hitbox[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@revsci[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@atdmt[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@cgi-bin[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@specificmedia[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@trafficmp[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@advertising[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@zedo[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@adinterax[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@gadget[1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][1].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@kontera[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@questionmarket[2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason [removed][2].txt
C:\Documents and Settings\Jason Tanner\Cookies\jason tanner@shopica[2].txt

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1AAA0BCA-2F7E-4C09-9F71-8B9EBC61438C}\RP1137\A0056930.DLL

If you need more info let me know.


Looks good, nice work!



Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack.

Please go to the link below to update.

http://www.adobe.com/products/acrobat/readstep2.html



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI