This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virus check. Please

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

after being cleaned up a week or two ago by IndiGenious, i forgot to turn AVG resident shield back on.

I did last night and did a quick pc spyware doctor scan and found a few infections and threat.
Just wanted to check these out.

So if possible can i please get your help again just to check.

Hijack this log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:17 AM, on 6/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\csrss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\Ati2evxx.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\Ati2evxx.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\WINDOWS1\Explorer.EXE
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS1\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\PCSUITE.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS1\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS1\System32\alg.exe
C:\PROGRAM FILES\PRINTKEY2000\PRINTKEY2000.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tegan\Desktop\frostwire-4.17.2.windows.exe
C:\DOCUME~1\Tegan\LOCALS~1\Temp\nsp7A.tmp\askBarSetup-4.1.0.2.exe
C:\DOCUME~1\Tegan\LOCALS~1\Temp\is-DVK26.tmp\askBarSetup-4.1.0.2.tmp
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS1\system32\wbem\wmiprvse.exe
C:\DOCUME~1\Tegan\LOCALS~1\Temp\~nsu.tmp\Au_.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS1\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [dla] C:\WINDOWS1\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\PCSUITE.EXE" -onlytray
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1B4F9DD7-2D7C-44B5-9126-73206DA0AE75} (CNavigationManager Object) - http://files.authentium.com/bigpond/bin/wizard.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1219707987109
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS1\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS1\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - c:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 12357 bytes


Malwarebytes Log:

Malwarebytes' Anti-Malware 1.34
Database version: 1790
Windows 5.1.2600 Service Pack 3

6/03/2009 7:54:34 AM
mbam-log-2009-03-06 (07-54-34).txt

Scan type: Quick Scan
Objects scanned: 113519
Time elapsed: 13 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Information on last two scans from spyware doctor:


3/5/2009 9:01:33 PM:906
Service Started
Spyware Doctor Service Application started
3/5/2009 9:01:33 PM:906
Anti-Malware Engine
Anti-Malware engine configuration loaded successfully.
3/5/2009 9:01:37 PM:421
IntelliGuards status
All IntelliGuards were Enabled
3/5/2009 9:01:38 PM:984
Immunizer Results
ActiveX section has been immunized. No items were processed.
3/5/2009 9:01:50 PM:750
Scan Started
Scan Type - Intelli-Scan
3/5/2009 9:02:26 PM:140
Immunizer Results
ActiveX section has been immunized. No items were processed.
3/5/2009 9:03:08 PM:578
Infection was detected on this computer
Threat Name - Spyware.Known_Bad_Sites
Type - Cookie
Risk Level - High
Infection - cc-dt.com/ cc-dt.com
3/5/2009 9:03:08 PM:625
Infection was detected on this computer
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Cookie
Risk Level - High
Infection - coolpixhost.biz/ coolpixhost.biz
3/5/2009 9:03:34 PM:578
Immunizer Results
ActiveX section has been immunized. No items were processed.
3/5/2009 9:03:52 PM:62
Infection was detected on this computer
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\LK64IM1R\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…00&DlgY=650
3/5/2009 9:03:57 PM:859
Infection was detected on this computer
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\ZRCUKSLN\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…lgY=6507ebd00f5
3/5/2009 9:04:01 PM:890
Infection was detected on this computer
Threat Name - Spyware.Known_Bad_Sites
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\FGYG4T6U\88000000000065047[1].jpg - http://creative.cc-dt.com/pfx/210000000001…00000065047.jpg
3/5/2009 9:04:04 PM:578
Infection was detected on this computer
Threat Name - Spyware.Known_Bad_Sites
Type - Cookie
Risk Level - High
Infection - GUID cc-dt.com
3/5/2009 9:04:04 PM:640
Infection was detected on this computer
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Cookie
Risk Level - High
Infection - u1006 coolpixhost.biz
3/5/2009 9:04:06 PM:453
Infection was detected on this computer
Threat Name - Application.TrackingCookies
Type - Cookie
Risk Level - Low
Infection - s_vi_x7Bx7Bmxxodocamyx7F 112.2o7.net
3/5/2009 9:04:06 PM:468
Infection was detected on this computer
Threat Name - Adware.Advertising
Type - Cookie
Risk Level - Low
Infection - AA002 atdmt.com
3/5/2009 9:04:10 PM:31
Infection was detected on this computer
Threat Name - Adware.Advertising
Type - Cookie
Risk Level - Low
Infection - clk.atdmt.com
3/5/2009 9:04:11 PM:937
Infection was detected on this computer
Threat Name - Application.TrackingCookies
Type - Cookie
Risk Level - Low
Infection - pages.ebay.com.au
3/5/2009 9:04:29 PM:125
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow
3/5/2009 9:04:29 PM:125
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs
3/5/2009 9:04:29 PM:125
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, SnapShot
3/5/2009 9:04:29 PM:125
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware
3/5/2009 9:04:29 PM:156
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance
3/5/2009 9:04:29 PM:156
Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME
3/5/2009 9:04:30 PM:625
Infection was detected on this computer
Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-2000478354-1993962763-725345543-1003\Software\Wget
3/5/2009 9:11:18 PM:515
Scan Finished
Scan Type - Intelli-Scan
Items Processed - 214588
Threats Detected - 6
Infections Detected - 18
Infections Ignored - 0
3/5/2009 9:11:24 PM:562
Anti-Malware Engine
Anti-Malware engine configuration loaded successfully.
3/5/2009 9:11:39 PM:875
Infection quarantined
Threat Name - Spyware.Known_Bad_Sites
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\FGYG4T6U\88000000000065047[1].jpg - http://creative.cc-dt.com/pfx/210000000001…00000065047.jpg
3/5/2009 9:11:41 PM:203
Infection cleaned
Threat Name - Spyware.Known_Bad_Sites
Type - Cookie
Risk Level - High
Infection - GUID cc-dt.com
3/5/2009 9:11:41 PM:312
Infection cleaned
Threat Name - Spyware.Known_Bad_Sites
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\FGYG4T6U\88000000000065047[1].jpg - http://creative.cc-dt.com/pfx/210000000001…00000065047.jpg
3/5/2009 9:11:41 PM:328
Infection cleaned
Threat Name - Spyware.Known_Bad_Sites
Type - Cookie
Risk Level - High
Infection - cc-dt.com/ cc-dt.com
3/5/2009 9:11:41 PM:671
Infection quarantined
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\ZRCUKSLN\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…lgY=6507ebd00f5
3/5/2009 9:11:41 PM:718
Infection quarantined
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\LK64IM1R\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…00&DlgY=650
3/5/2009 9:11:41 PM:953
Infection cleaned
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Cookie
Risk Level - High
Infection - u1006 coolpixhost.biz
3/5/2009 9:11:41 PM:968
Infection cleaned
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\ZRCUKSLN\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…lgY=6507ebd00f5
3/5/2009 9:11:41 PM:984
Infection cleaned
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Internet Temporary File
Risk Level - High
Infection - C:\Documents and Settings\Tegan\Local Settings\Temporary Internet Files\Content.IE5\LK64IM1R\provider_license_v7[1].htm - http://coolpixhost.biz/rd/provider_license…00&DlgY=650
3/5/2009 9:11:41 PM:984
Infection cleaned
Threat Name - Trojan-Downloader.WMA.GetCodec
Type - Cookie
Risk Level - High
Infection - coolpixhost.biz/ coolpixhost.biz
3/5/2009 9:11:42 PM:468
Infection cleaned
Threat Name - Application.TrackingCookies
Type - Cookie
Risk Level - Low
Infection - pages.ebay.com.au
3/5/2009 9:11:42 PM:890
Infection cleaned
Threat Name - Application.TrackingCookies
Type - Cookie
Risk Level - Low
Infection - s_vi_x7Bx7Bmxxodocamyx7F 112.2o7.net
3/5/2009 9:11:43 PM:296
Infection cleaned
Threat Name - Adware.Advertising
Type - Cookie
Risk Level - Low
Infection - clk.atdmt.com
3/5/2009 9:11:43 PM:453
Infection cleaned
Threat Name - Adware.Advertising
Type - Cookie
Risk Level - Low
Infection - AA002 atdmt.com
3/5/2009 9:11:43 PM:843
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME
3/5/2009 9:11:43 PM:843
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance
3/5/2009 9:11:43 PM:843
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware
3/5/2009 9:11:43 PM:859
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, SnapShot
3/5/2009 9:11:43 PM:859
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs
3/5/2009 9:11:43 PM:859
Infection quarantined
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, SnapShot
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs
3/5/2009 9:11:44 PM:31
Infection cleaned
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow
3/5/2009 9:11:44 PM:93
Infection quarantined
Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-2000478354-1993962763-725345543-1003\Software\Wget
3/5/2009 9:11:44 PM:296
Infection cleaned
Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-2000478354-1993962763-725345543-1003\Software\Wget
3/5/2009 9:11:46 PM:421
Infections Quarantined/Removed Summary
Quarantined - 10
Quarantine Failed - 0
Removed - 18
Remove Failed - 0
3/5/2009 9:12:04 PM:546
Scan Started
Scan Type - Full Scan
3/6/2009 7:17:26 AM:171
Service Started
Spyware Doctor Service Application started
3/6/2009 7:17:26 AM:171
Anti-Malware Engine
Anti-Malware engine configuration loaded successfully.
3/6/2009 7:17:26 AM:359
IntelliGuards status
All IntelliGuards were Enabled
3/6/2009 7:17:29 AM:203
Immunizer Results
ActiveX section has been immunized. No items were processed.
3/6/2009 7:31:30 AM:984
Immunizer Results
ActiveX section has been immunized. No items were processed.
3/6/2009 7:55:09 AM:906
Scan Started
Scan Type - Intelli-Scan
3/6/2009 8:01:55 AM:312
Scan Finished
Scan Type - Intelli-Scan
Items Processed - 217767
Threats Detected - 0
Infections Detected - 0
Infections Ignored - 0
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around.

Looks like it found mainly Cookies and leftovers of ComboFix. However, if you wish to have a deeper look, please do the following.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI