This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help needed! PC stops at "welcome" screen

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, guys. First of all I must praise you for doing such a great job here.

The sad thing is that my PC is infected with some trojan/virus, and I know it's my own fault. I downloaded this torrent "http://thepiratebay.org/torrent/4729171/Monopoly_2008_3D_version___Working_Crack" without reading the comments which was very stupid. I installed it and suddenly my antivirus (AVG) notifyes me that I have some trouble. I try to make it to fix the problem but the AVG can only send it to "vault". After this I ran a number of different antivirus- and malwarescans but none seemed to fix the problem because the AVG kept on sending me messages.

I restared my computer but when I tried to use it I couldn't click anything, nothing responded. So I restarted again in "safe mode" to do a "system restore". This did not work because when it tries to restart it stops at the "welcome" screen. I did this again for three times butwith no further success.

Someone told me to change the AVG into a different antivirus but a message saying "system administrator denies installation" (freely translated from swedish) pops up. Maybe this is only because it's in "safe mode" but I can still install other programs that aren't antiviruses.

I'll be very grateful if you try to help me/ DS

Here's my HJT-log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:01:19, on 2009-03-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.netpede.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Orbit.lnk.disabled
O4 - Global Startup: Trojan Guarder.lnk = C:\Program Files\Trojan Guarder\Trojan Guarder.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: donkeymails.com - {3B1BD330-82D0-4a56-AE53-C9EF12F6093D} - C:\Program Files\Internet Explorer\PLUGINS\toolbar4198185.dll
O9 - Extra 'Tools' menuitem: donkeymails.com - {3B1BD330-82D0-4a56-AE53-C9EF12F6093D} - C:\Program Files\Internet Explorer\PLUGINS\toolbar4198185.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://format.packardbell.com/cgi-bin/redirect/?country=SE&range=AD&phase=7&key=IESTART
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

–
End of file - 3778 bytes
Hi avskum,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Looks like you've managed to install some rogue spyware. Let's see a little more about what's going on.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Download the diagnostic tool MGADiag and save it to your desktop.

  • Double-click on MGADiag.exe.
  • Click Run and Run again.
  • Click Continue, then Copy.
  • Paste the report in your next reply.
Here is the logs

MGADia

Diagnostic Report (1.9.0006.1):
—————————————–
WGA Data–>
Validation Status: Genuine
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-YXDGW-VHYVW-9QK9M
Windows Product Key Hash: H7Smr1ocYUxDDsppdbyzUwQFi5U=
Windows Product ID: 76487-OEM-2211906-00824
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.2.0.med
ID: {396BBDB7-F219-4143-87BA-289984C14EF5}(1)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.17.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: 0
File Exists: Yes
Version: 1.7.17.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 101 Not Activated
Microsoft Word 2002 - 101 Not Activated
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1_3E121E02-385-80004005_3E121E02-452-80004005_3E121E02-312-80004005

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\PROGRA~1\MOZILL~1\FIREFOX.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {396BBDB7-F219-4143-87BA-289984C14EF5}1.9.0006.15.1.2600.2.00010100.2.0.medx32*****-*****-*****-*****-9QK9M76487-OEM-2211906-008242S-1-5-21-2079639103-3000294904-3235288827Packard Bell BVIMEDIA MC 2590American Megatrends Inc.Rio3010520061107000000.000000+000NECC_,NEC-PC,NEC Computers,NEC_Product0D02305F01842E6C041D0409W. Europe Standard Time(GMT+01:00)02Packard BellPackard Bell Computer101

Licensing Data–>
N/A

HWID Data–>
N/A

OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 13E7B:GENUINE C&C INC|18867:Packard Bell B.V|18867:Packard Bell B.V
Marker string from OEMBIOS.DAT: NECC_,NEC-PC,NEC Computers,NEC_Product

OEM Activation 2.0 Data–>
N/A


Rooster log


Microsoft Windows XP Professional (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:230471 Mo/Free:2877 Mo)
D:\ [Fixed] - NTFS - (Total:238475 Mo/Free:626 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
K:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
L:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
M:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
N:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
O:\ [Removable] (Total:0 Mo/Free:0 Mo)

2009-03-19|18:38

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\notepad.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - 2009-03-19|18:40

———————-\\ Scan completed at 18:40
avskum,

Well, that looks promising. :)

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
My PC still acts as before. When rebooted it stops at the welcome-screen.

I ran two scans in malawarebytes because the first one was written in swedish, I post both, though.
Also there is a new HTJ log.


Swedish scan

Malwarebytes' Anti-Malware 1.34
Databasversion: 1749
Windows 5.1.2600 Service Pack 2

2009-03-21 15:00:47
mbam-log-2009-03-21 (15-00-47).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 71262
Förfluten tid: 14 minute(s), 22 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 0
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 1

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
(Inga illasinnade poster hittades)

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\WINDOWS\system32\drivers\synsenddrv.sys (Trojan.Agent) -> Quarantined and deleted successfully.


Englsih scan

Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 2

2009-03-21 23:22:17
mbam-log-2009-03-21 (23-22-17).txt

Scan type: Quick Scan
Objects scanned: 71294
Time elapsed: 12 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


New HTJ-scan


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:01:56, on 2009-03-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.netpede.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Orbit.lnk.disabled
O4 - Global Startup: Trojan Guarder.lnk = C:\Program Files\Trojan Guarder\Trojan Guarder.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: donkeymails.com - {3B1BD330-82D0-4a56-AE53-C9EF12F6093D} - C:\Program Files\Internet Explorer\PLUGINS\toolbar4198185.dll
O9 - Extra 'Tools' menuitem: donkeymails.com - {3B1BD330-82D0-4a56-AE53-C9EF12F6093D} - C:\Program Files\Internet Explorer\PLUGINS\toolbar4198185.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://format.packardbell.com/cgi-bin/redirect/?country=SE&range=AD&phase=7&key=IESTART
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

–
End of file - 4011 bytes
avskum,

Let's dig a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix log


ComboFix 09-03-22.01 - Daniel Sving 2009-03-23 16:14:00.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.597 [GMT 1:00]
Körs från: c:\documents and settings\Daniel Sving\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Start Menu\Programs\Startup\Trojan Guarder.lnk
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder\Contact Us.lnk
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder\Help.lnk
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder\Trojan Guarder.lnk
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder\Uninstall.lnk
c:\documents and settings\All Users\Start Menu\Programs\Trojan Guarder\Visit Our Site.lnk
c:\documents and settings\Daniel Sving\Application Data\inst.exe
c:\documents and settings\Daniel Sving\Desktop\Trojan Guarder.lnk
c:\program files\Trojan Guarder
c:\program files\Trojan Guarder\Anti_Virus Help.chm
c:\program files\Trojan Guarder\AquaOS.dll
c:\program files\Trojan Guarder\BlockList.txt
c:\program files\Trojan Guarder\Contact.exe
c:\program files\Trojan Guarder\hook.dll
c:\program files\Trojan Guarder\msvcm.dll
c:\program files\Trojan Guarder\Products.htm
c:\program files\Trojan Guarder\SkinPPWTL.dll
c:\program files\Trojan Guarder\Trojan Guarder.exe
c:\program files\Trojan Guarder\trojan.update
c:\program files\Trojan Guarder\unins000.dat
c:\program files\Trojan Guarder\unins000.exe
c:\program files\Trojan Guarder\unism.dll
c:\program files\Trojan Guarder\update.exe
c:\program files\Trojan Guarder\Visit Our Site.url
c:\windows\system32\drivers\str.sys

—– BITS: Troligen infekterade webbplatser —–

hxxp://www.wzporn.com
.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_SYNSEND


(((((((((((((((((((((((( Filer Skapade från 2009-02-25 till 2009-03-25 ))))))))))))))))))))))))))))))
.

2009-03-21 11:31 . 2009-03-23 15:06 664 –a—— c:\windows\system32\d3d9caps.dat
2009-03-19 18:38 . 2009-03-19 18:40 d——– C:\Rooter$
2009-03-19 18:36 . 2009-03-19 18:36 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-03-15 16:10 . 2009-03-15 16:10 d——– c:\program files\ERUNT
2009-03-15 15:23 . 2009-03-15 15:23 d——– c:\program files\Trend Micro
2009-03-15 11:46 . 2009-03-23 16:13 d——– c:\windows\system32\CatRoot2
2009-03-14 19:49 . 2009-03-14 19:49 d——– c:\program files\Trojan Remover
2009-03-14 19:49 . 2009-03-14 19:49 d——– c:\documents and settings\Daniel Sving\Application Data\Simply Super Software
2009-03-14 19:49 . 2009-03-14 19:49 d——– c:\documents and settings\All Users\Application Data\Simply Super Software
2009-03-14 19:49 . 2006-05-25 14:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll
2009-03-14 19:49 . 2003-02-02 19:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-14 19:49 . 2005-08-26 00:50 77,312 –a—— c:\windows\system32\ztvunace26.dll
2009-03-14 19:49 . 2002-03-06 00:00 75,264 –a—— c:\windows\system32\unacev2.dll
2009-03-14 19:49 . 2006-06-19 12:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll
2009-03-13 17:33 . 2009-03-13 17:34 d——– c:\program files\Spyware Doctor
2009-03-13 17:33 . 2009-03-13 17:33 d——– c:\documents and settings\Daniel Sving\Application Data\PC Tools
2009-03-13 17:33 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2009-03-13 17:33 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2009-03-13 17:33 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2009-03-13 17:33 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2009-03-13 14:38 . 2009-03-13 14:38 78,976 –a—— c:\windows\system32\drivers\ctrkfzcckt.sys
2009-03-10 21:21 . 2009-03-12 20:34 d——– c:\windows\system32\config\systemprofile\Application Data\Orbit
2009-03-10 18:00 . 2009-03-10 18:00 78,976 –a—— c:\windows\system32\drivers\ihohmob.sys
2009-03-04 21:28 . 2009-03-04 21:28 d——– c:\program files\CCleaner
2009-03-04 21:20 . 2009-03-04 21:24 d——– c:\program files\Security Task Manager
2009-03-04 21:20 . 2009-03-14 19:43 d——– c:\documents and settings\All Users\Application Data\SecTaskMan
2009-03-04 13:27 . 2009-03-04 13:27 d——– c:\documents and settings\Daniel Sving\WINDOWS
2009-02-25 16:16 . 2009-02-25 16:16 d——– c:\documents and settings\Daniel Sving\Application Data\Agency9
2009-02-25 09:41 . 2009-01-09 20:18 1,089,601 ——— c:\windows\system32\dllcache\ntprint.cat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 20:21 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-03-13 16:36 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-13 13:33 31,608 —-a-w c:\documents and settings\Daniel Sving\Application Data\wklnhst.dat
2009-03-10 17:00 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\uTorrent
2009-03-06 10:46 ——— d—–w c:\program files\DC++
2009-03-06 03:11 ——— d—–w c:\program files\uTorrent
2009-03-05 15:30 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\Spotify
2009-03-05 15:23 ——— d—–w c:\program files\Google
2009-03-04 20:29 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\Orbit
2009-02-28 18:30 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\GigaTribe
2009-02-11 09:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-08 13:19 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-08 13:16 ——— d—–w c:\program files\Microsoft Visual Studio 8
2009-02-07 10:27 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-05 19:55 76,776 —-a-w c:\documents and settings\Daniel Sving\Application Data\GDIPFONTCACHEV1.DAT
2008-08-04 12:26 47,360 —-a-w c:\documents and settings\Daniel Sving\Application Data\pcouffin.sys
2007-04-24 18:54 299,008 —-a-w c:\program files\internet explorer\plugins\toolbar4198185.dll
2008-12-21 00:00 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-21 00:00 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-21 00:00 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-21 00:00 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-21 00:00 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"MXOBG"="c:\windows\MXOALDR.EXE" [2003-10-10 94208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-03-07 1303432]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-23 c:\windows\RTHDCPL.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk.disabled [2009-03-10 1557]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 15:13 49152 c:\progra~1\COMMON~1\stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Daniel Sving^Start Menu^Programs^Startup^GigaTribe.lnk]
path=c:\documents and settings\Daniel Sving\Start Menu\Programs\Startup\GigaTribe.lnk
backup=c:\windows\pss\GigaTribe.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Daniel Sving^Start Menu^Programs^Startup^TribalWeb.lnk]
path=c:\documents and settings\Daniel Sving\Start Menu\Programs\Startup\TribalWeb.lnk
backup=c:\windows\pss\TribalWeb.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-05-10 12:12 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
–a—— 2006-08-23 09:31 53248 c:\program files\Realtek\InstallShield\AzMixerSel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2006-11-12 11:48 157592 c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DetectorApp]
–a—— 2005-10-20 07:15 102400 c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-09-29 15:01 67584 c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
–a—— 2004-08-31 09:23 823296 c:\progra~1\MAXTOR~1\OneTouch\Utils\OneTouch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mRouterConfig]
–a—— 2006-03-02 11:54 290816 c:\program files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2006-01-24 19:32 7094272 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite for Smartphones]
-ra—— 2007-12-25 15:53 548864 c:\program files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys]
–a—— 2005-12-08 17:39 975360 c:\apps\SMP\SMPSYS.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-01-28 10:43 2097488 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-11-09 14:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
–a—— 2006-08-23 09:30 2879488 c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"x10nets"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"USBDeviceService"=2 (0x2)
"UleadBurningHelper"=2 (0x2)
"LiveUpdate"=3 (0x3)
"Automatisk LiveUpdate-schemaläggare"=2 (0x2)
"gusvc"=2 (0x2)
"gupdate1c996a88760ef1e"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\++Spel++\\RISK II\\RiskII.exe"=
"c:\\++Spel++\\EMPIRES2.ICD"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Daniel Sving\\Desktop\\Client-Windows\\Client-Windows.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20800:TCP"= 20800:TCP:BitComet 20800 TCP
"20800:UDP"= 20800:UDP:BitComet 20800 UDP
"50789:TCP"= 50789:TCP:BitComet 50789 TCP
"50789:UDP"= 50789:UDP:BitComet 50789 UDP

R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2006-11-30 7040]
S2 jhowkhjncl;jhowkhjncl;c:\windows\system32\drivers\ctrkfzcckt.sys [2009-03-13 78976]
S2 vxytwmyjofpsoq;vxytwmyjofpsoq;c:\windows\system32\drivers\ihohmob.sys [2009-03-10 78976]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2006-11-30 825600]
S4 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2007-01-21 100032]
S4 gupdate1c996a88760ef1e;Tjänsten Google Update (gupdate1c996a88760ef1e);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-13 356920]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34ec1062-2f40-11dd-87bb-001921583844}]
\Shell\AutoRun\command - M:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59351359-fef4-11db-866d-001921583844}]
\Shell\AutoRun\command - L:\Install.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94305b64-b156-11db-861c-001921583844}]
\Shell\AutoRun\command - K:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f12ff26c-8667-11dd-8809-001921583844}]
\Shell\AutoRun\command - N:\RunGame.exe
.
Innehållet i mappen 'Schemalagda aktiviteter':

2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 18:51]
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

HKLM-RunOnce- - (no file)
MSConfigStartUp-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
MSConfigStartUp-Mercora - c:\program files\Mercora\MercoraClient.exe


.
——- Extra genomsökning ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: &D&ownload &with BitComet
IE: &D&ownload all video with BitComet
IE: &D&ownload all with BitComet
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: {{3B1BD330-82D0-4a56-AE53-C9EF12F6093D} - {0C2DE3EC-DB84-4eeb-9FC1-69B5153C4239} -
FF - ProfilePath - c:\documents and settings\Daniel Sving\Application Data\Mozilla\Firefox\Profiles\nhccxgh5.default\
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-25 17:43:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_USERS\S-1-5-21-2079639103-3000294904-3235288827-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:26,7b,c3,3d,d5,27,c4,99,75,1e,28,27,1d,75,12,37,de,ba,52,83,13,d2,68,
d9,0d,23,03,d3,d1,06,88,72,cc,2a,f6,ea,1b,34,08,1e,c5,7f,cc,fa,f7,07,90,94,\
"??"=hex:02,b7,9d,4c,cb,9a,76,75,6f,8f,3a,89,5a,9f,d7,89
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'winlogon.exe'(300)
c:\windows\system32\Ati2evxx.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
.
———————— Andra processer som körs ————————
.
c:\progra~1\COMMON~1\stardock\SDMCP.exe
.
**************************************************************************
.
Sluttid: 2009-03-25 17:52:16 - datorn startades om.
ComboFix-quarantined-files.txt 2009-03-25 16:52:13

Före genomsökningen: 123 201 572 864 bytes free
Efter genomsökningen: 123,386,093,568 byte ledigt

281 — E O F — 2009-02-25 22:18:19
avskum,

DC++, BitComet, Limewire and uTorrent
You have DC++, BitComet, Limewire and uTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. There is little doubt that this is the source of your infections. You'll be doing yourself a favor by removing them.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall DC++, BitComet, Limewire and uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep them, please do not use them until your computer is cleaned.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\system32\drivers\ctrkfzcckt.sys
    c:\windows\system32\drivers\ihohmob.sys
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34ec1062-2f40-11dd-87bb-001921583844}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59351359-fef4-11db-866d-001921583844}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94305b64-b156-11db-861c-001921583844}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f12ff26c-8667-11dd-8809-001921583844}]
    
    Driver::
    jhowkhjncl
    vxytwmyjofpsoq
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Maybe I've forgot to tell you, but I can't connect to the internet. I've used this laptop to download files and then getting them to the infected computer by a mp3-player. I unplugged the internet shortly after getting the infection because I did not want any more carp**. Later when I tried to connect it again for some reason it dosen't seem to work. I don't know why. Maybe it's because i'm working in safe-mode. Besides, as I told you I uninstalled my antivirus (AVG) to install another one, but it did not work. Even I know connecting to the internet without an antivirus installed isn't recommended. So I can't really do the Java-thing, right? The same thing goes with the online scan. However I did the COMBOFíx scan and here is the results: ComboFix 09-03-22.01 - Daniel Sving 2009-03-30 15:57:23.2 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.583 [GMT 2:00] Körs från: c:\documents and settings\Daniel Sving\Desktop\ComboFix.exe Använda kommandoväxlar :: c:\documents and settings\Daniel Sving\Desktop\CFScript.txt FW: Norton Internet Worm Protection *disabled* FILE :: c:\windows\system32\drivers\ctrkfzcckt.sys c:\windows\system32\drivers\ihohmob.sys . ((((((((((((((((((((((((((((((((((((((( Andra raderingar )))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\drivers\ctrkfzcckt.sys c:\windows\system32\drivers\ihohmob.sys . ((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_JHOWKHJNCL ——-\Legacy_VXYTWMYJOFPSOQ ——-\Service_jhowkhjncl ——-\Service_vxytwmyjofpsoq (((((((((((((((((((((((( Filer Skapade från 2009-02-28 till 2009-03-30 )))))))))))))))))))))))))))))) . 2009-03-21 12:31 . 2009-03-30 14:42 664 –a—— c:\windows\system32\d3d9caps.dat 2009-03-19 19:38 . 2009-03-19 19:40 d——– C:\Rooter$ 2009-03-19 19:36 . 2009-03-19 19:36 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2009-03-15 17:10 . 2009-03-15 17:10 d——– c:\program files\ERUNT 2009-03-15 16:23 . 2009-03-15 16:23 d——– c:\program files\Trend Micro 2009-03-15 12:46 . 2009-03-30 15:57 d——– c:\windows\system32\CatRoot2 2009-03-14 20:49 . 2009-03-14 20:49 d——– c:\program files\Trojan Remover 2009-03-14 20:49 . 2009-03-14 20:49 d——– c:\documents and settings\Daniel Sving\Application Data\Simply Super Software 2009-03-14 20:49 . 2009-03-14 20:49 d——– c:\documents and settings\All Users\Application Data\Simply Super Software 2009-03-14 20:49 . 2006-05-25 15:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll 2009-03-14 20:49 . 2003-02-02 20:06 153,088 –a—— c:\windows\system32\UNRAR3.dll 2009-03-14 20:49 . 2005-08-26 01:50 77,312 –a—— c:\windows\system32\ztvunace26.dll 2009-03-14 20:49 . 2002-03-06 01:00 75,264 –a—— c:\windows\system32\unacev2.dll 2009-03-14 20:49 . 2006-06-19 13:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll 2009-03-13 18:33 . 2009-03-13 18:34 d——– c:\program files\Spyware Doctor 2009-03-13 18:33 . 2009-03-13 18:33 d——– c:\documents and settings\Daniel Sving\Application Data\PC Tools 2009-03-13 18:33 . 2008-08-25 13:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys 2009-03-13 18:33 . 2008-08-25 13:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys 2009-03-13 18:33 . 2008-08-25 13:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys 2009-03-13 18:33 . 2008-06-02 17:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys 2009-03-10 22:21 . 2009-03-12 21:34 d——– c:\windows\system32\config\systemprofile\Application Data\Orbit 2009-03-04 22:28 . 2009-03-04 22:28 d——– c:\program files\CCleaner 2009-03-04 22:20 . 2009-03-04 22:24 d——– c:\program files\Security Task Manager 2009-03-04 22:20 . 2009-03-14 20:43 d——– c:\documents and settings\All Users\Application Data\SecTaskMan 2009-03-04 14:27 . 2009-03-04 14:27 d——– c:\documents and settings\Daniel Sving\WINDOWS 2009-02-25 17:16 . 2009-02-25 17:16 d——– c:\documents and settings\Daniel Sving\Application Data\Agency9 2009-02-25 10:41 . 2009-01-09 21:18 1,089,601 ——— c:\windows\system32\dllcache\ntprint.cat 2009-02-24 19:50 . 2009-03-05 17:23 d——– c:\program files\Google 2009-02-08 15:16 . 2009-02-08 15:16 d——– c:\program files\Microsoft Visual Studio 8 2009-02-08 15:15 . 2009-02-08 15:19 d——– c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-08 15:14 . 2009-02-08 15:14 dr-h—– C:\MSOCache 2009-02-07 12:19 . 2009-02-07 12:19 d——– c:\windows\Logs . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-19 20:21 ——— d—–w c:\program files\Malwarebytes' Anti-Malware 2009-03-13 16:36 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP 2009-03-13 13:33 31,608 —-a-w c:\documents and settings\Daniel Sving\Application Data\wklnhst.dat 2009-03-05 15:30 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\Spotify 2009-03-04 20:29 ——— d—–w c:\documents and settings\Daniel Sving\Application Data\Orbit 2009-02-11 09:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 09:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys 2009-02-07 10:27 ——— d–h–w c:\program files\InstallShield Installation Information 2008-11-05 19:55 76,776 —-a-w c:\documents and settings\Daniel Sving\Application Data\GDIPFONTCACHEV1.DAT 2008-08-04 12:26 47,360 —-a-w c:\documents and settings\Daniel Sving\Application Data\pcouffin.sys 2007-04-24 18:54 299,008 —-a-w c:\program files\internet explorer\plugins\toolbar4198185.dll 2008-12-21 00:00 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll 2008-12-21 00:00 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll 2008-12-21 00:00 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll 2008-12-21 00:00 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll 2008-12-21 00:00 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( SnapShot@2009-03-25_17.49.38.60 ))))))))))))))))))))))))))))))))))))))))) . - 2005-10-20 19:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE + 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE - 2005-10-20 19:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE + 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE - 2000-08-31 07:00:00 29,696 —-a-w c:\windows\NIRCMD.exe + 2000-08-31 06:00:00 29,696 —-a-w c:\windows\NIRCMD.exe - 2000-08-31 07:00:00 161,792 —-a-w c:\windows\SWREG.exe + 2000-08-31 06:00:00 161,792 —-a-w c:\windows\SWREG.exe - 2009-03-13 16:29:02 71,060 —-a-w c:\windows\system32\perfc009.dat + 2009-03-30 12:26:32 71,060 —-a-w c:\windows\system32\perfc009.dat - 2009-03-13 16:29:02 441,124 —-a-w c:\windows\system32\perfh009.dat + 2009-03-30 12:26:32 441,124 —-a-w c:\windows\system32\perfh009.dat . (((((((((((((((((((((((((((((((((( Startpunkter i registret ))))))))))))))))))))))))))))))))))))))))))))))) . . *Not* Tomma poster & legitima standardposter visas inte. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952] "MXOBG"="c:\windows\MXOALDR.EXE" [2003-10-10 94208] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] "TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-03-07 1303432] "RTHDCPL"="RTHDCPL.EXE" [2006-08-23 c:\windows\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Orbit.lnk.disabled [2009-03-10 1557] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\windows\system32\logonuiX.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient] 2005-01-31 16:13 49152 c:\progra~1\COMMON~1\stardock\MCPStub.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm "msacm.mpegacm"= mpegacm.acm "msacm.ulmp3acm"= ulmp3acm.acm "msacm.ac3filter"= ac3filter.acm "vidc.hfyu"= huffyuv.dll "msacm.divxa32"= DivXa32.acm [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Daniel Sving^Start Menu^Programs^Startup^GigaTribe.lnk] path=c:\documents and settings\Daniel Sving\Start Menu\Programs\Startup\GigaTribe.lnk backup=c:\windows\pss\GigaTribe.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Daniel Sving^Start Menu^Programs^Startup^TribalWeb.lnk] path=c:\documents and settings\Daniel Sving\Start Menu\Programs\Startup\TribalWeb.lnk backup=c:\windows\pss\TribalWeb.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] –a—— 2006-05-10 13:12 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel] –a—— 2006-08-23 10:31 53248 c:\program files\Realtek\InstallShield\AzMixerSel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] –a—— 2006-11-12 12:48 157592 c:\program files\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DetectorApp] –a—— 2005-10-20 08:15 102400 c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] –a—— 2005-09-29 16:01 67584 c:\windows\ehome\ehtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch] –a—— 2004-08-31 10:23 823296 c:\progra~1\MAXTOR~1\OneTouch\Utils\OneTouch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mRouterConfig] –a—— 2006-03-02 12:54 290816 c:\program files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] –a—— 2004-10-13 18:24 1694208 c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] –a—— 2006-01-24 20:32 7094272 c:\program files\MSN Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite for Smartphones] -ra—— 2007-12-25 16:53 548864 c:\program files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] –a—— 2008-09-06 16:09 413696 c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys] –a—— 2005-12-08 18:39 975360 c:\apps\SMP\SMPSYS.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] -rahs—- 2008-01-28 11:43 2097488 c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] –a—— 2006-11-09 15:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] –a—— 2006-08-23 10:30 2879488 c:\windows\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "x10nets"=2 (0x2) "WMPNetworkSvc"=3 (0x3) "USBDeviceService"=2 (0x2) "UleadBurningHelper"=2 (0x2) "LiveUpdate"=3 (0x3) "Automatisk LiveUpdate-schemaläggare"=2 (0x2) "gusvc"=2 (0x2) "gupdate1c996a88760ef1e"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0)
avskum, You told me. I had hoped you could get on now and I didn't ask. :blush: Sorry about that. Can you download Anti-virus, transfer, and get it installed, then see if you can connect? Are you not able to log on in normal mode? Is safe mode the only thing that works?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI