This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Comp slow, email hijacked and spammed to friends and I

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good evening. Please bear with me as I am no good at this. My computer is acting up completely right now. Its slow, when I close programs that take up the full screen for example an mmo game that I play it wont exit out and i have to shut down my comp at the power strip and restart it. I cant even get it to shut down by hitting ctrl alt delete repeadly. As I type this message there is a delay before every letter shows up on the screen, its like I am typing to someone and then they are typing onto my computer. As I tried to send an email earlier today I got the same thing, the delay, but not all the letters would show up, I would get about half of them. I am really worried that something has possibly hijacked my computer. I ran avg and it found nothing, malwarebites found nothing as well the first time I ran it tonight. When I ran CA Yahoo! Anti-Spy, a spyware scanner that comes from yahoo in my yahoo tool bar it found quite alot. I had normal tracking cookies but it also said I had WinSpywareProtect a rogue security and Grokster and KaZaA which it called P2P. I searched my computer using my search option and I cant find either of those programs on my compter. The last thing yahoo said I had was Bifrost which it called a backdoor. I am very worried about that. I looked it up online and am now really freaked out. I just ran a malwarebites update and another scan as I wrote this post and it found something this time. Something called disabled security… I clicked to remove it but I know that doesnt always work. Please help me, I dont want to lose my computer or passwords or more importantly important data and files that are on my computer. I am putting my trust in you guys cause I just have no idea what to do. Please help. Here are my Hijackthis logs and the Malwarebyte log I just ran.

EDIT Sat March 28th Today a friend emailed me and I noticed that she had replied to an email I had sent her from my hotmail account. I have both hotmail and yahoo. The problem was, I havent been on my hotmail account in 3 months probally and I did not send out the email. So whatever is going on with my computer has now spread to include mass emailing thru my email accounts. I am completely in aloss here as to what to do. I am including a new Hijackthis log just incase this new issue is not on the one I first posted. Thanks a ton hope you can help me.

Morgan



HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56:39 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://games.myspace.com/gameshell/games/c…mesLauncher.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6931 bytes




MALWAREYTES LOG

Scan type: Quick Scan
Objects scanned: 69766
Time elapsed: 14 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Ugh! I dont know what to do, my hotmail account sent out another email without my consent. Its an advertisement that wants my friends to click on it. My comp is also still only typing half the letters I hit. I have to keep going back and retyping letters and correcting spelling, and I usually never have this problem. I dont want to change my password for fear that whatever is taking hold of my computer will now have the new password as well. I dont know what to do? Can you offer some advise. I dont want my friends infected or angry for that matter. Thanks again for you time, its much appreciated. Morgan
Hi Ladiebug,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'm not see any malware. Let's try an online scan.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Ugh!! I dont know what is going on. That scan was clean but I still dont know where the virus came from that went out thru an email account that I havent been on in months. Heres the report please tell me any ideas you have next. I do so appreciate it. Morgan ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, April 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, April 02, 2009 00:13:53 Records in database: 1994982 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics: Files scanned: 96307 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:14:29 No malware has been detected. The scan area is clean. The selected area was scanned.
Ladiebug,

It's entirely possible that the emails are not actually coming from your account. Sometimes malware is sent out "pretending" to be from an address that it isn't really from. There isn't anything I know of that you can do about it. Let's run a couple more scans looking for rootkit's.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.
Heres the first one, I cant do the other one until morning. I started and it kinda froze up and my eyes got too heavy. Thanks again for all your time. M ROOTER Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 C:\ [Fixed] - NTFS - (Total:152625 Mo/Free:245 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) E:\ [Removable] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:0 Mo/Free:0 Mo) G:\ [Removable] (Total:0 Mo/Free:0 Mo) H:\ [Removable] (Total:0 Mo/Free:0 Mo) Thu 04/02/2009| 4:28 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\WINDOWS\system32\nvsvc32.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\wdfmgr.exe ———- C:\PROGRA~1\AVG\AVG8\avgemc.exe ———- C:\PROGRA~1\AVG\AVG8\avgrsx.exe ———- C:\Program Files\AVG\AVG8\avgcsrvx.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\system32\VTTimer.exe ———- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe ———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe ———- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe ———- C:\PROGRA~1\AVG\AVG8\avgtray.exe ———- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe ———- C:\Program Files\Java\jre6\bin\jusched.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe ———- C:\Program Files\AVG\AVG8\avgscanx.exe ———- C:\Program Files\AVG\AVG8\avgcsrvx.exe ———- C:\Program Files\Internet Explorer\IEXPLORE.EXE ———- C:\PROGRA~1\AVG\AVG8\aAvgApi.exe ———- C:\PROGRA~1\AVG\AVG8\avgnsx.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! ———————-\\ Cracks & Keygens.. C:\DOCUME~1\Owner\Cookies\owner@crackle[1].txt C:\DOCUME~1\Owner\Local Settings\Temporary Internet Files\Content.IE5\TIK8L1VO\crackle_set5Godzilla40K15s_160x600[1].swf C:\DOCUME~1\Owner\Local Settings\Temporary Internet Files\Content.IE5\VLNGBE3X\crackle_set6SISwimsuitCovered40K15s_728x90[1].swf 1 - "C:\Rooter$\Rooter_1.txt" - Thu 04/02/2009| 4:31 ———————-\\ Scan completed at 4:31
Heres the gmer report, wow that sure took along time to run lol. Thanks again for everything, you guys are just awesome miracle workers.


EDIT: Ok I have 2 issues. First issue I didnt notice that you said dont run any programs while I was running the gmer program. I was actually on the internet while it was running. I hope this didnt affect the way the program runs. The second issue came when I tried to delete the program per your instructions. When I typed in the command prompt net stop gmer it gives me a message that says," The specified service does not exist as an installed service." I tried manually typing the words in and also copy and pasting your text it all gives me the same response. Thanks again for your help. I am not that great at this stuff.

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-02 15:36:26
Windows 5.1.2600 Service Pack 3


—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2540] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Ladiebug,

I'm not finding a cause for your problems. I don't think your computer is sending out the emails.

Log looks good :D


You need to create a new Clean restore point.
Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

Please delete Rooter from your Desktop and also deleter this folder: C:\Rooter$
Delete Gmer.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Alright I was able to do all of that without problem. Thanks so much for all the help. Whatever the problem, we must have caught it or something. I do apprecaite your time and all that you guys do. Your life savors for sure. Thanks again M
Ladiebug, Does it say "calulating disk space" "Please wait… This may take a few minutes" If so, then yes, you just want to wait.
oops I was editing my post while you were posting. That is exactly what it said. Sorry been along day and I just dont have my head on straight. Looks like I got it all done.
Ugh! I thought we were clean and good to go. I was on myspace tonight to do a few things when all of a sudden my page changed to the internet explore cant find located page thing. Like what happens when you are trying to go online and your internet isnt on. Thing of it was, I was typing a blog and it did it all of a sudden. I hit the back button and when I did a AVG notice popped up. But it popped up and closed so fast I didnt see it. I went into AVG's setting an in the WEB SHIELD FINDINGS it says, under the INFECTION spot "Exploit rogue spyware scanner (type 621)" and under the OBJECT spot it says, "activesecurityshield.com/index.php?affid=08043" Under DECTION TIME it says,"4/03/2009 3:36:19 AM" which is just a few minutes ago. Under OBJECT TYPE it says File. And under PROCESS is says,"C:\Program Files\Internet Explorer\iexplore.exe"" Is this something I need to be concerned with or something that just happens every once in a while. All I have done since your last steps was go to yahoo and read the news. Thats it. I didnt download anything or look around even for that matter. I havent been online most of the evening. If this is nothing to worry about please let me know. I am a tad neurotic and worry a ton. Thanks for helping me out. Ladie
Ladiebug,

Doesn't sound right to me. Let's dig in.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks again for taking your time, heres the combofix log. When I got the popup security warning I was pretty perplexed. I dont get them ever so I thought I would put it in your hands. Hope you get to enjoy yourself some this weekend.

Ladie

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1470.1043 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-04 to 2009-04-04 )))))))))))))))))))))))))))))))
.

2009-04-03 22:33 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-03 22:32 . 2009-04-03 22:34 d——– C:\32788R22FWJFW

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 22:23 ——— d—–w c:\program files\World of Warcraft
2009-03-27 06:12 ——— d—–w c:\program files\LimeWire
2009-03-27 05:37 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-03-26 20:49 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-03-23 21:00 ——— d—–w c:\program files\SecondLife
2009-03-19 19:15 ——— d—–w c:\documents and settings\Owner\Application Data\LimeWire
2009-03-10 07:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-10 07:43 ——— d—–w c:\program files\Java
2009-03-02 19:31 ——— d—–w c:\program files\HP
2009-02-28 08:00 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-24 23:48 ——— d—–w c:\program files\Yahoo! Games
2009-02-17 19:11 ——— d—–w c:\program files\Paint.NET
2009-02-11 10:09 ——— d—–w c:\program files\MSN Games
2009-02-11 03:17 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-11 02:55 ——— d—–w c:\documents and settings\All Users\Application Data\MythPeople
2009-02-11 02:54 ——— d—–w c:\program files\Oberon Media
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-04 00:56 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-01 19:59 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2008-03-09 22:42 0 -c–a-w c:\program files\temp01
2008-03-03 00:25 32 —-a-r c:\documents and settings\All Users\hash.dat
2008-12-23 05:30 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008122320081224\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-03-10 2356088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-09-30 176128]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-10 148888]
"VTTimer"="VTTimer.exe" [2006-09-14 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2007-04-25 c:\windows\system32\VTTrayp.exe]
"nwiz"="nwiz.exe" [2007-04-19 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-01 15:59 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\Infogrames Interactive\\Monopoly\\Monopoly.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\SecondLife\\SecondLife.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-03 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-07-03 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-05 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-05 298264]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfce1a1f-c8fc-11dd-bebe-0040caa82196}]
\Shell\AutoRun\command - I:\install.bat
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2008-04-13 20:12]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe


.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://games.myspace.com/gameshell/games/channel–110343720/lc–en/room–034af05f-5000-49bd-9acc-734bf6a9c6ef/online/mystery_pi_the_lottery_ticket/en/SpinTopGamesLauncher.cab
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-03 22:39:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2009-04-03 22:42:14
ComboFix-quarantined-files.txt 2009-04-04 02:40:57

Pre-Run: 130,179,776,512 bytes free
Post-Run: 130,481,098,752 bytes free

121 — E O F — 2009-03-15 07:09:17

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI