This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible lando trojan, Hijackthis log, help, please an

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Nbake,

Let's just check the one file to make sure it's not a false Positive on Kaspersky's part. It is a legitimate file name.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, into the "Suspicious files to scan" box on the top of the page:

    C:\WINDOWS\system32\WgaTray.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

The other one we will remove and clean out the temp folders at the same time.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\apiqkuasu.dll
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please post back with
  • VirScan results
  • OTMOVEIT3 log.

How the computer?

Thanks
oldman960,

The computer has been much better lately, thank you.

Here is the OTMOVEIT3 log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\apiqkuasu.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Nick\LOCALS~1\Temp\etilqs_fmPx5CMIYlTAgPKgg1dF scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\mcafee_frkP65Dr706t01W scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_j26N5XeLEVMdzAD scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_n25ODiANDrJTK8u scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_ozQQgC5a1N8IupL scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_qcfFgLqpoTHAnkV scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_258.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\WFV38.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04062009_012259

Files moved on Reboot…
File C:\DOCUME~1\Nick\LOCALS~1\Temp\etilqs_fmPx5CMIYlTAgPKgg1dF not found!
File C:\WINDOWS\temp\mcafee_frkP65Dr706t01W not found!
File C:\WINDOWS\temp\mcmsc_j26N5XeLEVMdzAD not found!
File C:\WINDOWS\temp\mcmsc_n25ODiANDrJTK8u not found!
File C:\WINDOWS\temp\mcmsc_ozQQgC5a1N8IupL not found!
File C:\WINDOWS\temp\mcmsc_qcfFgLqpoTHAnkV not found!
File C:\WINDOWS\temp\Perflib_Perfdata_258.dat not found!
File C:\WINDOWS\temp\WFV38.tmp not found!
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\XUL.mfl moved successfully.

And the Virscan log:

VirSCAN.org Scanned Report :
Scanned time : 2009/04/06 01:29:39 (MDT)
Scanner results: 22% Scanner(8/37) found malware!
File Name : WgaTray.exe
File Size : 332672 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : de9c69997c0ae174f7ea3f29795a8f13
SHA1 : 2cbc607f3f5f008559f31bc251bad3e54280a0b4
Online report : http://virscan.org/report/3cc369849ae13484…0272facd11.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090406020355 2009-04-06 4.29 Trojan.Win32.Agent!IK
AhnLab V3 2009.04.06.02 2009.04.06 2009-04-06 0.87 -
AntiVir 7.9.0.138 7.1.3.15 2009-04-06 1.98 TR/Agent.bxhr
Antiy 2.0.18 20090406.2281954 2009-04-06 0.17 -
Authentium 5.1.1 200904051244 2009-04-05 2.58 -
AVAST! 3.0.1 090405-1 2009-04-05 0.94 -
AVG 7.5.52.442 270.11.42/2042 2009-04-05 2.07 -
BitDefender 7.81008.2828924 7.24642 2009-04-06 2.71 -
CA (VET) 9.0.0.143 31.6.6435 2009-04-04 13.28 -
ClamAV 0.95 9205 2009-04-05 0.15 -
Comodo 3.8 1100 2009-04-05 13.23 -
CP Secure 1.1.0.715 2009.04.06 2009-04-06 8.12 -
Dr.Web 4.44.0.9170 2009.04.06 2009-04-06 4.42 -
F-Prot 4.4.4.56 20090405 2009-04-05 3.15 -
F-Secure 5.51.6100 2009.04.06.03 2009-04-06 0.10 Trojan.Win32.Agent.bxhr [AVP]
Fortinet 2.81-3.117 10.251 2009-04-05 0.42 -
GData 19.4437/19.290 20090406 2009-04-06 4.37 Trojan.Win32.Agent.bxhr [Engine:A]
ViRobot 20090404 2009.04.04 2009-04-04 1.37 -
Ikarus T3.1.01.49 2009.04.06.72531 2009-04-06 2.85 Trojan.Win32.Agent
JiangMin 11.0.706 2009.04.05 2009-04-05 3.08 -
Kaspersky 5.5.10 2009.04.06 2009-04-06 0.07 Trojan.Win32.Agent.bxhr
KingSoft 2009.2.5.15 2009.4.6.14 2009-04-06 2.57 -
McAfee 5.3.00 5575 2009-04-05 2.88 -
Microsoft 1.4502 2009.04.06 2009-04-06 11.57 -
mks_vir 2.01 2009.04.05 2009-04-05 2.91 -
Norman 6.00.06 6.00.00 2009-04-03 10.01 -
Panda 9.05.01 2009.04.05 2009-04-05 5.77 -
Trend Micro 8.700-1004 5.944.02 2009-04-03 0.04 -
Quick Heal 10.00 2009.04.04 2009-04-04 1.41 -
Rising 20.0 21.23.40.00 2009-04-03 1.48 -
Sophos 2.85.0 4.40 2009-04-06 2.13 -
Sunbelt 5078 5078 2009-04-04 0.82 Trojan.Win32.Agent.bxhr
Symantec 1.3.0.24 20090405.003 2009-04-05 0.45 -
nProtect 20090406.01 3423365 2009-04-06 14.54 -
The Hacker [removed] v00302 2009-04-05 2.42 -
VBA32 3.12.10.2 20090405.1443 2009-04-05 2.07 Trojan.Win32.Agent.bxhr
VirusBuster 4.5.11.10 10.102.34/1210107 2009-04-05 1.57 -


I know we're not quite done, but I've started looking into what I need to do to not let this happen again. Apparently I've been doing a lot of things wrong and this whole process has been very informative. Thanks again and cheers to you!

nbake
Hi Nbake,

I'll give you some prevention tips and suggestions when we are done.

Did your antivirus program nab that file C:\WINDOWS\system32\apiqkuasu.dll ? Generally if an antivirus program can find a file, so can OTMOVEIT3.

Let's see if something else is going on with WgaTray.exe


Please download FindAWF and save it to your desktop


* Double-click FindAWF.exe to start the tool.
* Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
* When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here along with a new HJT log.

Thanks
oldman960,

Hope you had a good weekend. I don't know if McAfee found that file. My guess is no. I'm not sure how to find it other than doing a scan.

Here is the AWF report:

Find AWF report by noahdfear ©2006
Version 1.40

The current date is: 2009-04-07
The current time is: 11:13:10.78


bak folders found
~~~~~~~~~~~



Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~



end of report

And the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17, on 2009-04-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 8355 bytes
Hi Nbake,

Use OTMOVEIT3 again with this fix
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Do Not copy the word CODE note the fix starts with the :
:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\system32\WgaTray.exe 


:Commands
[start explorer]
[Reboot]



Next

It's possible the file renamed it's self. Delete the copy of combofix.exe you have from your desktop and download a new copy from Here or Here to your Desktop.


Disable McAfee and run combofix.


Please post back with the OTMOVEIT3 log, combofix log and a new HJT log.

Thanks
Hey oldman960,

Here's the OTMOVEIT3 log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\system32\WgaTray.exe moved successfully.
========== COMMANDS ==========
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04072009_213713

And the combofix log

ComboFix 09-04-04.01 - Nick 2009-04-07 22:38:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.673 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-08 to 2009-04-08 )))))))))))))))))))))))))))))))
.

2009-04-06 01:20 . 2009-04-06 01:20 d——– C:\_OTMoveIt
2009-04-04 13:46 . 2009-04-04 13:46 d——– c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-03 12:04 . 2009-04-03 12:04 d——– c:\documents and settings\Administrator
2009-03-31 12:02 . 2009-04-03 12:00 d——– c:\program files\ERUNT
2009-03-31 12:00 . 2009-03-31 12:00 d——– c:\program files\Trend Micro
2009-03-31 11:36 . 2009-03-31 11:36 d——– c:\documents and settings\Nick\Application Data\Malwarebytes
2009-03-31 11:36 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-31 11:36 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-31 11:35 . 2009-03-31 11:36 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-31 11:35 . 2009-03-31 11:35 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-31 11:28 . 2009-03-31 11:28 d——– c:\program files\iTunes
2009-03-31 11:28 . 2009-03-31 11:28 d——– c:\program files\iPod
2009-03-30 22:10 . 2009-03-30 22:10 d——– c:\windows\Sun
2009-03-29 12:22 . 2009-03-29 12:21 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-29 12:22 . 2009-03-29 12:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-27 11:41 . 2009-03-31 11:26 d——– c:\program files\QuickTime
2009-03-24 13:57 . 2009-03-27 11:41 d——– c:\program files\iTunes(2)
2009-03-24 13:57 . 2009-03-27 11:41 d——– c:\program files\iPod(2)
2009-03-24 13:57 . 2009-03-24 13:58 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-24 13:56 . 2009-03-31 11:27 d——– c:\program files\Bonjour
2009-03-24 13:55 . 2009-03-27 11:41 d——– c:\program files\QuickTime(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-04 19:47 ——— d—–w c:\program files\Project64 1.6
2009-04-04 19:33 ——— d–h–w c:\program files\InstallShield Installation Information
2009-04-04 19:25 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-04 19:24 ——— d—–w c:\documents and settings\Nick\Application Data\Yahoo!
2009-04-04 19:24 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-04-04 19:22 ——— d—–w c:\program files\Yahoo!
2009-04-02 01:27 ——— d—–w c:\documents and settings\Nick\Application Data\U3
2009-03-31 17:24 ——— d—–w c:\program files\Apple Software Update
2009-03-29 18:21 ——— d—–w c:\program files\Java
2009-03-25 02:31 ——— d—–w c:\documents and settings\Nick\Application Data\Apple Computer
2009-03-24 19:57 ——— d—–w c:\program files\Common Files\Apple
2009-02-14 05:22 ——— d—–w c:\documents and settings\All Users\Application Data\Comcast
2009-02-13 04:49 ——— d—–w c:\program files\McAfee
2009-02-12 21:13 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-02-12 21:08 ——— d—–w c:\program files\McAfee.com
2009-02-12 21:08 ——— d—–w c:\program files\Common Files\McAfee
2009-02-11 21:35 ——— d—–w c:\documents and settings\All Users\Application Data\SupportSoft
2009-02-11 21:34 ——— d—–w c:\program files\Common Files\SupportSoft
2009-02-11 21:34 ——— d—–w c:\program files\Comcast
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2007-07-13 17:33 92,064 -c–a-w c:\documents and settings\Nick\mqdmmdm.sys
2007-07-13 17:33 9,232 -c–a-w c:\documents and settings\Nick\mqdmmdfl.sys
2007-07-13 17:33 79,328 -c–a-w c:\documents and settings\Nick\mqdmserd.sys
2007-07-13 17:33 66,656 -c–a-w c:\documents and settings\Nick\mqdmbus.sys
2007-07-13 17:33 6,208 -c–a-w c:\documents and settings\Nick\mqdmcmnt.sys
2007-07-13 17:33 5,936 -c–a-w c:\documents and settings\Nick\mqdmwhnt.sys
2007-07-13 17:33 4,048 -c–a-w c:\documents and settings\Nick\mqdmcr.sys
2007-07-13 17:33 25,600 -c–a-w c:\documents and settings\Nick\usbsermptxp.sys
2007-07-13 17:33 22,768 -c–a-w c:\documents and settings\Nick\usbsermpt.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-04-03_23.41.16.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-04 00:52:07 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-08 03:43:51 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-04-04 00:52:07 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-04-08 03:43:51 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-13 18:45:36 26,112 -c–a-w c:\windows\system32\dllcache\usbser.sys
- 2009-03-29 02:11:34 189,792 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-04-06 15:33:32 189,792 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-04-08 03:38:28 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-29 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-14 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-02 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27696:TCP"= 27696:TCP:BitComet 27696 TCP
"27696:UDP"= 27696:UDP:BitComet 27696 UDP


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66b2c17f-32ff-11dc-96d2-000d87ec1e3d}]
\Shell\AutoRun\command - J:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2279b8c-cd27-11dd-97b0-000d87ec1e3d}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-04-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-05-10 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1200603524.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 20:38]

2009-02-12 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 14:32]

2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 14:32]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\mrhhh9sm.default\
FF - prefs.js: browser.startup.homepage - c:\\Documents and Settings\\Nick\\Desktop\\bookmarks.html
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-07 22:41:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-07 22:42:51
ComboFix-quarantined-files.txt 2009-04-08 04:42:48
ComboFix2.txt 2009-04-04 18:01:34
ComboFix3.txt 2009-04-04 05:42:43

Pre-Run: 223,967,027,200 bytes free
Post-Run: 223,968,518,144 bytes free

169 — E O F — 2009-03-29 00:36:46

And finally the hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:27, on 2009-04-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 8251 bytes

Those viruses and trojans better look out. We're on their trail…

thanks again,

nbake
Hey oldman960, Everything has been acting normal for the last several days. I'm pumped the logs came back good. I guess now I just need to work on keeping it clean. You said you have some advice? I've looked through the forums and the suggestions that were made in the stickied topics, but haven't gone through with a lot of it for fear of screwing up what we've been doing. I might even be able to get my taxes done now! And we still have to discuss the homebrew… Thank you, nbake
Hi Nbake,

Reading the stickies is a sure sign that you are on the road to prevention. I will make some suggestion, you may find other programs that suit your needs better. If you can find a way to attach a jar of something cool and clear……..

Okay we'll clean up our tools

From your desktop, please delete
  • any notepads/logs that we created
  • SystemLook.exe
  • DDS.scr
  • FindAWF.exe

Click the Start button (lower left of your screen), click Run. Copy and paste the following line into the run box and click OK

Combofix /u


Open OTMoveIt3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.

You may also be interested in ATF Cleaner by Atribune. It a temporary folder/cache cleaner that can clean out the nooks and crannies where malware likes to hide.


Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7 first. Be sure to move any PDF documents to another folder first though.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have some of those all ready. You have an antivirus program, an on demand spyware program and a firewall.

I recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :wavey:
Hi oldman960, So I've spent the morning downloading spyware guards and extra protection and I'm a bit overwhelmed. Also, there are a few things on my desktop that I can't identify that I'm hoping to remove, but I wanted to make sure it won't mess up anything else. The list is as follows: validate.exe clean.dat internet.dat names.dat scan.dat packing.lst I assume several of these go together, but I don't remember which download added what. I have installed: ATF cleaner JavaRa SpywareBlaster SpywareGuard Winpatrol And I also have: Malwarebytes Erunt Hijackthis I'm running McAfee because it came free with comcast. I might just delete it and go for AVG. Are there McAfee applications that interfere with my other spyware apps? Also, Zone Alarm is going to drive me nuts, as it is asking me to allow or deny access for something every minute. And it isn't like I know what a process is based on the name anyway. I also added more accounts and am going to try to use a limited account when accessing the internet. Is this necessary? Is there anything special I need to know about the programs I've installed, or do they pretty much run themselves. I can remember to update them, but I'm not really confident working with them yet. Let me know if I'm being too lazy in trying to understand what is going on. In your signature it says that if I liked my service, I could donate to the cause. I guess that's what you would prefer then? Hmm. Now your signature doesn't show up. I wonder if I blocked it with one of these fancy new programs. Oh yeah, and one more thing: you obviously advocate for internet explorer use, but I'm more a fan of mozilla. Do you feel like Mozilla is more vulnerable? I am just much more comfortable with it. Cheers and thank you so much! nbake
Hi Nbake,

I'm not sure what these are for certain, they look like a McAfee update package

validate.exe
clean.dat
internet.dat
names.dat
scan.dat
packing.lst

Right click on them and select properties. There may be more info.

SpywareGuard
Winpatrol

These may conflict with each other, so I suggest keeping only one. No preference. Either one will run at start up.

ATFcleaner -use it every now and then to clear out the caches
JavaRa-used for updating and uninstalling Java. Java was bad for not uninstalling the old versions before installing the new version. I believe starting with version 6 update 10, it will now also uninstall the old java for you. So you can probably get rid of it.
SpywareBlaster-it will block known bad sites/addresses.

Malwarebytes-great on demand scanner. Use it once a week, you never know when some thing might sneak in. The free version will become on demand, which means you will have to manually run the scan.
Erunt-always handy to have a backup of your registry.
Hijackthis-it's a good program to have on your computer should you ever get infected and not be able to download this program. At least you will be able to start a diagnosis process.

I might just delete it and go for AVG.

Your choice, but keep in mind you will loose the Mcafee firewall as uninstalling McAfee usually involves using a tool to make sure it uninstalls properly. Speaking of firewalls, if you decide to keep McAfee there is no need for Zone Alarm. You should have only one firewall installed at a time. Other than that, I don't see anything that will conflict with McAfee.

also added more accounts and am going to try to use a limited account when accessing the internet. Is this necessary?

Malware will inherit the rights of the account that it infects. So the more rights the account has, the more "damage" it can do.

you obviously advocate for internet explorer use

No not really. It's just that you need IE for certain things such as going to the Windows update site and most online scans, so you may as well have it as secure as possible. At this point in time FireFox may be a more secure browser, though that may change as the bug authors start to target it. By all means continue to use FF. Bottom line, keep it updated as you would any program.

Not sure why the signature doesn't show up. Other than the banner, the rest is just text with links. Anyway if that's what you wish to do here a link. http://www.whatthetech.com/donate/

Hope I've answered your questions or at least added to the confusion.
oldman960,

Hope I've answered your questions or at least added to the confusion.

Ha. You've definitely helped AND added a bit of well needed confusion. I feel like I'm much more secure, or if not, at least a bit more knowledgeable in the area. I thank you for that.

My computer seems free and clear so I guess this one is resolved.

Thank you for the great work you do,

nbake
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI