This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] My HijackThis Log

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
I've been having some problems lately and after running some spyware removal tools like AdAware, Spybot, and doing a full system scan with Norton I'm still getting some problems. Lately I've been getting a ton of pop up windows whenever I try to open anything saying Windows/system32/kiramega.dll is not available.
Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:37 PM, on 4/6/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CPMed7773cd] Rundll32.exe "c:\windows\system32\lilomijo.dll",a
O4 - HKLM\..\Run: [sehulehiye] Rundll32.exe "C:\Windows\system32\resevine.dll",s
O4 - HKLM\..\Run: [ee444051] rundll32.exe "C:\Windows\system32\hujinuya.dll",b
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O20 - AppInit_DLLs: c:\windows\system32\lilomijo.dll,C:\Windows\system32\kiramega.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lilomijo.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lilomijo.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c98a0acf968bae) (gupdate1c98a0acf968bae) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 9321 bytes
Hello sled14

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.
It is advisable that you back up your personal data before starting any clean up procedure.



Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O4 - HKLM\..\Run: [CPMed7773cd] Rundll32.exe "c:\windows\system32\lilomijo.dll",a
O4 - HKLM\..\Run: [sehulehiye] Rundll32.exe "C:\Windows\system32\resevine.dll",s
O4 - HKLM\..\Run: [ee444051] rundll32.exe "C:\Windows\system32\hujinuya.dll",b

O20 - AppInit_DLLs: c:\windows\system32\lilomijo.dll,C:\Windows\system32\kiramega.dll

O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lilomijo.dll (file missing)

O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lilomijo.dll (file missing)






Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
I followed your directions and the two logs are below. The popups have stopped but I received an error message after running HijackThis and checking the ones you told me to fix, and they are still on the log. This is what I got:
[external image: Posted Image]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:25 PM, on 4/7/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CPMed7773cd] Rundll32.exe "c:\windows\system32\lilomijo.dll",a
O4 - HKLM\..\Run: [sehulehiye] Rundll32.exe "C:\Windows\system32\resevine.dll",s
O4 - HKLM\..\Run: [ee444051] rundll32.exe "C:\Windows\system32\hujinuya.dll",b
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c98a0acf968bae) (gupdate1c98a0acf968bae) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 8664 bytes




Malwarebytes' Anti-Malware 1.36
Database version: 1948
Windows 6.0.6001 Service Pack 1

4/7/2009 12:38:50 PM
mbam-log-2009-04-07 (12-38-50).txt

Scan type: Quick Scan
Objects scanned: 61047
Time elapsed: 4 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmed7773cd (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sehulehiye (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ee444051 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\dijanumo.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\katowola.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\TKL0Dq18.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
Hi,

The TeaTimer is preventing some of those entries from being removed.

Do this first…Important

Disable the TeaTimer, leave it disabled until we're done or it will prevent fixes from taking

  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Restart your computer.<–You need to do this for it to take effect
Please do not proceed until the TeaTimer is disabled


Then try removing them again.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O4 - HKLM\..\Run: [CPMed7773cd] Rundll32.exe "c:\windows\system32\lilomijo.dll",a
O4 - HKLM\..\Run: [sehulehiye] Rundll32.exe "C:\Windows\system32\resevine.dll",s
O4 - HKLM\..\Run: [ee444051] rundll32.exe "C:\Windows\system32\hujinuya.dll",b







Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Ok I followed your steps and it appears everythings working normally, thanks a lot! I was wondering if you recommend having Ad-Aware and Spy-Bot running in the background along with Norton or is just Norton fine?
sled14,

I need to see the Combofix log, it will show if anything else bad has to be removed.

C:\ComboFix.txt
<–You can find it here
Oh sorry, here it is:

ComboFix 09-04-04.01 - Jon 2009-04-07 15:22:40.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3581.2516 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\kiramega.dll
c:\windows\system32\orokujow.ini

.
((((((((((((((((((((((((( Files Created from 2009-03-07 to 2009-04-07 )))))))))))))))))))))))))))))))
.

2009-04-07 15:27 . 2009-04-07 15:28 353,668,401 –a—— c:\windows\MEMORY.DMP
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\Jon\AppData\Roaming\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\All Users\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\programdata\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-07 12:33 . 2009-04-06 15:32 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-04-07 12:33 . 2009-04-06 15:32 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-04-07 00:19 . 2008-04-17 12:12 107,368 –a—— c:\windows\System32\GEARAspi.dll
2009-04-07 00:19 . 2009-03-19 16:32 23,400 –a—— c:\windows\System32\drivers\GEARAspiWDM.sys
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\program files\iTunes
2009-04-07 00:18 . 2009-04-07 00:18 d——– c:\program files\iPod
2009-04-07 00:16 . 2009-04-07 00:17 d——– c:\program files\QuickTime
2009-04-07 00:08 . 2009-04-07 00:08 d——– c:\program files\Safari
2009-04-07 00:06 . 2009-04-07 00:06 d——– c:\program files\Bonjour
2009-04-06 23:27 . 2009-04-06 23:27 d——– c:\program files\Trend Micro
2009-04-06 23:13 . 2009-04-06 23:13 d——– c:\program files\ERUNT
2009-04-06 22:30 . 2008-06-19 21:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-04-06 22:30 . 2008-06-19 21:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-04-06 22:30 . 2008-06-19 21:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-04-06 22:30 . 2008-06-19 21:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-04-06 22:30 . 2008-06-19 21:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-04-06 22:30 . 2008-06-19 21:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-04-06 22:20 . 2008-07-27 14:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-04-06 22:20 . 2008-07-27 14:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-04-06 22:20 . 2008-07-27 14:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-04-06 22:20 . 2008-07-27 14:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-04-06 22:20 . 2008-07-27 14:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-04-06 00:13 . 2009-04-06 00:13 1,430,456 —hs—- c:\windows\System32\ayunijuh.tmp
2009-03-31 20:03 . 2009-03-31 20:03 d——– c:\program files\Symantec
2009-03-31 20:03 . 2009-03-31 20:05 d——– c:\program files\Common Files\Symantec Shared
2009-03-31 20:03 . 2009-03-31 20:03 124,464 –a—— c:\windows\System32\drivers\SYMEVENT.SYS
2009-03-31 20:03 . 2009-03-31 20:02 25,136 -ra—— c:\windows\System32\drivers\SymIMV.sys
2009-03-31 20:03 . 2009-03-31 20:03 7,386 –a—— c:\windows\System32\drivers\SYMEVENT.CAT
2009-03-31 20:03 . 2009-03-31 20:03 805 –a—— c:\windows\System32\drivers\SYMEVENT.INF
2009-03-31 20:01 . 2009-03-31 20:01 d——– c:\windows\System32\drivers\NIS
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\users\All Users\Symantec
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\programdata\Symantec
2009-03-31 20:01 . 2009-03-31 20:02 d——– c:\program files\Norton Internet Security
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\Norton
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\Norton
2009-03-31 19:53 . 2009-03-31 19:53 d——– c:\program files\NortonInstaller
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\users\All Users\Symantec Temporary Files
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\programdata\Symantec Temporary Files
2009-03-31 18:24 . 2009-02-16 00:10 109,960 –a—— c:\windows\System32\~GLH0028.TMP
2009-03-26 15:23 . 2009-03-26 15:23 1,900,544 –a—— c:\windows\System32\usbaaplrc.dll
2009-03-26 15:23 . 2009-03-26 15:23 36,864 –a—— c:\windows\System32\drivers\usbaapl.sys
2009-03-24 20:25 . 2009-03-24 20:25 131,584 ——— c:\windows\combatfs.exe
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\users\All Users\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\programdata\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\program files\DVD Shrink
2009-03-19 19:41 . 2009-03-19 20:01 d——– c:\program files\DOSBox-0.72
2009-03-19 19:39 . 2009-03-19 19:39 d–h—– c:\windows\PIF
2009-03-19 19:38 . 2009-03-19 19:39 d——– C:\CCUSA
2009-03-17 17:55 . 2009-03-17 17:55 d——– c:\program files\Microsoft Virtual PC
2009-03-14 19:26 . 2009-03-14 19:26 d——– c:\program files\Common Files\Logitech
2009-03-10 17:58 . 2008-12-15 23:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-10 17:58 . 2009-02-08 23:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-10 17:58 . 2008-11-27 00:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-10 17:58 . 2008-12-16 01:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-03-08 23:19 . 2008-02-15 18:24 4,947,968 –a—— c:\windows\System32\stacgui.cpl
2009-03-08 23:19 . 2007-04-10 18:02 1,601,536 –a—— c:\windows\System32\stlang.dll
2009-03-08 23:19 . 2007-09-20 15:31 647,168 –a—— c:\windows\System32\aestecap.dll
2009-03-08 23:19 . 2007-09-20 15:31 131,072 –a—— c:\windows\System32\aestacap.dll
2009-03-08 23:19 . 2008-02-15 18:25 102,400 –a—— c:\windows\System32\stacsv.exe
2009-03-08 23:18 . 2008-02-15 18:25 527,872 –a—— c:\windows\System32\stapo.dll
2009-03-08 23:18 . 2008-02-15 18:27 330,752 –a—— c:\windows\System32\drivers\stwrt.sys
2009-03-08 23:18 . 2008-02-15 18:26 328,704 –a—— c:\windows\System32\stcplx.dll
2009-03-08 23:18 . 2008-02-15 18:23 312,320 –a—— c:\windows\System32\stapi32.dll
2009-03-08 23:18 . 2008-02-15 18:24 150,016 –a—— c:\windows\System32\st325866.dll
2009-03-08 23:13 . 2009-03-10 19:59 d——– c:\users\Jon\AppData\Roaming\dvdcss

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-07 19:12 ——— d—–w c:\programdata\Spybot - Search & Destroy
2009-04-07 16:15 ——— d—–w c:\programdata\Google Updater
2009-04-07 04:18 ——— d—–w c:\program files\Common Files\Apple
2009-03-31 22:26 ——— d—–w c:\program files\AskBarDis
2009-03-29 21:56 27,145 —-a-w c:\users\Jon\AppData\Roaming\nvModes.dat
2009-03-26 16:18 31,693,590 —-a-w c:\windows\Internet Logs\vsmon_on_demand_thread_2009_03_26_00_26_26_full.dmp.zip
2009-03-25 21:06 2,821,617 —-a-w c:\windows\Internet Logs\tvDebug.Zip
2009-03-14 23:26 ——— d—–w c:\program files\Logitech
2009-03-11 22:51 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-11 21:51 ——— d—–w c:\program files\Windows Mail
2009-02-17 23:26 ——— d—–w c:\users\Jon\AppData\Roaming\Apple Computer
2009-02-17 23:25 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-16 04:11 293,528 —-a-w c:\windows\system32\drivers\vsdatant.sys
2009-02-14 02:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-12 17:39 ——— d—–w c:\program files\CCleaner
2009-02-12 16:02 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-12 16:02 15,688 —-a-w c:\windows\System32\lsdelete.exe
2009-02-12 16:02 ——— d—–w c:\programdata\Lavasoft
2009-02-12 16:00 ——— dc-h–w c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-12 16:00 ——— d—–w c:\program files\Lavasoft
2009-02-12 15:58 ——— d—–w c:\program files\Google
2009-02-12 03:49 ——— d—–w c:\program files\SpywareGuard
2009-01-18 23:28 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-01-18 05:56 174 –sha-w c:\program files\desktop.ini
2009-01-18 05:38 82,432 —-a-w c:\windows\System32\axaltocm.dll
2009-01-18 05:38 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2009-01-17 03:00 269,312 —-a-w c:\windows\System32\es.dll
2009-01-16 05:40 61,440 —-a-w c:\windows\System32\winipsec.dll
2009-01-16 05:40 361,984 —-a-w c:\windows\System32\IPSECSVC.DLL
2009-01-16 05:40 28,672 —-a-w c:\windows\System32\FwRemoteSvr.dll
2009-01-16 05:40 272,896 —-a-w c:\windows\System32\polstore.dll
2009-01-16 05:38 94,720 —-a-w c:\windows\System32\PortableDeviceClassExtension.dll
2009-01-16 05:38 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2009-01-16 05:38 160,768 —-a-w c:\windows\System32\PortableDeviceTypes.dll
2009-01-16 05:32 296,960 —-a-w c:\windows\System32\gdi32.dll
2009-01-16 05:30 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2009-01-16 05:30 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2009-01-16 05:30 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-16 05:30 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2009-01-16 05:30 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2009-01-16 05:30 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2009-01-16 05:30 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2009-01-16 05:30 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-16 05:30 1,695,744 —-a-w c:\windows\System32\gameux.dll
2009-01-16 05:29 303,616 —-a-w c:\windows\System32\wmpeffects.dll
2009-01-16 05:28 2,048 —-a-w c:\windows\System32\msxml3r.dll
2009-01-16 05:28 1,191,936 —-a-w c:\windows\System32\msxml3.dll
2009-01-16 05:25 2,048 —-a-w c:\windows\System32\tzres.dll
2009-01-16 05:22 2,927,104 —-a-w c:\windows\explorer.exe
2009-01-16 05:16 988,216 —-a-w c:\windows\System32\winload.exe
2009-01-16 05:16 927,288 —-a-w c:\windows\System32\winresume.exe
2009-01-16 05:16 615,992 —-a-w c:\windows\System32\ci.dll
2009-01-16 05:16 6,656 —-a-w c:\windows\System32\kbd106n.dll
2009-01-16 05:16 46,592 —-a-w c:\windows\System32\setbcdlocale.dll
2009-01-16 05:16 40,960 —-a-w c:\windows\System32\srclient.dll
2009-01-16 05:16 378,368 —-a-w c:\windows\System32\srcore.dll
2009-01-16 05:16 318,464 —-a-w c:\windows\System32\rstrui.exe
2009-01-16 05:16 19,000 —-a-w c:\windows\System32\kd1394.dll
2009-01-16 05:16 14,848 —-a-w c:\windows\System32\srdelayed.exe
2009-01-16 03:32 712,704 —-a-w c:\windows\System32\WindowsCodecs.dll
2009-01-16 03:32 425,472 —-a-w c:\windows\System32\PhotoMetadataHandler.dll
2009-01-16 03:32 347,136 —-a-w c:\windows\System32\WindowsCodecsExt.dll
2009-01-16 03:30 443,392 —-a-w c:\windows\System32\win32spl.dll
2009-01-16 03:30 37,888 —-a-w c:\windows\System32\printcom.dll
2009-01-16 03:30 14,848 —-a-w c:\windows\System32\wshrm.dll
2009-01-16 03:28 996,352 —-a-w c:\windows\System32\WMNetMgr.dll
2009-01-16 03:28 98,816 —-a-w c:\windows\System32\mfps.dll
2009-01-16 03:28 94,720 —-a-w c:\windows\System32\logagent.exe
2009-01-16 03:28 53,248 —-a-w c:\windows\System32\rrinstaller.exe
2009-01-16 03:28 24,576 —-a-w c:\windows\System32\mfpmp.exe
2009-01-16 03:28 2,868,736 —-a-w c:\windows\System32\mf.dll
2009-01-16 03:28 2,048 —-a-w c:\windows\System32\mferror.dll
2009-01-16 03:27 84,480 —-a-w c:\windows\System32\INETRES.dll
2009-01-16 03:27 738,304 —-a-w c:\windows\System32\inetcomm.dll
2009-01-16 03:27 1,645,568 —-a-w c:\windows\System32\connect.dll
2009-01-16 03:26 1,314,816 —-a-w c:\windows\System32\quartz.dll
2009-01-16 03:25 3,601,464 —-a-w c:\windows\System32\ntkrnlpa.exe
2009-01-16 03:25 3,549,240 —-a-w c:\windows\System32\ntoskrnl.exe
2009-01-16 03:24 2,048 —-a-w c:\windows\System32\msxml6r.dll
2009-01-16 03:24 1,334,272 —-a-w c:\windows\System32\msxml6.dll
2009-01-16 02:14 83,456 —-a-w c:\windows\System32\wudriver.dll
2009-01-16 02:14 561,688 —-a-w c:\windows\System32\wuapi.dll
2009-01-16 02:14 51,224 —-a-w c:\windows\System32\wuauclt.exe
2009-01-16 02:14 43,544 —-a-w c:\windows\System32\wups2.dll
2009-01-16 02:14 34,328 —-a-w c:\windows\System32\wups.dll
2009-01-16 02:14 31,232 —-a-w c:\windows\System32\wuapp.exe
2009-01-16 02:14 162,064 —-a-w c:\windows\System32\wuwebv.dll
2009-01-16 02:14 1,809,944 —-a-w c:\windows\System32\wuaueng.dll
2009-01-16 02:14 1,524,736 —-a-w c:\windows\System32\wucltux.dll
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2009-01-13 23:13 244,232 —-a-w c:\windows\System32\WmJoyFrc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-16 18:22 333192 –a—— c:\program files\AskBarDis\bar\bin\askBar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-03-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-08-07 1548288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-18 136600]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-13 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-13 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-13 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-09-13 81920]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-12 509784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]

c:\users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-16 809488]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-09-07 1180952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\kiramega.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{61CC2CBC-37DF-4D5C-99A9-EFB9D38A761F}"= UDP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{4B05BE9C-3469-4ACA-9EEE-7D7EC4CCB0DE}"= TCP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{D984C0F1-BEC5-4FDD-A249-609C481B14F7}"= UDP:c:\windows\explorer.exe:Explorer
"{D6BE0FAF-2C33-44D2-B6D6-4076006AB9FD}"= TCP:c:\windows\explorer.exe:Explorer
"{A7403CB3-3C2C-4EB6-8E65-F3B736A65C7D}"= UDP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{BC667654-2874-4781-8155-C6CEDAF455B2}"= TCP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{5B3D8633-CE16-4164-945E-B2B19068ECCB}"= UDP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{24F27D91-B6D8-4B4E-A221-A1DAB8BCFD75}"= TCP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{3ECE1C9A-5046-4267-AC5D-C4859A24C9F9}"= UDP:c:\windows\System32\winlogon.exe:winlogon
"{0361CFC8-23F3-4281-8C48-6C8C3B2FB61E}"= TCP:c:\windows\System32\winlogon.exe:winlogon
"{A6E2680A-4BAB-4593-B9F2-E74E5B912507}"= UDP:c:\windows\System32\wininit.exe:wininit
"{31A51577-3A75-4040-BE14-C9745D6B1709}"= TCP:c:\windows\System32\wininit.exe:wininit
"{64C09E2B-2963-4CD7-84C9-C2E23FB405F4}"= UDP:c:\windows\System32\dwm.exe:Dwm
"{7F241BD0-946C-488B-83F9-AF0E827F8060}"= TCP:c:\windows\System32\dwm.exe:Dwm
"{EBD600B2-34F0-44F9-99A1-857324C67DE4}"= UDP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{A82A2C39-9090-4027-98F5-C6B1D0A69C82}"= TCP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{2362CD5D-C082-4759-B35E-E85A1BBFAE94}"= UDP:c:\windows\System32\LogonUI.exe:LogonUI
"{2E8ADCBB-ED0C-46A2-8E62-9695E1409F62}"= TCP:c:\windows\System32\LogonUI.exe:LogonUI
"{E844669B-18D6-40DB-8E0D-048F4A649A57}"= UDP:c:\windows\System32\lsass.exe:lsass
"{100239A4-1B4A-4CAB-A910-DED16BBF49A3}"= TCP:c:\windows\System32\lsass.exe:lsass
"{87DBD8CE-4A91-4C8C-8E7F-099B0287E34E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AAF139A8-80EC-4B8C-B4F0-19FCC22ABE7A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BF2B11A-B583-45F6-8340-854C335E3FBC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6CE23A8C-3114-4790-B13D-521EC5B639B8}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-02-12 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1005000.087\SymEFA.sys [2009-03-31 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NIS\1005000.087\BHDrvx86.sys [2009-03-31 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1005000.087\cchpx86.sys [2009-03-31 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSvix86.sys [2009-04-02 292912]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2009-01-15 73728]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-01-16 464264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [2009-03-31 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-02-13 1153368]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-31 101936]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2007-03-05 7424]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NIS\1005000.087\symndisv.sys [2009-03-31 39984]
S2 gupdate1c98a0acf968bae;Google Update Service (gupdate1c98a0acf968bae);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-12 12:01]

2009-04-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 20:37]

2009-04-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 12:32]

2009-03-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3952132311-1714827031-4215795686-1000.job
- c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-16 19:39]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
MSConfigStartUp-systeminit - c:\users\Jon\AppData\Local\Temp\systeminit.exe


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\nojrflrp.default\
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\users\Jon\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-07 15:29:18
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4172)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\users\Jon\AppData\Local\Temp\catchme.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\combofix\hidec.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\combofix\Catchme.tmp
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-04-07 15:37:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-07 19:35:41

Pre-Run: 265,294,508,032 bytes free
Post-Run: 265,375,649,792 bytes free

391 — E O F — 2009-04-07 02:37:42
Sled

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.
Where not on the same page, I need a new HJT log also
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:26 PM, on 4/7/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\CF832.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\Explorer.exe
C:\ComboFix\handle.cfexe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c98a0acf968bae) (gupdate1c98a0acf968bae) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 7326 bytes
You may need to disable SpywareGuard for this fix to take. When your back to normal, if you keep the TeaTimer in Spybot enabled, then keep SG disabled as they both do the same thing.

  • Double click on the Red SG Icon in your system tray.
  • Go to Options and remove the Three security checkmarks.
  • OK your way out of the program



You have a dangerous file hooked into your logon.


Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
c:\windows\system32\kiramega.dll

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Hi Starting up my computer today I received a Windows Boot Manager "windows failed to start" saying the NLS data is missing, or corrupt. It just goes to that screen and gives a couple options to start in safe mode or normally. None of these options do anything other than takeme back to the first screen. Any tips on what I can try?
Try This

  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Last Known Good
  • Then press the Enter Key on your Keyboard



Do you have your Vista CD or a re installation CD
Hi
I was able to get the normal Windows startup screen and did the repair option after booting to the Windows disc. It wouldn't start about a month or two ago and I had to do the repair option then. I ran ComboFix using the notepad file. It went through the process, then when it restarted it gave me the same startup error as before, so I booted again from the disc and repaired. In Windows, made sure Norton, AdAware and Spybot were all off and ran ComboFix again with the notepad file, this time it rebooted fine. The two logs are below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:33:44 PM, on 4/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c98a0acf968bae) (gupdate1c98a0acf968bae) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 7215 bytes





ComboFix 09-04-04.01 - Jon 2009-04-08 18:20:00.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3581.2604 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jon\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\kiramega.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\kiramega.dll
c:\windows\system32\orokujow.ini
.
—- Previous Run ——-
.
c:\windows\system32\kiramega.dll
c:\windows\system32\orokujow.ini

.
((((((((((((((((((((((((( Files Created from 2009-03-08 to 2009-04-08 )))))))))))))))))))))))))))))))
.

2009-04-08 17:44 . 2009-04-08 17:45 327,802,161 –a—— c:\windows\MEMORY.DMP
2009-04-08 17:14 . 2009-04-08 17:35 d——– C:\ComboFix(0)
2009-04-08 17:01 . 2009-04-08 17:01 dr——- c:\program files\Norton Support
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\Jon\AppData\Roaming\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\All Users\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\programdata\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-07 12:33 . 2009-04-06 15:32 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-04-07 12:33 . 2009-04-06 15:32 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-04-07 00:19 . 2008-04-17 12:12 107,368 –a—— c:\windows\System32\GEARAspi.dll
2009-04-07 00:19 . 2009-03-19 16:32 23,400 –a—— c:\windows\System32\drivers\GEARAspiWDM.sys
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\program files\iTunes
2009-04-07 00:18 . 2009-04-07 00:18 d——– c:\program files\iPod
2009-04-07 00:16 . 2009-04-07 00:17 d——– c:\program files\QuickTime
2009-04-07 00:08 . 2009-04-07 00:08 d——– c:\program files\Safari
2009-04-07 00:06 . 2009-04-07 00:06 d——– c:\program files\Bonjour
2009-04-06 23:27 . 2009-04-06 23:27 d——– c:\program files\Trend Micro
2009-04-06 23:13 . 2009-04-06 23:13 d——– c:\program files\ERUNT
2009-04-06 22:30 . 2008-06-19 21:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-04-06 22:30 . 2008-06-19 21:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-04-06 22:30 . 2008-06-19 21:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-04-06 22:30 . 2008-06-19 21:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-04-06 22:30 . 2008-06-19 21:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-04-06 22:30 . 2008-06-19 21:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-04-06 22:20 . 2008-07-27 14:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-04-06 22:20 . 2008-07-27 14:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-04-06 22:20 . 2008-07-27 14:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-04-06 22:20 . 2008-07-27 14:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-04-06 22:20 . 2008-07-27 14:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-04-06 00:13 . 2009-04-06 00:13 1,430,456 —hs—- c:\windows\System32\ayunijuh.tmp
2009-03-31 20:03 . 2009-03-31 20:03 d——– c:\program files\Symantec
2009-03-31 20:03 . 2009-03-31 20:05 d——– c:\program files\Common Files\Symantec Shared
2009-03-31 20:03 . 2009-03-31 20:03 124,464 –a—— c:\windows\System32\drivers\SYMEVENT.SYS
2009-03-31 20:03 . 2009-03-31 20:02 25,136 -ra—— c:\windows\System32\drivers\SymIMV.sys
2009-03-31 20:03 . 2009-03-31 20:03 7,386 –a—— c:\windows\System32\drivers\SYMEVENT.CAT
2009-03-31 20:03 . 2009-03-31 20:03 805 –a—— c:\windows\System32\drivers\SYMEVENT.INF
2009-03-31 20:01 . 2009-03-31 20:01 d——– c:\windows\System32\drivers\NIS
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\users\All Users\Symantec
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\programdata\Symantec
2009-03-31 20:01 . 2009-03-31 20:02 d——– c:\program files\Norton Internet Security
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\Norton
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\Norton
2009-03-31 19:53 . 2009-03-31 19:53 d——– c:\program files\NortonInstaller
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\users\All Users\Symantec Temporary Files
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\programdata\Symantec Temporary Files
2009-03-31 18:24 . 2009-02-16 00:10 109,960 –a—— c:\windows\System32\~GLH0028.TMP
2009-03-26 15:23 . 2009-03-26 15:23 1,900,544 –a—— c:\windows\System32\usbaaplrc.dll
2009-03-26 15:23 . 2009-03-26 15:23 36,864 –a—— c:\windows\System32\drivers\usbaapl.sys
2009-03-24 20:25 . 2009-03-24 20:25 131,584 ——— c:\windows\combatfs.exe
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\users\All Users\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\programdata\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\program files\DVD Shrink
2009-03-19 19:41 . 2009-03-19 20:01 d——– c:\program files\DOSBox-0.72
2009-03-19 19:39 . 2009-03-19 19:39 d–h—– c:\windows\PIF
2009-03-19 19:38 . 2009-03-19 19:39 d——– C:\CCUSA
2009-03-17 17:55 . 2009-03-17 17:55 d——– c:\program files\Microsoft Virtual PC
2009-03-14 19:26 . 2009-03-14 19:26 d——– c:\program files\Common Files\Logitech
2009-03-10 17:58 . 2008-12-15 23:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-10 17:58 . 2009-02-08 23:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-10 17:58 . 2008-11-27 00:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-10 17:58 . 2008-12-16 01:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-03-08 23:19 . 2008-02-15 18:24 4,947,968 –a—— c:\windows\System32\stacgui.cpl
2009-03-08 23:19 . 2007-04-10 18:02 1,601,536 –a—— c:\windows\System32\stlang.dll
2009-03-08 23:19 . 2007-09-20 15:31 647,168 –a—— c:\windows\System32\aestecap.dll
2009-03-08 23:19 . 2007-09-20 15:31 131,072 –a—— c:\windows\System32\aestacap.dll
2009-03-08 23:19 . 2008-02-15 18:25 102,400 –a—— c:\windows\System32\stacsv.exe
2009-03-08 23:18 . 2008-02-15 18:25 527,872 –a—— c:\windows\System32\stapo.dll
2009-03-08 23:18 . 2008-02-15 18:27 330,752 –a—— c:\windows\System32\drivers\stwrt.sys
2009-03-08 23:18 . 2008-02-15 18:26 328,704 –a—— c:\windows\System32\stcplx.dll
2009-03-08 23:18 . 2008-02-15 18:23 312,320 –a—— c:\windows\System32\stapi32.dll
2009-03-08 23:18 . 2008-02-15 18:24 150,016 –a—— c:\windows\System32\st325866.dll
2009-03-08 23:13 . 2009-03-10 19:59 d——– c:\users\Jon\AppData\Roaming\dvdcss

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 01:43 ——— d—–w c:\program files\SpywareGuard
2009-04-08 21:47 ——— d—–w c:\programdata\Google Updater
2009-04-07 19:12 ——— d—–w c:\programdata\Spybot - Search & Destroy
2009-04-07 04:18 ——— d—–w c:\program files\Common Files\Apple
2009-03-31 22:26 ——— d—–w c:\program files\AskBarDis
2009-03-29 21:56 27,145 —-a-w c:\users\Jon\AppData\Roaming\nvModes.dat
2009-03-14 23:26 ——— d—–w c:\program files\Logitech
2009-03-11 22:51 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-11 21:51 ——— d—–w c:\program files\Windows Mail
2009-02-17 23:26 ——— d—–w c:\users\Jon\AppData\Roaming\Apple Computer
2009-02-17 23:25 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-16 04:11 293,528 —-a-w c:\windows\system32\drivers\vsdatant.sys
2009-02-14 02:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-12 17:39 ——— d—–w c:\program files\CCleaner
2009-02-12 16:02 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-12 16:02 ——— d—–w c:\programdata\Lavasoft
2009-02-12 16:00 ——— dc-h–w c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-12 16:00 ——— d—–w c:\program files\Lavasoft
2009-02-12 15:58 ——— d—–w c:\program files\Google
2009-01-18 05:56 174 –sha-w c:\program files\desktop.ini
2009-01-16 05:30 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2009-01-16 05:30 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2009-01-16 05:30 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-16 05:30 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2009-01-16 05:30 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2009-01-16 05:30 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-16 05:22 2,927,104 —-a-w c:\windows\explorer.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-16 18:22 333192 –a—— c:\program files\AskBarDis\bar\bin\askBar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-03-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-08-07 1548288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-18 136600]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-13 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-13 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-13 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-09-13 81920]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-12 509784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [BU]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]

c:\users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-16 809488]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-09-07 1180952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\systeminit.exe]
c:\users\Jon\AppData\Local\Temp\systeminit.exe [BU]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{61CC2CBC-37DF-4D5C-99A9-EFB9D38A761F}"= UDP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{4B05BE9C-3469-4ACA-9EEE-7D7EC4CCB0DE}"= TCP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{D984C0F1-BEC5-4FDD-A249-609C481B14F7}"= UDP:c:\windows\explorer.exe:Explorer
"{D6BE0FAF-2C33-44D2-B6D6-4076006AB9FD}"= TCP:c:\windows\explorer.exe:Explorer
"{A7403CB3-3C2C-4EB6-8E65-F3B736A65C7D}"= UDP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{BC667654-2874-4781-8155-C6CEDAF455B2}"= TCP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{5B3D8633-CE16-4164-945E-B2B19068ECCB}"= UDP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{24F27D91-B6D8-4B4E-A221-A1DAB8BCFD75}"= TCP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{3ECE1C9A-5046-4267-AC5D-C4859A24C9F9}"= UDP:c:\windows\System32\winlogon.exe:winlogon
"{0361CFC8-23F3-4281-8C48-6C8C3B2FB61E}"= TCP:c:\windows\System32\winlogon.exe:winlogon
"{A6E2680A-4BAB-4593-B9F2-E74E5B912507}"= UDP:c:\windows\System32\wininit.exe:wininit
"{31A51577-3A75-4040-BE14-C9745D6B1709}"= TCP:c:\windows\System32\wininit.exe:wininit
"{64C09E2B-2963-4CD7-84C9-C2E23FB405F4}"= UDP:c:\windows\System32\dwm.exe:Dwm
"{7F241BD0-946C-488B-83F9-AF0E827F8060}"= TCP:c:\windows\System32\dwm.exe:Dwm
"{EBD600B2-34F0-44F9-99A1-857324C67DE4}"= UDP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{A82A2C39-9090-4027-98F5-C6B1D0A69C82}"= TCP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{2362CD5D-C082-4759-B35E-E85A1BBFAE94}"= UDP:c:\windows\System32\LogonUI.exe:LogonUI
"{2E8ADCBB-ED0C-46A2-8E62-9695E1409F62}"= TCP:c:\windows\System32\LogonUI.exe:LogonUI
"{E844669B-18D6-40DB-8E0D-048F4A649A57}"= UDP:c:\windows\System32\lsass.exe:lsass
"{100239A4-1B4A-4CAB-A910-DED16BBF49A3}"= TCP:c:\windows\System32\lsass.exe:lsass
"{87DBD8CE-4A91-4C8C-8E7F-099B0287E34E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AAF139A8-80EC-4B8C-B4F0-19FCC22ABE7A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BF2B11A-B583-45F6-8340-854C335E3FBC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6CE23A8C-3114-4790-B13D-521EC5B639B8}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-02-12 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1005000.087\SymEFA.sys [2009-03-31 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NIS\1005000.087\BHDrvx86.sys [2009-03-31 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1005000.087\cchpx86.sys [2009-03-31 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSvix86.sys [2009-04-02 292912]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2009-01-15 73728]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-01-16 464264]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [2009-03-31 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-02-13 1153368]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2007-03-05 7424]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NIS\1005000.087\symndisv.sys [2009-03-31 39984]
S2 gupdate1c98a0acf968bae;Google Update Service (gupdate1c98a0acf968bae);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-31 101936]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-12 12:01]

2009-04-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 20:37]

2009-04-08 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 12:32]

2009-03-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3952132311-1714827031-4215795686-1000.job
- c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-16 19:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\nojrflrp.default\
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 18:26:47
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

[0] 0x79746E61

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3880)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\rundll32.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\Java\jre6\bin\jucheck.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-04-08 18:31:56 - machine was rebooted [Jon]
ComboFix-quarantined-files.txt 2009-04-08 22:31:53
ComboFix2.txt 2009-04-08 02:02:34
ComboFix3.txt 2009-04-07 19:37:06

Pre-Run: 262,024,949,760 bytes free
Post-Run: 262,589,263,872 bytes free

291 — E O F — 2009-04-07 02:37:42
Hi, Glad you back up and running, you may have some windows issues on this system if this has happened before. I am still looking at some bad entries on your Combofix log, give me sometime to go over it. Be back in a bit
Hi,

One bad entry to remove.

Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
c:\users\Jon\AppData\Local\Temp\systeminit.exe 

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\systeminit.exe]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI