This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer unusually slow. Log showed trojans. Please he

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has become unusually slow recently.

SuperAS log showed trojans. AVG also found some trojans some days ago
but is not showing anything right now.

I attach related logs.
Please help. Thanks in advance.

HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:23 AM, on 16/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Trellian &Toolbar - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 10299 bytes
==
MBAM log
Malwarebytes' Anti-Malware 1.36
Database version: 1967
Windows 5.1.2600 Service Pack 3

15/04/2009 7:31:42 PM
mbam-log-2009-04-15 (19-31-42).txt

Scan type: Quick Scan
Objects scanned: 85522
Time elapsed: 4 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
==
SuperAS log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/16/2009 at 02:09 AM

Application Version : 4.25.1012

Core Rules Database Version : 3846
Trace Rules Database Version: 1801

Scan type : Complete Scan
Total Scan Time : 02:43:21

Memory items scanned : 631
Memory threats detected : 0
Registry items scanned : 7534
Registry threats detected : 12
File items scanned : 226123
File threats detected : 3

Trojan.DNSChanger-Codec
HKLM\Software\1
HKLM\Software\1#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\1#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\1#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\8
HKLM\Software\8#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\8#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\8#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\9
HKLM\Software\9#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\9#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\9#31C2E1E4D78E6A11B88DFA803456A1FFA5

Adware.Tracking Cookie
.apmebf.com [ C:\Documents and Settings\karolinka\Application Data\Mozilla\Firefox\Profiles\pnl5om15.default\cookies.txt ]
.sixapart.adbureau.net [ C:\Documents and Settings\karolinka\Application Data\Mozilla\Firefox\Profiles\pnl5om15.default\cookies.txt ]
adserver.adreactor.com [ C:\Documents and Settings\karolinka\Application Data\Mozilla\Firefox\Profiles\pnl5om15.default\cookies.txt ]
==
Rooter
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.80GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : HP_Administrator ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.5 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)

C:\ (Local Disk) - NTFS - Total:224 Go (Free:104 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)

16/04/2009|11:01

———————-\\ Search..

———————-\\ Cracks & Keygens..

C:\DOCUME~1\HP_ADM~1\Desktop\Articles\MegaPLR\PLR ARTICLE PACKS\PLR ARTICLE PACK - PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\SSBuilderProKeyGen.exe
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\frmMain.frm
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\frmMain.frx
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\SSBuilderProKeyGen.vbp
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\SSBuilderProKeyGen.vbw
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\clsRegistration.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\clsRijndael.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\CSHA256.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Form1.frm
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Form1.frx
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Keygenerator.exe
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\modBranding.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\modRegistration.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Module1.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Modulecrypt.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Project1.vbp
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Project1.vbw
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\UserControl1.ctl
C:\DOCUME~1\HP_ADM~1\Desktop\FOPStore\fmw_pc_security_website\PC Security - Protect Your Computer System\PC Security - Protect Your Computer System\Department-of-Defense-Crackdown.htm
C:\DOCUME~1\HP_ADM~1\Desktop\GURUS\Cody400\adsense49content\familylife\family life\Cracks-In-A-Family-Unit.txt
C:\DOCUME~1\HP_ADM~1\Desktop\GURUS\Cody400\adsense49content\familylife\sites\cracks.html
C:\DOCUME~1\HP_ADM~1\Desktop\JV\GIVEWAYS\ycbt-freever\MegaPLR\PLR ARTICLE PACKS\PLR ARTICLE PACK - PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc
C:\DOCUME~1\HP_ADM~1\Desktop\PLR2USE\9000PLRarticles\9000PLRArticles\9000PLRArticles\PLRArticles\Marketing PLR\PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc


1 - "C:\Rooter$\Rooter_1.txt" - 16/04/2009|11:04

———————-\\ Scan completed at 11:04

Thnaks again and best regards.

pumex
Hi,

Please post a fresh HJT log if you still require assistance as well post logs from the following:


1. Download MGADiag to your desktop.
Double-click on MGADiag.exe to launch the program
Click "Continue"
Ensure that the "Windows" tab is selected (it should be by default).
Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
Paste the MGA Diagnostic Report back here in your next reply.

2. Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.
Here are the logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:25 PM, on 20/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Trellian &Toolbar - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 10611 bytes


==
Diagnostic Report (1.9.0006.1):
—————————————–
WGA Data–>
Validation Status: Genuine
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-9TCCK-JPCBM-B2FQ8
Windows Product Key Hash: B/IohRcCzV6LJrex8WpCdnxgTvg=
Windows Product ID: 76487-OEM-2211906-00803
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.3.0.med
ID: {4B9A54EA-CD8C-4545-A006-075551DAA0A9}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: 0
File Exists: Yes
Version: 1.7.18.5
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {4B9A54EA-CD8C-4545-A006-075551DAA0A9}1.9.0006.15.1.2600.2.00010100.3.0.medx32*****-*****-*****-*****-B2FQ876487-OEM-2211906-008032S-1-5-21-4145149802-1176095902-786414141HP Pavilion 061ER904AA-ABA A1440NPhoenix Technologies, LTD 3.1520060623000000.000000+000HP PAVILIONE2103EA701847B7C10090409Pacific Standard Time(GMT-08:00)02Hewlett-Packard CompanyHP Pavilion100

Licensing Data–>
N/A

HWID Data–>
N/A

OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 1E0D3:Compaq Computer Corporation|1E0D3:Compaq Computer Corporation|1E0D3:Hewlett-Packard Company|1005F:Hewlett-Packard Company
Marker string from OEMBIOS.DAT: HP PAVILION

OEM Activation 2.0 Data–>
N/A
==
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.80GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : HP_Administrator ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.5 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)

C:\ (Local Disk) - NTFS - Total:224 Go (Free:104 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)

20/04/2009|12:28

———————-\\ Search..

———————-\\ Cracks & Keygens..

C:\DOCUME~1\HP_ADM~1\Desktop\Articles\Articles-Plus\300PLRArticlePack\PLR ARTICLE PACKS\PLR ARTICLE PACK - PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc
C:\DOCUME~1\HP_ADM~1\Desktop\Articles\MegaPLR\PLR ARTICLE PACKS\PLR ARTICLE PACK - PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\SSBuilderProKeyGen.exe
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\frmMain.frm
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\frmMain.frx
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\SSBuilderProKeyGen.vbp
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\keygenerator\SSBuilderProKeyGen.vbw
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\clsRegistration.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\clsRijndael.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\CSHA256.cls
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Form1.frm
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Form1.frx
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Keygenerator.exe
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\modBranding.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\modRegistration.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Module1.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Modulecrypt.bas
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Project1.vbp
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\Project1.vbw
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\shareware\SharewareCreator\product\Simple Shareware Creator Source Code\Keygenerator\UserControl1.ctl
C:\DOCUME~1\HP_ADM~1\Desktop\FOPStore\fmw_pc_security_website\PC Security - Protect Your Computer System\PC Security - Protect Your Computer System\Department-of-Defense-Crackdown.htm
C:\DOCUME~1\HP_ADM~1\Desktop\GURUS\Cody400\adsense49content\familylife\family life\Cracks-In-A-Family-Unit.txt
C:\DOCUME~1\HP_ADM~1\Desktop\GURUS\Cody400\adsense49content\familylife\sites\cracks.html
C:\DOCUME~1\HP_ADM~1\Desktop\JV\GIVEWAYS\ycbt-freever\MegaPLR\PLR ARTICLE PACKS\PLR ARTICLE PACK - PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc
C:\DOCUME~1\HP_ADM~1\Desktop\PLR2USE\9000PLRarticles\9000PLRArticles\9000PLRArticles\PLRArticles\Marketing PLR\PC SECURITY 25\Department of Defense Crackdown on Secuity - 2006.doc


1 - "C:\Rooter$\Rooter_1.txt" - 16/04/2009|11:04
2 - "C:\Rooter$\Rooter_2.txt" - 20/04/2009|12:30

———————-\\ Scan completed at 12:30

Thanks in advance

pumex
Hi,

Please do the following

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
O3 - Toolbar: Trellian &Toolbar - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT


Please advise about this program and it's usage?

C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\SSBuilderProKeyGen.ex

NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Re:
C:\DOCUME~1\HP_ADM~1\Desktop\BUYS\MIPLRPPACK\screensaver\screensavermakerpro\SSBuilderProKeyGen.ex

I bought the MIPLRPACK some months ago. I unzipped that pack, but never used anything from it.

After the combofix computer works ok - nothing suspicious, although I can't say yet if it's faster or not.

Enclosed please find the log:

ComboFix 09-04-21.03 - HP_Administrator 20/04/2009 13:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1323 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Services
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\drivers\atmapi.sys
c:\windows\system32\drivers\RKHit.sys
c:\windows\system32\ntnet.drv
c:\windows\system32\skinboxer43.dll
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-03-20 to 2009-04-20 )))))))))))))))))))))))))))))))
.

2009-04-20 19:45 . 2009-04-20 19:45 ——– d—–w C:\_OTMoveIt
2009-04-20 19:24 . 2009-04-20 19:24 ——– d—–w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-20 04:27 . 2009-04-20 04:27 ——– d—–w C:\rsit
2009-04-19 01:08 . 2009-04-19 01:36 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\FullTiltPoker
2009-04-19 01:07 . 2009-04-19 01:36 ——– d—–w c:\program files\Full Tilt Poker
2009-04-18 06:18 . 2009-04-18 06:23 ——– d—–w c:\program files\EsetOnlineScanner
2009-04-16 18:01 . 2009-04-20 19:30 ——– d—–w C:\Rooter$
2009-04-16 01:53 . 2009-04-16 01:54 ——– d—–w c:\program files\ERUNT
2009-04-05 08:09 . 2009-04-05 08:09 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\{38962301-708A-4293-A228-0564C1121181}
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\1.0.0.0
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\program files\Wincorp Consulting Company
2009-04-03 00:03 . 2009-04-03 00:04 ——– d—–w c:\program files\MetaTrader 4 Client Terminal
2009-03-27 00:27 . 2009-03-27 00:27 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AVG8
2009-03-22 02:30 . 2009-03-22 02:33 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\Desktop Budget
2009-03-22 02:26 . 2009-03-22 02:27 ——– d—–w c:\program files\CBE
2009-03-22 00:49 . 2009-04-02 22:57 ——– d—–w c:\program files\FXCM Trader 4

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 20:11 . 2006-04-06 22:54 ——– d—–w c:\program files\Mozilla Thunderbird
2009-04-20 19:30 . 2009-04-16 18:04 4478 —-a-w C:\Rooter.txt
2009-04-20 09:31 . 2006-04-07 02:51 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-19 01:07 . 2006-02-13 18:05 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2009-04-16 02:32 . 2008-11-30 02:34 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-11 20:16 . 2008-12-08 03:57 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-08 17:34 . 2008-06-06 03:08 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-08 13:05 . 2006-07-14 21:05 ——– d—–w c:\program files\Opera
2009-04-06 22:32 . 2008-12-08 03:57 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 22:32 . 2008-12-08 03:57 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-02 23:04 . 2008-02-19 01:26 ——– d—–w c:\program files\iTunes
2009-04-02 23:03 . 2006-08-15 21:50 ——– d—–w c:\program files\MetaTrader 4
2009-03-31 19:31 . 2006-02-13 18:45 ——– d—–w c:\program files\Google
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–w c:\documents and settings\All Users\Application Data\Skype
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–r c:\program files\Skype
2009-03-30 15:41 . 2008-06-06 03:08 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-27 01:02 . 2006-04-03 23:07 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AdobeUM
2009-03-27 00:52 . 2008-06-06 03:08 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-27 00:52 . 2008-06-06 03:08 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-03-16 05:04 . 2006-07-31 01:00 ——– d—–w c:\program files\CandleWorks
2009-03-07 18:11 . 2009-03-07 18:11 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\iLike
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\TweetDeck
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-02-24 03:45 . 2009-02-24 03:17 20 —h–w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-02-24 03:26 . 2009-02-24 03:26 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\Nikon
2009-02-24 03:26 . 2009-02-24 03:18 ——– d—–w c:\program files\Common Files\Nikon
2009-02-24 03:18 . 2009-02-24 03:18 ——– d—–w c:\documents and settings\All Users\Application Data\Nikon
2009-02-24 03:18 . 2009-02-24 03:18 ——– d—–w c:\program files\Nikon
2009-02-24 03:17 . 2009-02-24 03:17 ——– d—–w c:\documents and settings\All Users\Application Data\Ultima_T15
2009-02-24 03:17 . 2009-02-24 03:17 ——– d—–w c:\documents and settings\All Users\Application Data\EnterNHelp
2009-02-24 03:17 . 2003-03-19 03:05 106496 —-a-w c:\windows\system32\ATL71.DLL
2009-02-24 03:15 . 2009-02-24 03:15 ——– d—–w c:\program files\ArcSoft
2009-02-09 11:13 . 2008-10-15 09:33 1846784 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-09 21:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 06:40 . 2009-02-06 06:40 196 —ha-w C:\aaw7boot.cmd
2009-02-02 02:32 . 2006-02-13 18:21 229224 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-01-24 03:07 . 2006-02-13 18:40 118492307 —-a-w C:\hpWebHelper.log
2008-10-17 01:36 . 2008-10-17 01:36 365040 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-09-28 22:15 . 2008-09-28 22:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-02-06 03:15 . 2006-04-07 23:21 198512 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-11-15 03:13 . 2006-07-15 06:32 14 —-a-w c:\documents and settings\HP_Administrator\getfile.dat
2006-10-11 01:05 . 2006-10-11 01:05 368 —-a-w c:\documents and settings\HP_Administrator\DesktopLightningUpgrader.bat
2006-09-22 04:16 . 2006-09-22 01:15 14 —-a-w c:\documents and settings\karolinka\getfile.dat
2006-04-15 17:32 . 2006-04-07 23:21 132 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\fusioncache.dat
2006-04-06 20:05 . 2006-04-06 20:05 0 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2006-03-30 23:49 . 2006-03-30 22:45 139 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
2006-02-13 18:37 . 2006-03-30 22:45 51976 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-02-13 18:37 . 2006-03-30 22:44 51976 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-02-13 17:49 . 2006-03-30 22:44 136 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2006-02-13 17:49 . 2006-02-13 17:49 136 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2006-05-04 22:2006-05-04 22:53 53:17 . c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-24 20:2008-10-24 20:20 14:52 . c:\program files\opera\program\plugins\dapop.dll
2008-06-05 00:2008-06-05 00:55 55:16 . c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-09-23 04:12 . 2008-09-23 04:12 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
.
file copied: c:\windows\system32\user32.dll -> c:\qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir ( 578560 bytes )
Infected c:\windows\system32\user32.dll hex repaired


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-27 1932568]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-06-05 29744]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-24 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-7-28 368640]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-27 00:52 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=c:\windows\pss\Updates From HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Pml Driver HPZ12"=0 (0x0)
"NVSvc"=2 (0x2)
"nmservice"=2 (0x2)
"nmraapache"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=2 (0x2)
"FinePrint Dispatcher v5"=2 (0x2)
"ELService"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R2 gupdate1c8e254e49c1a68;Google Update Service (gupdate1c8e254e49c1a68);c:\program files\Google\Update\GoogleUpdate.exe [2008-09-02 133104]
R3 GoogleDesktopManager-051608-133132;Google Desktop Manager 5.7.805.16405;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-06-05 29744]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-27 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-30 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-27 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-27 298264]
S2 FinePrint Dispatcher v5;FinePrint Dispatcher v5;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe [2008-04-09 520192]
S2 FinePrint Dispatcher v6;FinePrint Dispatcher v6;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe [2008-10-28 602112]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfe55943-04f2-11dc-bedf-0015f2d56872}]
\Shell\AutoRun\command - K:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]

2009-04-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-24 05:50]

2009-04-20 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-12 18:59]

2009-02-26 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2005-10-17 10:04]

2009-04-15 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-24 02:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.speedbit.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.msn.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Customize Menu
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Fill Forms
IE: RoboForm Toolbar
IE: Save Forms
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2103525&SearchSource;=3&q;=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{32be036a-4d7a-44e7-827d-4cb5b3da428f}\components\FFAlert.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{db7a1b0e-2c9e-4ad3-a2fd-21907ef2c9d1}\components\FFAlert.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\[removed]\components\gps.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.10.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-20 13:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(792)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2976)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-20 13:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-20 20:48

Pre-Run: 111,694,405,632 bytes free
Post-Run: 111,588,339,712 bytes free

307 — E O F — 2009-03-15 10:03
==
I hope I did everything OK, although I noticed that when the combofix was rebooting the computer SuperAntispyware started - should I have disabled it - like I did with the AVG AV??

Thanks again.

pumex
Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • c:\qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Do the same for this file: c:\windows\system32\user32.dll


NEXT




Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Kaspersky report: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, April 21, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, April 21, 2009 13:57:35 Records in database: 2066193 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics: Files scanned: 248107 Threat name: 8 Infected objects: 22 Suspicious objects: 7 Duration of the scan: 05:24:46 File name / Threat name / Threats count C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox Infected: Trojan-Clicker.HTML.Agent.ag 1 C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox.sbd\20062008 Deals Suspicious: Trojan-Spy.HTML.Fraud.gen 3 C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox.sbd\GAMBLING.sbd\AAPoker Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\SentOld Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Trash Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\HP_Administrator\Desktop\Articles\700Articles\msm.zip Infected: Trojan-Clicker.HTML.IFrame.aer 4 C:\Documents and Settings\HP_Administrator\Desktop\BUYS\England\ForumMkt.zip Infected: Trojan.Win32.KillWin.em 1 C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\MembershipSiteManager-Rights.zip Infected: Trojan-Clicker.HTML.IFrame.aer 2 C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\membership_manager.rar Infected: Trojan-Clicker.HTML.IFrame.aer 1 C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\SuperForumMarketing.zip Infected: Trojan.Win32.KillWin.em 1 C:\Documents and Settings\HP_Administrator\Desktop\Goodies\ezmembershipsystem.zip Infected: Trojan-Clicker.HTML.IFrame.aer 1 C:\Documents and Settings\HP_Administrator\Desktop\Goodies\FREERemoteControlPC.rar Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 2 C:\Documents and Settings\HP_Administrator\Desktop\Goodies\FREERemoteControlPC.rar Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 1 C:\Documents and Settings\HP_Administrator\Desktop\JV\GIVEWAYS\MEMB\MembershipSiteManager-Rights.zip Infected: Trojan-Clicker.HTML.IFrame.aer 2 C:\Documents and Settings\HP_Administrator\My Documents\TransfersfromoldPC\Ethicash\membership_manager.rar Infected: Trojan-Clicker.HTML.IFrame.aer 1 C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs Infected: Hoax.JS.BadJoke.RJump 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir Infected: Trojan.Win32.Patched.dr 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\_user32_.dll.zip Infected: Trojan.Win32.Patched.dr 1 C:\WINDOWS\system32\bjzrozi Infected: Trojan.Win32.Patched.dr 1 C:\WINDOWS\system32\xqfoemn Infected: Trojan.Win32.Patched.dr 1 The selected area was scanned. = I did virscan, but was unable to clipcopy (?). However, I copied the results to Notepad. The results: Viruses found: c:\qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir Win-Trojan/User32Hk W32.Patched.Bb Win32:SysPatch [Wrm] BackDoor.Zapinit Trojan.Win32.Patched.dr [AVP] W32/Patched.D!tr Trojan.Win32.Patched.dr [Engine:A] Win32/PatchFile.d Trojan.Win32.Patched.dr Win32.Patched.bb.10 Virus:Win32/Mariofev.A W32/Patched.D Trojan.Patched.AP Trojan.Win32.Patched.bi Troj/User32Hk-A Possible_Patch-1 Trojan.Patched.AP c:\windows\system32\user32.dll no malware found - I hope it's useful. Thanks again for any help. pumex
Hi,

Please do the following:

Delete the emails from your inbox that Kaspersky indicated were infected. I cannpt include these in my script or it will delete your entire inbox.
Do not open the emails or attachments if you haven't already done so.

NEXT

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\Documents and Settings\HP_Administrator\Desktop\Articles\700Articles\msm.zip 
C:\Documents and Settings\HP_Administrator\Desktop\BUYS\England\ForumMkt.zip 
C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\MembershipSiteManager-Rights.zip 
C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\membership_manager.rar 
C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\SuperForumMarketing.zip 
C:\Documents and Settings\HP_Administrator\Desktop\Goodies\ezmembershipsystem.zip
C:\Documents and Settings\HP_Administrator\Desktop\JV\GIVEWAYS\MEMB\MembershipSiteManager-Rights.zip 
C:\Documents and Settings\HP_Administrator\My Documents\TransfersfromoldPC\Ethicash\membership_manager.rar 
C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs 
C:\WINDOWS\system32\bjzrozi
C:\WINDOWS\system32\xqfoemn 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Include a fresh HJT log in with the OTMoveIt3 log also describe how your computer is behaving now.
Thanks, I went to the email folders, but don't see any way to find the faulty emails. How to find those with the viruses? Also, should I delete he infected files? I will wait for your response before I do the OT Move stuff. Thanks a lot. pumex
Hi The OT move it script is going to delete the infected files that Kaspersky found. As for the emails, to be safe I would delete all the emails in your inbox unless there is something essential there that you know and trust the source of as there isn't a way that I know of to identify which particular email might be the offender. there is one that mentions "deals' and one that mentions 'gambling' but other than that, there is nothing to specifically identify which message it might be. You will have to use your best judgment there. If it were my inbox, I'd delete them all.
I deleted almost all suggested emails, except the 20062008Deals sub-folder in the Inbox. Here is the log: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Documents and Settings\HP_Administrator\Desktop\Articles\700Articles\msm.zip moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\BUYS\England\ForumMkt.zip moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\MembershipSiteManager-Rights.zip moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\membership_manager.rar moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\FilesToUse\SuperForumMarketing.zip moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\Goodies\ezmembershipsystem.zip moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\JV\GIVEWAYS\MEMB\MembershipSiteManager-Rights.zip moved successfully. C:\Documents and Settings\HP_Administrator\My Documents\TransfersfromoldPC\Ethicash\membership_manager.rar moved successfully. C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs moved successfully. C:\WINDOWS\system32\bjzrozi moved successfully. C:\WINDOWS\system32\xqfoemn moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\FSSync.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kave.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kosglue-7.0.26.0.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\hsperfdata_HP_Administrator\3212 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\hsperfdata_HP_Administrator\4072 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\etilqs_0haaLPIZhzhvaaGhUJ0Q scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\~DFCF9F.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\P80YVAXR\favicon[1].ico scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\6O4BWIUI\favicon[1].ico scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\info[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\pngbehavior[1].htc scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\virusscanner[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\530O5DUR\favicon[1].ico scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\530O5DUR\MarkFlavinsBlog[1].xml scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2e4.dat scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\21\66415395-16d3740c scheduled to be deleted on reboot. Java cache emptied. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Opera cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04212009_192454 Files moved on Reboot… DllUnregisterServer procedure not found in C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\FSSync.dll C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\FSSync.dll NOT unregistered. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\FSSync.dll moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kave.dll C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kave.dll NOT unregistered. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kave.dll moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kosglue-7.0.26.0.dll C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kosglue-7.0.26.0.dll NOT unregistered. C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jkos-HP_Administrator\binaries\kosglue-7.0.26.0.dll moved successfully. File C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\hsperfdata_HP_Administrator\3212 not found! File C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\hsperfdata_HP_Administrator\4072 not found! File C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\etilqs_0haaLPIZhzhvaaGhUJ0Q not found! File C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\~DFCF9F.tmp not found! C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\P80YVAXR\favicon[1].ico moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\6O4BWIUI\favicon[1].ico moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\info[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\pngbehavior[1].htc moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5ZS4GL8Y\virusscanner[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\530O5DUR\favicon[1].ico moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\530O5DUR\MarkFlavinsBlog[1].xml moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully. File C:\WINDOWS\temp\Perflib_Perfdata_2e4.dat not found! C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\21\66415395-16d3740c moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\XUL.mfl moved successfully. = Thanks pumex
C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox.sbd\20062008 Deals Suspicious: Trojan-Spy.HTML.Fraud.gen 3

This link will give you more info on what might be contained in that Deals folder - I'm not sure you want to keep it - up to you
http://www.viruslist.com/en/viruses/encycl…a?virusid=66363


can you please post a fresh HJT log and describe how your computer is running now….
That trojan looks awful, but I would prefer to keep the folder that has important info for me. Moreover, as I understand vulnerability is in IE and I use mainly (99%) Firefox.

So here is the HJT log. Do you see any improvement? I think the computer is running better, but it's hard to say- just after few minutes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:03:35 PM, on 21/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\ehome\ehshell.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ehome\EHTray.exe
C:\WINDOWS\ehome\ehExtHost.exe
c:\Program Files\HP\Digital Imaging\bin\HPZISMGR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

–
End of file - 9352 bytes
==
Thanks again

pumex
Good news, your log is clean :thumbup:

Now we need to clean up after ourselves:

please do the following:


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



NEXT

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI