This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] What is wrong with this computer!

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I'm not sure what is going on with this computer. I keep getting pop-ups with nothing but a could not process 404 message. I do have access to the net but I don't trust it at all. I'm writing this post from a different computer.

Here's my log, and thanks in advance to anyone who can help out:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:07:03 PM, on 5/15/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16830)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Student\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ycomp/def…://ca.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.ca.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.ca.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.rd.yahoo.com/customize/ycomp/def…://ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AH IE BHO - {10384d0e-2bc1-48b6-844b-ad0e9e6d2511} - C:\Program Files\ZoomText 9.1\AHOI\ah_ie_bho.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Windows\system32\SysMonitor.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoomText] "C:\Program Files\ZoomText 9.1\ZT.exe" /AUTOSTART
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [?????????] ??????????????e
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-685457160-246752126-2549573056-1001\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Student')
O4 - HKUS\S-1-5-21-685457160-246752126-2549573056-1001\..\Run: [CPM573aff37] Rundll32.exe "C:\ProgramData\banoroya\banoroya.dll",a (User 'Student')
O4 - S-1-5-21-685457160-246752126-2549573056-1001 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Student')
O4 - S-1-5-21-685457160-246752126-2549573056-1001 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Student')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://config.skillcheck.com/onlinetesting…linetesting.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{59491320-FDB5-405E-AD8F-A5AA7722D0C3}: NameServer = 64.71.255.198
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ZoomText Helper Service - Ai Squared - C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe

–
End of file - 7702 bytes
Hi,

Please do the following:

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi CatByte,

Thank you very much for replying. Here is my log:

ComboFix 09-05-15.01 - Admin 05/15/2009 15:04.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.767.206 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Redemption.ECF

.
((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-15 13:32 . 2009-05-15 16:59 ——– d—–w c:\programdata\zevububu
2009-05-15 13:32 . 2009-05-15 16:59 ——– d—–w c:\users\All Users\zevububu
2009-05-15 13:32 . 2009-05-15 13:32 ——– d—–w c:\programdata\banoroya
2009-05-15 13:32 . 2009-05-15 13:32 ——– d—–w c:\users\All Users\banoroya
2009-05-14 18:25 . 2009-05-14 18:25 ——– d—–w C:\New Folder
2009-05-11 15:32 . 2009-05-11 15:32 ——– d—–w c:\users\Student\New Folder
2009-04-24 12:56 . 2009-04-24 16:48 ——– d—–w c:\users\Student\AppData\Local\Google
2009-04-23 20:03 . 2009-05-11 15:31 ——– d—–w c:\program files\Google
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\programdata\NOS
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\users\All Users\NOS
2009-04-23 20:03 . 2009-04-23 20:03 ——– d—–w c:\program files\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 20:08 . 2006-01-07 04:37 ——– d—–w c:\program files\Common Files\Adobe
2009-03-27 12:08 . 2009-03-23 16:03 ——– d—–w c:\program files\ZoomText 9.1
2009-03-23 16:34 . 2009-03-23 16:13 4 —-a-w c:\windows\vx86036.dat
2009-03-23 16:09 . 2006-01-07 04:22 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-23 16:08 . 2009-03-23 16:08 ——– d—–w c:\program files\VW
2009-03-23 16:08 . 2009-03-23 16:07 ——– d—–w c:\program files\ViaVoiceTTS
2009-03-23 16:05 . 2009-03-23 16:04 ——– d—–w c:\program files\ZoomText 9.1 Tutorial
2009-03-17 03:16 . 2009-04-16 12:35 14848 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-16 12:35 25600 —-a-w c:\windows\system32\amxread.dll
2009-03-03 04:24 . 2009-04-16 12:35 3503584 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:24 . 2009-04-16 12:35 3469280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:20 . 2009-04-16 12:34 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:19 . 2009-04-16 12:35 158720 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:19 . 2009-04-16 12:35 549888 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:19 . 2009-04-16 12:35 24576 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:16 . 2009-04-16 12:34 56320 —-a-w c:\windows\system32\iesetup.dll
2009-03-03 04:16 . 2009-04-16 12:35 97280 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:16 . 2009-04-16 12:35 53248 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:16 . 2009-04-16 12:35 37888 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:16 . 2009-04-16 12:34 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:15 . 2009-04-16 12:34 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-03 02:40 . 2009-04-16 12:35 654336 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:08 . 2009-04-16 12:34 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-03 00:44 . 2009-04-16 12:34 48128 —-a-w c:\windows\system32\mshtmler.dll
2008-12-12 13:23 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"?????????"="??????????????e" [?]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2006-11-23 319488]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2006-12-13 3166208]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2006-12-04 1261568]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-11-17 453120]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"ZoomText"="c:\program files\ZoomText 9.1\ZT.exe" [2008-02-25 1922296]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

c:\users\Student\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{606F9767-608B-402B-961F-09F4FD26CF0D}"= UDP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{F805D548-A289-46D1-BD6F-D4F60A7C6050}"= TCP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B72072FB-56BB-43FD-9A80-9BCF8D7289E0}"= UDP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{0C764EEA-4B92-4251-88CF-A63A3B6BAC2F}"= TCP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{CCC058AA-2F4C-4604-8F3C-93811B85C4A2}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{53DBA74A-093C-4270-BF2C-A9A443CAA248}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{69E5CD57-D89E-46A5-BB98-A79C39D6EC2A}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{9DE2CC96-75DC-47FF-BA30-9162BE1C38CF}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{7A5CBA66-D006-4CD7-BA7B-7086872ADBC1}"= UDP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{03DE0338-B9D1-4DEA-986A-80946EA0CDE7}"= TCP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{4B01CBB9-8D7A-4122-AB6D-3262EAA63B49}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{B8E32171-50F1-4136-9151-EBF67F73F729}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{3330805C-ABEB-4F92-9D05-4BB78A5E5C57}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{32401E4C-6557-463B-B46B-9A3D145DD2B0}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{1033866B-7A16-4E39-B1FB-10C2AEA2E432}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E79E8F3D-AF98-4B34-B8EF-2538941FDC2E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{F5FC6099-8265-4003-B66A-FEABECB90E7B}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:javaw
"UDP Query User{1C35E3EE-AC22-418E-9407-DA61F1735ADD}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:javaw
"{353DB548-3BA1-48FE-BF03-D1000FF45883}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4A7D4D94-D738-4C98-9261-62026CD2C6EA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{521C78DB-7371-438D-A087-446AC5B9AEFE}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0C7B7580-C725-47D9-8DCC-BF00263103BD}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0258952C-6B93-48FD-AA3B-2047156391E2}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0638C3D3-349E-4C87-80CB-42EC1AA8E0A6}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 Ai2sXP;Ai2sXP;c:\windows\System32\drivers\Ai2sXP.sys [3/23/2009 12:03 PM 7296]
R2 ZoomText Helper Service;ZoomText Helper Service;c:\program files\ZoomText 9.1\ZoomTextHelperService.exe [3/23/2009 12:03 PM 49152]
R3 Ai2Mmpd;Ai2Mmpd;c:\windows\System32\drivers\Ai2Mmpd.sys [3/23/2009 12:03 PM 5120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/9/2009 8:12 AM 101936]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [4/23/2009 4:03 PM 33176]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [11/28/2006 6:34 AM 122008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ LPDSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-15 c:\windows\Tasks\User_Feed_Synchronization-{662230EF-AD01-4649-B570-8DEA7A65F7D6}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
- - - - ORPHANS REMOVED - - - -

HKCU-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil9e.exe
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ncr
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {59491320-FDB5-405E-AD8F-A5AA7722D0C3} = 64.71.255.198
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 15:07
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-15 15:09
ComboFix-quarantined-files.txt 2009-05-15 19:09

Pre-Run: 85,044,207,616 bytes free
Post-Run: 84,898,787,328 bytes free

151 — E O F — 2009-05-14 12:37
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/What_wrong_computer_t103094.html&view=findpost&p=558941#entry558941

Collect::
c:\programdata\zevububu
c:\users\All Users\zevububu
c:\programdata\banoroya
c:\users\All Users\banoroya

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-
"?????????"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi CatByte,

I did as you suggested and I'm not sure if I've done it right but here's the new log, again many thanks!:

ComboFix 09-05-15.01 - Admin 05/19/2009 9:09.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.767.215 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Student\Desktop\CFScript.txt
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-15 13:32 . 2009-05-15 16:59 ——– d—–w c:\programdata\zevububu
2009-05-15 13:32 . 2009-05-15 16:59 ——– d—–w c:\users\All Users\zevububu
2009-05-15 13:32 . 2009-05-15 13:32 ——– d—–w c:\programdata\banoroya
2009-05-15 13:32 . 2009-05-15 13:32 ——– d—–w c:\users\All Users\banoroya
2009-05-14 18:25 . 2009-05-14 18:25 ——– d—–w C:\New Folder
2009-05-11 15:32 . 2009-05-11 15:32 ——– d—–w c:\users\Student\New Folder
2009-04-24 12:56 . 2009-04-24 16:48 ——– d—–w c:\users\Student\AppData\Local\Google
2009-04-23 20:03 . 2009-05-11 15:31 ——– d—–w c:\program files\Google
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\programdata\NOS
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\users\All Users\NOS
2009-04-23 20:03 . 2009-04-23 20:03 ——– d—–w c:\program files\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 20:08 . 2006-01-07 04:37 ——– d—–w c:\program files\Common Files\Adobe
2009-03-27 12:08 . 2009-03-23 16:03 ——– d—–w c:\program files\ZoomText 9.1
2009-03-23 16:34 . 2009-03-23 16:13 4 —-a-w c:\windows\vx86036.dat
2009-03-23 16:09 . 2006-01-07 04:22 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-23 16:08 . 2009-03-23 16:08 ——– d—–w c:\program files\VW
2009-03-23 16:08 . 2009-03-23 16:07 ——– d—–w c:\program files\ViaVoiceTTS
2009-03-23 16:05 . 2009-03-23 16:04 ——– d—–w c:\program files\ZoomText 9.1 Tutorial
2009-03-17 03:16 . 2009-04-16 12:35 14848 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-16 12:35 25600 —-a-w c:\windows\system32\amxread.dll
2009-03-03 04:24 . 2009-04-16 12:35 3503584 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:24 . 2009-04-16 12:35 3469280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:20 . 2009-04-16 12:34 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:19 . 2009-04-16 12:35 158720 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:19 . 2009-04-16 12:35 549888 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:19 . 2009-04-16 12:35 24576 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:16 . 2009-04-16 12:34 56320 —-a-w c:\windows\system32\iesetup.dll
2009-03-03 04:16 . 2009-04-16 12:35 97280 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:16 . 2009-04-16 12:35 53248 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:16 . 2009-04-16 12:35 37888 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:16 . 2009-04-16 12:34 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:15 . 2009-04-16 12:34 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-03 02:40 . 2009-04-16 12:35 654336 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:08 . 2009-04-16 12:34 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-03 00:44 . 2009-04-16 12:34 48128 —-a-w c:\windows\system32\mshtmler.dll
2008-12-12 13:23 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-05-15_19.07.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-01-07 04:27 . 2009-05-19 13:05 41580 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-01-07 04:27 . 2009-05-15 18:52 41580 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-19 13:05 61506 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-06-25 11:51 . 2009-05-19 13:05 11984 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-685457160-246752126-2549573056-1001_UserData.bin
+ 2006-01-07 04:53 . 2009-05-15 19:34 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-01-07 04:53 . 2009-05-15 19:34 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-01-07 04:53 . 2009-05-15 19:34 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-19 13:02 . 2009-05-19 13:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-15 18:49 . 2009-05-15 18:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-15 18:49 . 2009-05-15 18:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-19 13:02 . 2009-05-19 13:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-05-19 13:07 626738 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-15 18:54 626738 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-19 13:07 107508 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-05-15 18:54 107508 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"?????????"="??????????????e" [?]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2006-11-23 319488]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2006-12-13 3166208]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2006-12-04 1261568]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-11-17 453120]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"ZoomText"="c:\program files\ZoomText 9.1\ZT.exe" [2008-02-25 1922296]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

c:\users\Student\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{606F9767-608B-402B-961F-09F4FD26CF0D}"= UDP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{F805D548-A289-46D1-BD6F-D4F60A7C6050}"= TCP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B72072FB-56BB-43FD-9A80-9BCF8D7289E0}"= UDP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{0C764EEA-4B92-4251-88CF-A63A3B6BAC2F}"= TCP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{CCC058AA-2F4C-4604-8F3C-93811B85C4A2}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{53DBA74A-093C-4270-BF2C-A9A443CAA248}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{69E5CD57-D89E-46A5-BB98-A79C39D6EC2A}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{9DE2CC96-75DC-47FF-BA30-9162BE1C38CF}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{7A5CBA66-D006-4CD7-BA7B-7086872ADBC1}"= UDP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{03DE0338-B9D1-4DEA-986A-80946EA0CDE7}"= TCP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{4B01CBB9-8D7A-4122-AB6D-3262EAA63B49}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{B8E32171-50F1-4136-9151-EBF67F73F729}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{3330805C-ABEB-4F92-9D05-4BB78A5E5C57}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{32401E4C-6557-463B-B46B-9A3D145DD2B0}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{1033866B-7A16-4E39-B1FB-10C2AEA2E432}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E79E8F3D-AF98-4B34-B8EF-2538941FDC2E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{F5FC6099-8265-4003-B66A-FEABECB90E7B}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:javaw
"UDP Query User{1C35E3EE-AC22-418E-9407-DA61F1735ADD}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:javaw
"{353DB548-3BA1-48FE-BF03-D1000FF45883}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4A7D4D94-D738-4C98-9261-62026CD2C6EA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{521C78DB-7371-438D-A087-446AC5B9AEFE}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0C7B7580-C725-47D9-8DCC-BF00263103BD}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0258952C-6B93-48FD-AA3B-2047156391E2}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0638C3D3-349E-4C87-80CB-42EC1AA8E0A6}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 Ai2sXP;Ai2sXP;c:\windows\System32\drivers\Ai2sXP.sys [3/23/2009 12:03 PM 7296]
R2 ZoomText Helper Service;ZoomText Helper Service;c:\program files\ZoomText 9.1\ZoomTextHelperService.exe [3/23/2009 12:03 PM 49152]
R3 Ai2Mmpd;Ai2Mmpd;c:\windows\System32\drivers\Ai2Mmpd.sys [3/23/2009 12:03 PM 5120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/9/2009 8:12 AM 101936]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [4/23/2009 4:03 PM 33176]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [11/28/2006 6:34 AM 122008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ LPDSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-19 c:\windows\Tasks\User_Feed_Synchronization-{662230EF-AD01-4649-B570-8DEA7A65F7D6}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ncr
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {59491320-FDB5-405E-AD8F-A5AA7722D0C3} = 64.71.255.198
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-19 09:13
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(2460)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\ShowErrMsg.dll
c:\programdata\zevububu\zevububu.dll
c:\programdata\banoroya\banoroya.dll
.
Completion time: 2009-05-19 9:15
ComboFix-quarantined-files.txt 2009-05-19 13:15
ComboFix2.txt 2009-05-15 19:09

Pre-Run: 85,063,278,592 bytes free
Post-Run: 84,787,077,120 bytes free

174 — E O F — 2009-05-14 12:37
Hi,

We need to do that again, there are more files to collect and delete.


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/What_wrong_computer_t103094.html&view=findpost&p=560102#entry560102

Collect::
c:\programdata\zevububu\zevububu.dll
c:\programdata\banoroya\banoroya.dll

Folder::
c:\programdata\zevububu
c:\users\All Users\zevububu
c:\programdata\banoroya
c:\users\All Users\banoroya

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-
"?????????"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi CatByte, I've taken the appropriate actions but there's a snag, ComboFix has produced the following message: "Submit Files for further analysis ComboFix needs to submit malware files for furthur analysis. Please ensure you're connected to the internet and before clicking OK" Here's the problem, I no longer have internet access on the computer. I'm using another one to type and send this message. What should I do? Click OK anyways? I'm going to wait for your reply before I make a next move. Thanks CatByte.
Hi,

This is the first you have mentioned that you don't have internet access.

I do have access to the net but I don't trust it at all. I'm writing this post from a different computer.

have you just disconnected this computer from the internet or has it been lost since we started cleaning or some other reason, please describe what has happened.

Perhaps try disabling your firewall temporarily, while the files are uploaded.

If you can reestablish a connection - that would be better, if not, we can upload those files later.
Hi CatByte, You're correct, the connection has been lost since we last communicated. How that may have happened, I'm completely unaware. I have not used the computer in a few days (vacation). I did disable the firewall but a connection has not been established. Press OK anways? Thanks CatByte.
Yes, we will upload those files later. what happens when you try and connect? are you on a router..if you are - try connecting directly if you can.
Hi CatByte,

Nothing happens when I try to connect. The "Internet Explorer page cannot be accessed" comes up and that's it. I am on a router, however I am directly connected as well.

Here is the log:

ComboFix 09-05-15.01 - Admin 05/19/2009 10:50.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.767.190 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Student\Desktop\CFScript.txt
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\programdata\banoroya
c:\programdata\banoroya\banoroya.dll
c:\programdata\zevububu
c:\programdata\zevububu\ububuvez.ini
c:\programdata\zevububu\zevububu.dll
c:\users\All Users\banoroya\banoroya.dll
c:\users\All Users\zevububu\ububuvez.ini
c:\users\All Users\zevububu\zevububu.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-14 18:25 . 2009-05-14 18:25 ——– d—–w C:\New Folder
2009-05-11 15:32 . 2009-05-11 15:32 ——– d—–w c:\users\Student\New Folder
2009-04-24 12:56 . 2009-04-24 16:48 ——– d—–w c:\users\Student\AppData\Local\Google
2009-04-23 20:03 . 2009-05-11 15:31 ——– d—–w c:\program files\Google
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\programdata\NOS
2009-04-23 20:03 . 2009-04-23 20:05 ——– d—–w c:\users\All Users\NOS
2009-04-23 20:03 . 2009-04-23 20:03 ——– d—–w c:\program files\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 20:08 . 2006-01-07 04:37 ——– d—–w c:\program files\Common Files\Adobe
2009-03-27 12:08 . 2009-03-23 16:03 ——– d—–w c:\program files\ZoomText 9.1
2009-03-23 16:34 . 2009-03-23 16:13 4 —-a-w c:\windows\vx86036.dat
2009-03-23 16:09 . 2006-01-07 04:22 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-23 16:08 . 2009-03-23 16:08 ——– d—–w c:\program files\VW
2009-03-23 16:08 . 2009-03-23 16:07 ——– d—–w c:\program files\ViaVoiceTTS
2009-03-23 16:05 . 2009-03-23 16:04 ——– d—–w c:\program files\ZoomText 9.1 Tutorial
2009-03-17 03:16 . 2009-04-16 12:35 14848 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-16 12:35 25600 —-a-w c:\windows\system32\amxread.dll
2009-03-03 04:24 . 2009-04-16 12:35 3503584 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:24 . 2009-04-16 12:35 3469280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:20 . 2009-04-16 12:34 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:19 . 2009-04-16 12:35 158720 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:19 . 2009-04-16 12:35 549888 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:19 . 2009-04-16 12:35 24576 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:16 . 2009-04-16 12:34 56320 —-a-w c:\windows\system32\iesetup.dll
2009-03-03 04:16 . 2009-04-16 12:35 97280 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:16 . 2009-04-16 12:35 53248 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:16 . 2009-04-16 12:35 37888 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:16 . 2009-04-16 12:34 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:15 . 2009-04-16 12:34 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-03 02:40 . 2009-04-16 12:35 654336 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:08 . 2009-04-16 12:34 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-03 00:44 . 2009-04-16 12:34 48128 —-a-w c:\windows\system32\mshtmler.dll
2008-12-12 13:23 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-05-15_19.07.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-01-07 04:27 . 2009-05-19 14:46 41988 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-19 14:46 61554 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-06-25 11:51 . 2009-05-19 14:46 11984 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-685457160-246752126-2549573056-1001_UserData.bin
+ 2006-01-07 04:53 . 2009-05-15 19:34 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-01-07 04:53 . 2009-05-15 19:34 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-01-07 04:53 . 2009-05-15 19:34 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-01-07 04:53 . 2009-05-15 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-19 14:44 . 2009-05-19 14:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-15 18:49 . 2009-05-15 18:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-15 18:49 . 2009-05-15 18:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-19 14:44 . 2009-05-19 14:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-05-19 14:49 626738 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-15 18:54 626738 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-19 14:49 107508 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-05-15 18:54 107508 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2006-11-23 319488]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2006-12-13 3166208]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2006-12-04 1261568]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-11-17 453120]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"ZoomText"="c:\program files\ZoomText 9.1\ZT.exe" [2008-02-25 1922296]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

c:\users\Student\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{606F9767-608B-402B-961F-09F4FD26CF0D}"= UDP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{F805D548-A289-46D1-BD6F-D4F60A7C6050}"= TCP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B72072FB-56BB-43FD-9A80-9BCF8D7289E0}"= UDP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{0C764EEA-4B92-4251-88CF-A63A3B6BAC2F}"= TCP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{CCC058AA-2F4C-4604-8F3C-93811B85C4A2}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{53DBA74A-093C-4270-BF2C-A9A443CAA248}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{69E5CD57-D89E-46A5-BB98-A79C39D6EC2A}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{9DE2CC96-75DC-47FF-BA30-9162BE1C38CF}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{7A5CBA66-D006-4CD7-BA7B-7086872ADBC1}"= UDP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{03DE0338-B9D1-4DEA-986A-80946EA0CDE7}"= TCP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{4B01CBB9-8D7A-4122-AB6D-3262EAA63B49}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{B8E32171-50F1-4136-9151-EBF67F73F729}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{3330805C-ABEB-4F92-9D05-4BB78A5E5C57}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{32401E4C-6557-463B-B46B-9A3D145DD2B0}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{1033866B-7A16-4E39-B1FB-10C2AEA2E432}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E79E8F3D-AF98-4B34-B8EF-2538941FDC2E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{F5FC6099-8265-4003-B66A-FEABECB90E7B}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:javaw
"UDP Query User{1C35E3EE-AC22-418E-9407-DA61F1735ADD}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:javaw
"{353DB548-3BA1-48FE-BF03-D1000FF45883}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4A7D4D94-D738-4C98-9261-62026CD2C6EA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{521C78DB-7371-438D-A087-446AC5B9AEFE}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0C7B7580-C725-47D9-8DCC-BF00263103BD}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0258952C-6B93-48FD-AA3B-2047156391E2}"= UDP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1
"{0638C3D3-349E-4C87-80CB-42EC1AA8E0A6}"= TCP:c:\program files\ZoomText 9.1\Zt.exe:ZoomText 9.1

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 Ai2sXP;Ai2sXP;c:\windows\System32\drivers\Ai2sXP.sys [3/23/2009 12:03 PM 7296]
R2 ZoomText Helper Service;ZoomText Helper Service;c:\program files\ZoomText 9.1\ZoomTextHelperService.exe [3/23/2009 12:03 PM 49152]
R3 Ai2Mmpd;Ai2Mmpd;c:\windows\System32\drivers\Ai2Mmpd.sys [3/23/2009 12:03 PM 5120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/9/2009 8:12 AM 101936]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [4/23/2009 4:03 PM 33176]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [11/28/2006 6:34 AM 122008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ LPDSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-19 c:\windows\Tasks\User_Feed_Synchronization-{662230EF-AD01-4649-B570-8DEA7A65F7D6}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ncr
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.ca.acer.yahoo.com
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {59491320-FDB5-405E-AD8F-A5AA7722D0C3} = 64.71.255.198
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-19 10:53
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3160)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-05-19 10:55
ComboFix-quarantined-files.txt 2009-05-19 14:55
ComboFix2.txt 2009-05-19 13:15
ComboFix3.txt 2009-05-15 19:09

Pre-Run: 85,201,391,616 bytes free
Post-Run: 85,134,954,496 bytes free

181 — E O F — 2009-05-14 12:37
Hi,

here are a couple of things to try to get you back on line:

Please try the following:

go to Start > Run > type: cmd
Press OK or Hit Enter.
At the command prompt, type or copy/paste:

ipconfig /flushdns

(note the space between “..g /f…” it needs to be there)
Hit Enter.
You will get a confirmation that the flush was successful.
Close the command box.

NEXT

Please reset Internet Explorer

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.

In Internet Explorer

  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes

Please advise if that resolves the internet connection issues.

If not,

try downloading an alternate browser as the issue may just be with IE

http://www.mozilla.com/en-US/firefox/ie.html

download Firefox ( I recommend everyone use this browser )

see if you can connect with it
Hi CatByte, It's not working. I've done as you've suggested (including the space) but all that keeps coming back is the following message: The requested operation requires elevation. I'm not sure what this means or what the next step is but I appreciate you sticking with me. Many thanks.
Hi, It's a Vista thing, I'll have to check with my tech associates, move on to the next steps and see if that resolves anything
Hi CatByte, I tried moving onto the next set of steps but there are a few differences. I think this coincides with your "It's a Vista thing" comment. And this is the step I am referring to: Please reset Internet Explorer Go to Start > Control Panel, and choose Network Connections. Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties. Click the Networking tab Double-click on the Internet Protocol (TCP/IP) item. Write down the settings in case you should need to change them back. Select the radio button that says "Obtain DNS servers automatically". Click OK twice to get out of the properties screen and restart your computer. If not prompted to reboot go ahead and reboot manually.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI