This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] redirecting our websites

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:14:26 AM, on 5/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\BJCard\Bjmcmng.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
c:\program files\common files\mozilla shared\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivirprotection.com
O1 - Hosts: 94.232.248.66 www.antivirprotection.com
O2 - BHO: (no name) - {A483C4B7-FC10-4486-B931-5F2212EF2EB4} - c:\windows\system32\mttsgcw.dll
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: D-link AirPlus G DWL-G120 Wireless USB.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/oneclickfix/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136593632451
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: cfjajrhc - C:\WINDOWS\SYSTEM32\mttsgcw.dll
O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Program Files\Canon\BJCard\Bjmcmng.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4298 bytes

Symptoms - anything we put in yahoo or foxfire search is redirected to random websites, task manager and system restore is disabled, audio come on randomly without our direction. i have tried the advanced help to run mbam, but it will not run. please help!
Hi,

Please do the following:

  • Open HijackThis.
  • Click Do a System Scan Only.
  • Put a checkmark in the box on the left side of these entries only:

    O1 - Hosts: ::1 localhost
    O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
    O1 - Hosts: 94.232.248.66 antivirprotection.com
    O1 - Hosts: 94.232.248.66 www.antivirprotection.com
    O20 - Winlogon Notify: cfjajrhc - C:\WINDOWS\SYSTEM32\mttsgcw.dll

  • Close ALL windows and browsers except HijackThis and click "Fix checked"
  • Exit HijackThis


NEXT
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
i was thrilled to get a response! However, i can't get combofix to do anything when i double click it to run on my desktop. Where do i go from here? I get an hour glass, but then it goes away and nothing happens.
Do this in Safe Mode

Go to Start >> Run and copy/paste this line into the run box

"%userprofile%\desktop\combofix.exe" /killall


Click OK.

this will start ComboFix in a special way.
When finished, it will produce a log.
Please save that log to a Notepad File.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.
started computer in safe mode, then did the run detail, and combo would still not run. just came up with a box to tell me that the application is not verified and was i sure that i wanted to run it. i clicked run…and then the box left and i got an hour glass and then nothing.
Hi,

try this,

delete the copy you have on your desktop and then download and rename.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt back into this thread.
ComboFix 09-05-25.01 - Owner 05/25/2009 15:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.297 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\bambam.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\drivers\aeiecdod.sys
c:\windows\system32\drivers\ehxxwzmk.sys
c:\windows\system32\drivers\TDSSiqwh.sys
c:\windows\system32\drivers\UACdfyakxaqvairnvv.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mttsgcw.dll
c:\windows\system32\pnifiir.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\TDSSatfl.dll
c:\windows\system32\TDSSbrgo.dll
c:\windows\system32\TDSSduwt.dll
c:\windows\system32\TDSSeref.dat
c:\windows\system32\TDSSfbdm.dll
c:\windows\system32\TDSSkjbu.log
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnuhc.dll
c:\windows\system32\TDSSqirg.dll
c:\windows\system32\TDSSxhwp.log
c:\windows\system32\tfykttxx.dll
c:\windows\system32\UACbgqhnukeonnqulm.dll
c:\windows\system32\UAChcfoimcldovtuks.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkbrogdtrfhdrost.dll
c:\windows\system32\UACnwabtniuvbnucom.dll
c:\windows\system32\UACnynxfwsobxehels.dll
c:\windows\system32\UACpuskuouknbckaao.dll
c:\windows\system32\UACsrqusuvyqxukjlr.log
c:\windows\system32\UACtrcdnpmbkovpxdn.dll
c:\windows\system32\UACuowrophysdrshbr.log
c:\windows\system32\UACvuewemdbbrqupeg.dat
c:\windows\system32\UACymthpymsmbqaohn.log
c:\windows\Tasks\At1.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
——-\Service_UACd.sys
——-\Legacy_AEIECDOD
——-\Legacy_LAAICMFT
——-\Service_aeiecdod
——-\Service_laaicmft


((((((((((((((((((((((((( Files Created from 2009-04-25 to 2009-05-25 )))))))))))))))))))))))))))))))
.

2009-05-25 11:17 . 2009-05-25 11:17 ——– d—–w c:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\fsmqxlqb
2009-05-25 11:14 . 2009-05-25 11:14 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\fsmqxlqb
2009-05-25 11:14 . 2009-05-25 11:14 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb
2009-05-24 23:52 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 23:52 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 23:52 . 2009-05-25 00:23 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 20:10 . 2009-05-24 20:10 13104 —-a-w c:\documents and settings\Administrator.PETE-05CK9PEMS6\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 19:22 . 2009-05-24 19:22 182 —-a-w C:\487656.bat
2009-05-24 18:11 . 2009-05-24 18:11 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-23 23:47 . 2009-03-24 20:08 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-23 23:27 . 2009-05-23 23:27 ——– d—–w c:\windows\Sun
2009-05-23 00:26 . 2009-05-23 00:26 ——– d—–w c:\program files\Trend Micro
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\program files\IObit
2009-05-21 11:28 . 2009-05-21 11:07 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-21 11:07 . 2009-05-21 11:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 11:07 . 2009-05-21 11:07 299352 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-05-21 11:07 . 2009-05-21 11:07 25440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-05-21 11:07 . 2009-05-21 11:07 15688 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 343888 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-05-21 11:07 . 2009-05-21 11:07 165728 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-05-21 11:07 . 2009-05-21 11:07 289632 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-05-21 11:07 . 2009-05-21 11:07 82784 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-05-21 11:06 . 2009-05-21 11:06 1629024 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-05-21 11:06 . 2009-05-21 11:06 212848 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 40288 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-05-21 11:06 . 2009-05-21 11:06 64160 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-21 11:06 . 2009-05-21 11:06 632680 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 539512 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-05-21 11:06 . 2009-05-21 11:06 552808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-05-21 11:06 . 2009-05-21 11:06 2324808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-05-21 11:06 . 2009-05-21 11:06 626000 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-05-21 11:06 . 2009-05-21 11:06 516440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-05-21 11:06 . 2009-05-21 11:06 953168 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-05-21 11:04 . 2009-05-21 11:05 ——– dc-h–w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 11:04 . 2009-03-12 08:17 2902048 -c–a-w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-21 11:04 . 2009-05-21 11:07 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-05-20 23:54 . 2009-05-20 23:54 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 19:44 . 2009-01-24 01:17 459980 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-25 19:44 . 2009-01-24 01:17 39234080 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-24 20:02 . 2009-05-24 20:12 2333184 —-a-w c:\windows\Internet Logs\xDB1A.tmp
2009-05-21 11:04 . 2004-07-15 18:46 ——– d—–w c:\program files\Lavasoft
2009-05-09 22:16 . 2008-01-05 00:47 4212 —h–w c:\windows\system32\zllictbl.dat
2009-05-09 19:46 . 2009-05-09 19:47 2240000 —-a-w c:\windows\Internet Logs\xDB19.tmp
2009-05-02 19:40 . 2009-05-02 19:41 2237440 —-a-w c:\windows\Internet Logs\xDB18.tmp
2009-05-02 19:40 . 2009-05-02 19:41 43008 —-a-w c:\windows\Internet Logs\xDB17.tmp
2009-05-02 18:42 . 2009-05-02 19:36 2236928 —-a-w c:\windows\Internet Logs\xDB16.tmp
2009-05-02 15:07 . 2009-05-02 15:08 2236416 —-a-w c:\windows\Internet Logs\xDB15.tmp
2009-05-02 15:07 . 2009-05-02 15:08 694272 —-a-w c:\windows\Internet Logs\xDB14.tmp
2009-04-16 23:12 . 2009-04-16 23:13 285184 —-a-w c:\windows\Internet Logs\xDB13.tmp
2009-04-15 00:05 . 2008-05-24 21:09 8383086 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-11 17:13 . 2009-04-11 17:14 2197504 —-a-w c:\windows\Internet Logs\xDB12.tmp
2009-04-04 16:57 . 2009-04-04 16:58 1690112 —-a-w c:\windows\Internet Logs\xDB11.tmp
2009-03-31 23:35 . 2009-03-31 23:36 2191872 —-a-w c:\windows\Internet Logs\xDB10.tmp
2009-03-06 14:22 . 2003-07-16 20:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-10-21 20:51 826368 —-a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-21 516440]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
D-link AirPlus G DWL-G120 Wireless USB.lnk - c:\program files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe [2006-1-6 241664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/21/2009 7:07 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]

— Other Services/Drivers In Memory —

*NewlyCreated* - AEIECDOD
*Deregistered* - aeiecdod
.
Contents of the 'Scheduled Tasks' folder

2009-05-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 11:06]
.
- - - - ORPHANS REMOVED - - - -

BHO-{471E37EB-AC5E-4F2A-8973-768010E3AFFa} - c:\windows\system32\tfykttxx.dll
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\o6u7ojsr.default\
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-25 15:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2884)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Canon\BJCard\Bjmcmng.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-25 15:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-25 19:52

Pre-Run: 28,566,269,952 bytes free
Post-Run: 29,212,868,608 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

208 — E O F — 2009-05-14 22:14

Yes, I actually renamed it while i was waiting for you and it actually did the scan and then a rootkit, i think it was called. anyway, for the moment, the computer is all right. thank you so much. I have to tell you that i have a dell and went to their website first and they looked at my highjack log, but noone helped me.
My final question is how does my husband prevent it from happening again. We do have zone alarm, but it didn't stop this from happening. please advise and again, thank you very much
Hi, Please stay with me - absence of symptoms does not mean your computer is clean. We have more cleaning to do, that was just phase one. I will analyze the log and get back to you as soon as I can with further instructions Thank-you CB
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\487656.bat

Folder::
c:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\fsmqxlqb
c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\fsmqxlqb
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT


[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.
Malwarebytes' Anti-Malware 1.36
Database version: 2178
Windows 5.1.2600 Service Pack 3

5/25/2009 6:56:39 PM
mbam-log-2009-05-25 (18-56-39).txt

Scan type: Quick Scan
Objects scanned: 123018
Time elapsed: 3 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

And below is the combo fix log

ComboFix 09-05-25.05 - Owner 05/25/2009 18:42.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.467 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\bambam.exe
Command switches used :: c:\documents and settings\Owner.PETE-05CK9PEMS6\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
C:\487656.bat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\487656.bat
c:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\fsmqxlqb
c:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\urlclassifier3.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\XPC.mfl
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\profiles.ini
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\cert8.db
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\compatibility.ini
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\compreg.dat
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\cookies.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\formhistory.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\key3.db
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\localstore.rdf
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\permissions.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\places.sqlite-journal
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\places.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\pluginreg.dat
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\prefs.js
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\secmod.db
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\webappsstore.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\xpti.dat
c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\fsmqxlqb
c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\urlclassifier3.sqlite
c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\XPC.mfl

.
((((((((((((((((((((((((( Files Created from 2009-04-25 to 2009-05-25 )))))))))))))))))))))))))))))))
.

2009-05-25 11:17 . 2009-05-25 11:17 ——– d—–w c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb
2009-05-24 23:52 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 23:52 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 23:52 . 2009-05-25 00:23 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 20:10 . 2009-05-24 20:10 13104 —-a-w c:\documents and settings\Administrator.PETE-05CK9PEMS6\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 18:11 . 2009-05-24 18:11 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-23 23:47 . 2009-03-24 20:08 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-23 23:27 . 2009-05-23 23:27 ——– d—–w c:\windows\Sun
2009-05-23 00:26 . 2009-05-23 00:26 ——– d—–w c:\program files\Trend Micro
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\program files\IObit
2009-05-21 11:28 . 2009-05-21 11:07 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-21 11:07 . 2009-05-21 11:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 11:07 . 2009-05-21 11:07 299352 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-05-21 11:07 . 2009-05-21 11:07 25440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-05-21 11:07 . 2009-05-21 11:07 15688 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 343888 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-05-21 11:07 . 2009-05-21 11:07 165728 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-05-21 11:07 . 2009-05-21 11:07 289632 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-05-21 11:07 . 2009-05-21 11:07 82784 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-05-21 11:06 . 2009-05-21 11:06 1629024 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-05-21 11:06 . 2009-05-21 11:06 212848 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 40288 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-05-21 11:06 . 2009-05-21 11:06 64160 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-21 11:06 . 2009-05-21 11:06 632680 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 539512 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-05-21 11:06 . 2009-05-21 11:06 552808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-05-21 11:06 . 2009-05-21 11:06 2324808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-05-21 11:06 . 2009-05-21 11:06 626000 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-05-21 11:06 . 2009-05-21 11:06 516440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-05-21 11:06 . 2009-05-21 11:06 953168 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-05-21 11:04 . 2009-05-21 11:05 ——– dc-h–w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 11:04 . 2009-03-12 08:17 2902048 -c–a-w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-21 11:04 . 2009-05-21 11:07 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-05-20 23:54 . 2009-05-20 23:54 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 19:44 . 2009-01-24 01:17 459980 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-25 19:44 . 2009-01-24 01:17 39234080 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-24 20:02 . 2009-05-24 20:12 2333184 —-a-w c:\windows\Internet Logs\xDB1A.tmp
2009-05-21 11:04 . 2004-07-15 18:46 ——– d—–w c:\program files\Lavasoft
2009-05-09 22:16 . 2008-01-05 00:47 4212 —h–w c:\windows\system32\zllictbl.dat
2009-05-09 19:46 . 2009-05-09 19:47 2240000 —-a-w c:\windows\Internet Logs\xDB19.tmp
2009-05-02 19:40 . 2009-05-02 19:41 2237440 —-a-w c:\windows\Internet Logs\xDB18.tmp
2009-05-02 19:40 . 2009-05-02 19:41 43008 —-a-w c:\windows\Internet Logs\xDB17.tmp
2009-05-02 18:42 . 2009-05-02 19:36 2236928 —-a-w c:\windows\Internet Logs\xDB16.tmp
2009-05-02 15:07 . 2009-05-02 15:08 2236416 —-a-w c:\windows\Internet Logs\xDB15.tmp
2009-05-02 15:07 . 2009-05-02 15:08 694272 —-a-w c:\windows\Internet Logs\xDB14.tmp
2009-04-16 23:12 . 2009-04-16 23:13 285184 —-a-w c:\windows\Internet Logs\xDB13.tmp
2009-04-15 00:05 . 2008-05-24 21:09 8383086 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-11 17:13 . 2009-04-11 17:14 2197504 —-a-w c:\windows\Internet Logs\xDB12.tmp
2009-04-04 16:57 . 2009-04-04 16:58 1690112 —-a-w c:\windows\Internet Logs\xDB11.tmp
2009-03-31 23:35 . 2009-03-31 23:36 2191872 —-a-w c:\windows\Internet Logs\xDB10.tmp
2009-03-06 14:22 . 2003-07-16 20:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-10-21 20:51 826368 —-a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-21 516440]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
D-link AirPlus G DWL-G120 Wireless USB.lnk - c:\program files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe [2006-1-6 241664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/21/2009 7:07 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]

— Other Services/Drivers In Memory —

*NewlyCreated* - AEIECDOD
*Deregistered* - aeiecdod
.
Contents of the 'Scheduled Tasks' folder

2009-05-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 11:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\o6u7ojsr.default\
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-25 18:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-25 18:50
ComboFix-quarantined-files.txt 2009-05-25 22:50
ComboFix2.txt 2009-05-25 19:53

Pre-Run: 29,013,782,528 bytes free
Post-Run: 29,254,246,400 bytes free

164 — E O F — 2009-05-14 22:14

I know i am a pain, but i need to tell you that i forgot to reactivate my zone alarm after the initial combofix early this afternoon. my husband was on the computer without protection until now.
Hi,

Please do the following

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

Folder::
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb

Driver::
AEIECDOD

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

Note: disable your security programs before running this online scan

  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.
ComboFix 09-05-25.05 - Owner 05/25/2009 21:19.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.413 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\bambam.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\profiles.ini
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\cert8.db
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\compatibility.ini
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\compreg.dat
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\cookies.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\formhistory.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\key3.db
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\localstore.rdf
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\permissions.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\places.sqlite-journal
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\places.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\pluginreg.dat
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\prefs.js
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\secmod.db
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\webappsstore.sqlite
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\fsmqxlqb\Profiles\cp9z0zn4.default\xpti.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AEIECDOD


((((((((((((((((((((((((( Files Created from 2009-04-26 to 2009-05-26 )))))))))))))))))))))))))))))))
.

2009-05-25 22:51 . 2009-05-25 22:51 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Malwarebytes
2009-05-24 23:52 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 23:52 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 23:52 . 2009-05-25 00:23 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 20:10 . 2009-05-24 20:10 13104 —-a-w c:\documents and settings\Administrator.PETE-05CK9PEMS6\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 18:11 . 2009-05-24 18:11 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-05-23 23:47 . 2009-03-24 20:08 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-23 23:27 . 2009-05-23 23:27 ——– d—–w c:\windows\Sun
2009-05-23 00:26 . 2009-05-23 00:26 ——– d—–w c:\program files\Trend Micro
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
2009-05-22 23:26 . 2009-05-22 23:26 ——– d—–w c:\program files\IObit
2009-05-21 11:28 . 2009-05-21 11:07 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-21 11:07 . 2009-05-21 11:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 11:07 . 2009-05-21 11:07 299352 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-05-21 11:07 . 2009-05-21 11:07 25440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-05-21 11:07 . 2009-05-21 11:07 15688 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-05-21 11:07 . 2009-05-21 11:07 343888 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-05-21 11:07 . 2009-05-21 11:07 165728 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-05-21 11:07 . 2009-05-21 11:07 289632 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-05-21 11:07 . 2009-05-21 11:07 82784 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-05-21 11:06 . 2009-05-21 11:06 1629024 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-05-21 11:06 . 2009-05-21 11:06 212848 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 40288 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-05-21 11:06 . 2009-05-21 11:06 64160 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-21 11:06 . 2009-05-21 11:06 632680 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-05-21 11:06 . 2009-05-21 11:06 539512 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-05-21 11:06 . 2009-05-21 11:06 552808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-05-21 11:06 . 2009-05-21 11:06 2324808 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-05-21 11:06 . 2009-05-21 11:06 626000 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-05-21 11:06 . 2009-05-21 11:06 516440 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-05-21 11:06 . 2009-05-21 11:06 953168 —-a-w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-05-21 11:04 . 2009-05-21 11:05 ——– dc-h–w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 11:04 . 2009-03-12 08:17 2902048 -c–a-w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-21 11:04 . 2009-05-21 11:07 ——– d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-05-20 23:54 . 2009-05-20 23:54 ——– d—–w c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 01:13 . 2009-01-24 01:17 466340 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-26 01:13 . 2009-01-24 01:17 39234080 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-24 20:02 . 2009-05-24 20:12 2333184 —-a-w c:\windows\Internet Logs\xDB1A.tmp
2009-05-21 11:04 . 2004-07-15 18:46 ——– d—–w c:\program files\Lavasoft
2009-05-09 22:16 . 2008-01-05 00:47 4212 —h–w c:\windows\system32\zllictbl.dat
2009-05-09 19:46 . 2009-05-09 19:47 2240000 —-a-w c:\windows\Internet Logs\xDB19.tmp
2009-05-02 19:40 . 2009-05-02 19:41 2237440 —-a-w c:\windows\Internet Logs\xDB18.tmp
2009-05-02 19:40 . 2009-05-02 19:41 43008 —-a-w c:\windows\Internet Logs\xDB17.tmp
2009-05-02 18:42 . 2009-05-02 19:36 2236928 —-a-w c:\windows\Internet Logs\xDB16.tmp
2009-05-02 15:07 . 2009-05-02 15:08 2236416 —-a-w c:\windows\Internet Logs\xDB15.tmp
2009-05-02 15:07 . 2009-05-02 15:08 694272 —-a-w c:\windows\Internet Logs\xDB14.tmp
2009-04-16 23:12 . 2009-04-16 23:13 285184 —-a-w c:\windows\Internet Logs\xDB13.tmp
2009-04-15 00:05 . 2008-05-24 21:09 8383086 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-11 17:13 . 2009-04-11 17:14 2197504 —-a-w c:\windows\Internet Logs\xDB12.tmp
2009-04-04 16:57 . 2009-04-04 16:58 1690112 —-a-w c:\windows\Internet Logs\xDB11.tmp
2009-03-31 23:35 . 2009-03-31 23:36 2191872 —-a-w c:\windows\Internet Logs\xDB10.tmp
2009-03-06 14:22 . 2003-07-16 20:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-10-21 20:51 826368 —-a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-25_19.47.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-07-16 20:41 . 2009-05-25 19:49 39992 c:\windows\system32\perfc009.dat
+ 2003-07-16 20:41 . 2009-05-26 01:18 39992 c:\windows\system32\perfc009.dat
+ 2009-01-24 01:19 . 2009-05-26 01:15 313800 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2003-07-16 20:41 . 2009-05-26 01:18 311604 c:\windows\system32\perfh009.dat
- 2003-07-16 20:41 . 2009-05-25 19:49 311604 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-21 516440]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
D-link AirPlus G DWL-G120 Wireless USB.lnk - c:\program files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe [2006-1-6 241664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/21/2009 7:07 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]
.
Contents of the 'Scheduled Tasks' folder

2009-05-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 11:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\o6u7ojsr.default\
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-25 21:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2416)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-26 21:26
ComboFix-quarantined-files.txt 2009-05-26 01:25
ComboFix2.txt 2009-05-25 22:50
ComboFix3.txt 2009-05-25 19:53

Pre-Run: 29,240,786,944 bytes free
Post-Run: 29,230,067,712 bytes free

170 — E O F — 2009-05-14 22:14
and i ran the kaspersky and i believe i uploaded it as an attachment because i couldn't copy it.

Attachments:

Hi,

That looks much better. The items found by Kaspersky are either in quarantine or in an old system restore point which we will clean up soon.

Please do the following:

Launch your MalwareBytes AntiMalware program
  • Update the program to download the latest virus definitions
  • select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


Also post a fresh HJT log as well and describe how your computer is running now and if there are any outstanding issues.
Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 5.1.2600 Service Pack 3

5/26/2009 5:05:16 PM
mbam-log-2009-05-26 (17-05-16).txt

Scan type: Quick Scan
Objects scanned: 125049
Time elapsed: 4 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:07:21 PM, on 5/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Canon\BJCard\Bjmcmng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: D-link AirPlus G DWL-G120 Wireless USB.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/oneclickfix/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136593632451
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Program Files\Canon\BJCard\Bjmcmng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4253 bytes

computer is running great! The only thing that is different is that when you launch internet explorer, it opens in a small window. Then we maximize the window, and all is fine. Also, the wallpaper is gone on the desktop. It was a picture of my husband's kenworth, and now an older picture is on the desktop. Could it have been infected? We had it a long time.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI