This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] MSN virus link

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I'm sending some nice links on MSN, Thanks for your help. Very much appreciated:

Spam removed. Please don't post any more - Novi.

My old topic got locked due to inactivity, so I open a new one now. Thanks!

———————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:41:56, on 28.05.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programfiler\Bonjour\mDNSResponder.exe
C:\Programfiler\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Notebook Hardware Control\nhc.exe
C:\Programfiler\ESET\ESET NOD32 Antivirus\egui.exe
C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe
C:\Programfiler\iTunes\iTunesHelper.exe
C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\iPod\bin\iPodService.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Programfiler\Tele2 Mobile Partner\Tele2 Mobile Partner.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programfiler\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.no/sphome.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Programfiler\GetRight\xx2gr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Programfiler\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Programfiler\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Programfiler\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [egui] "C:\Programfiler\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] "C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Internet Explorer.lnk = C:\Programfiler\Internet Explorer\iexplore.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Internet Explorer.lnk = C:\Programfiler\Internet Explorer\iexplore.exe (User 'Default user')
O4 - Startup: Internet Explorer.lnk = C:\Programfiler\Internet Explorer\iexplore.exe
O8 - Extra context menu item: Download Links As… - file://C:\WINDOWS\system32\page.htm
O8 - Extra context menu item: Download Target(s) As… - file://C:\WINDOWS\system32\link.htm
O8 - Extra context menu item: Download with GetRight Pro - C:\Programfiler\GetRight\GRdownload.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Link to &MidpX - C:\Programfiler\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Programfiler\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5423B21-CB95-427E-986A-868BB2906C80}: NameServer = 193.216.1.9 193.216.69.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\FELLES~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programfiler\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programfiler\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Programfiler\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Programfiler\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Programfiler\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programfiler\Fellesfiler\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programfiler\Fellesfiler\Ahead\Lib\NMIndexingService.exe

–
End of file - 8042 bytes

————————————————-

Mbam log:

Malwarebytes' Anti-Malware 1.37
Databaseversjon: 2185
Windows 5.1.2600 Service Pack 2

27.05.2009 21:29:59
mbam-log-2009-05-27 (21-29-59).txt

Skanntype: Full Skann (C:\|)
Objekter skannet: 172411
Tid tilbakelagt: 1 hour(s), 27 minute(s), 33 second(s)

Minneprosesser infisert: 0
Minnemoduler infisert: 0
Registernøkler infisert: 3
Registerverdier infisert: 0
Registerfiler infisert: 2
Mapper infisert: 0
Filer infisert: 0

Minneprosesser infisert:
(Ingen mistenkelige filer funnet)

Minnemoduler infisert:
(Ingen mistenkelige filer funnet)

Registernøkler infisert:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.

Registerverdier infisert:
(Ingen mistenkelige filer funnet)

Registerfiler infisert:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Mapper infisert:
(Ingen mistenkelige filer funnet)

Filer infisert:
(Ingen mistenkelige filer funnet)

———————————————————


DDS file:


DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:34:57.47 on 28.05.2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_12
Microsoft Windows XP Professional 5.1.2600.2.1252.47.1044.18.510.184 [GMT 2:00]

AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programfiler\Bonjour\mDNSResponder.exe
C:\Programfiler\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Programfiler\Notebook Hardware Control\nhc.exe
C:\Programfiler\ESET\ESET NOD32 Antivirus\egui.exe
C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe
C:\Programfiler\iTunes\iTunesHelper.exe
C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Programfiler\Tele2 Mobile Partner\Tele2 Mobile Partner.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programfiler\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Master\Skrivebord\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.vg.no/
uSearch Bar = hxxp://search.msn.no/sphome.aspx
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programfiler\fellesfiler\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\programfiler\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\programfiler\getright\xx2gr.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programfiler\java\jre1.6.0_05\bin\ssv.dll
BHO: Påloggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programfiler\fellesfiler\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Kwyshell MidpX: {ebe9e2b5-b526-48bc-ad46-687263edcb0e} - c:\programfiler\kwyshell\midpx\jadinvoker\MidpInvoker.dll
TB: Kwyshell MidpX: {ebe9e2b5-b526-48bc-ad46-687263edcb0e} - c:\programfiler\kwyshell\midpx\jadinvoker\MidpInvoker.dll
uRun: [MsnMsgr] "c:\programfiler\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [NotebookHardwareControl] "c:\programfiler\notebook hardware control\nhc.exe" -quiet
mRun: [egui] "c:\programfiler\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [LVCOMSX] "c:\programfiler\fellesfiler\logishrd\lcommgr\LVComSX.exe"
mRun: [QuickTime Task] "c:\programfiler\quicktime alternative\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\programfiler\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\programfiler\adobe\reader 8.0\reader\Reader_sl.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\master\start-~1\progra~1\oppstart\intern~1.lnk - c:\programfiler\internet explorer\iexplore.exe
IE: Download Links As… - file://c:\windows\system32\page.htm
IE: Download Target(s) As… - file://c:\windows\system32\link.htm
IE: Download with GetRight Pro - c:\programfiler\getright\GRdownload.htm
IE: E&ksporter til Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Link to &MidpX - c:\programfiler\kwyshell\midpx\jadinvoker\extent\jad_wrap.htm
IE: Open with GetRight Pro Browser - c:\programfiler\getright\GRbrowse.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\programfiler\java\jre1.6.0_05\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\programfiler\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
TCP: {A5423B21-CB95-427E-986A-868BB2906C80} = 193.216.1.9 193.216.69.4
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\felles~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\DownloadMage - {99488E3C-CC26-4854-ABCD-9F462E1129F3} -
Name-Space Handler: http\DownloadMage - {99488E3C-CC26-4854-ABCD-9F462E1129F3} -

================= FIREFOX ===================

FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\programfiler\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");

============= SERVICES / DRIVERS ===============

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-7-1 34312]
R2 ekrn;Eset Service;c:\programfiler\eset\eset nod32 antivirus\ekrn.exe [2007-12-21 468224]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\programfiler\iolo\common\lib\ioloservicemanager.exe –> c:\programfiler\iolo\common\lib\ioloServiceManager.exe [?]
S2 ioloSystemService;iolo System Service;c:\programfiler\iolo\common\lib\ioloservicemanager.exe –> c:\programfiler\iolo\common\lib\ioloServiceManager.exe [?]
S3 hitmanpro3;Hitman Pro 3 Support Driver;\??\c:\windows\system32\drivers\hitmanpro3.sys –> c:\windows\system32\drivers\hitmanpro3.sys [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-10-27 7808]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\rtl8180.sys [2009-1-5 173184]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2009-2-24 32000]

============== File Associations ===============

JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2009-05-27 17:28 –d—– c:\docume~1\master\progra~1\Malwarebytes
2009-05-27 17:28 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-27 17:28 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-05-27 17:28 –d—– c:\docume~1\alluse~1.win\progra~1\Malwarebytes
2009-05-27 17:28 –d—– c:\programfiler\Malwarebytes' Anti-Malware
2009-05-26 19:46 –d—– C:\Virus removal
2009-05-14 18:30 –d—– c:\docume~1\alluse~1.win\progra~1\Hitman Pro
2009-05-14 18:30 –d—– c:\programfiler\Hitman Pro 3
2009-05-14 18:30 –d—– c:\docume~1\alluse~1.win\progra~1\Hitman Pro 3

==================== Find3M ====================

2009-05-28 17:31 22,528 a——- c:\windows\system32\drivers\nhcDriver.sys
2009-05-25 17:01 402,324 a——- c:\windows\system32\perfh014.dat
2009-05-25 17:01 68,462 a——- c:\windows\system32\perfc014.dat
2009-03-06 16:47 283,648 a——- c:\windows\system32\pdh.dll
2009-03-01 19:45 585,728 a——- c:\windows\system32\bsratswf.dll
2009-03-01 19:45 147,456 a——- c:\windows\system32\bsratwmv.dll
2009-03-01 19:35 2,048 a——- c:\windows\system32\Tr_sttool.dat
2008-01-27 22:45 32 a——- c:\docume~1\alluse~1.win\progra~1\ezsid.dat

============= FINISH: 17:35:49.50 ===============

Attachments:

Hi slasherkill,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 14

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
one problem now. the download stopped. and now it wont let me start a new download from the link I got from you! what to do now?
DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 17:02:10.89 on 06.06.2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_12 Microsoft Windows XP Professional 5.1.2600.2.1252.47.1044.18.510.114 [GMT 2:00] AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Programfiler\Bonjour\mDNSResponder.exe C:\Programfiler\ESET\ESET NOD32 Antivirus\ekrn.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Programfiler\Notebook Hardware Control\nhc.exe C:\Programfiler\ESET\ESET NOD32 Antivirus\egui.exe C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Programfiler\Windows Live\Messenger\usnsvc.exe C:\Documents and Settings\Master\Skrivebord\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.vg.no/ uSearch Bar = hxxp://search.msn.no/sphome.aspx uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programfiler\fellesfiler\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\programfiler\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\programfiler\getright\xx2gr.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programfiler\java\jre1.6.0_05\bin\ssv.dll BHO: Påloggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programfiler\fellesfiler\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Kwyshell MidpX: {ebe9e2b5-b526-48bc-ad46-687263edcb0e} - c:\programfiler\kwyshell\midpx\jadinvoker\MidpInvoker.dll TB: Kwyshell MidpX: {ebe9e2b5-b526-48bc-ad46-687263edcb0e} - c:\programfiler\kwyshell\midpx\jadinvoker\MidpInvoker.dll uRun: [MsnMsgr] "c:\programfiler\windows live\messenger\MsnMsgr.Exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ATIModeChange] Ati2mdxx.exe mRun: [NotebookHardwareControl] "c:\programfiler\notebook hardware control\nhc.exe" -quiet mRun: [egui] "c:\programfiler\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [LVCOMSX] "c:\programfiler\fellesfiler\logishrd\lcommgr\LVComSX.exe" mRun: [QuickTime Task] "c:\programfiler\quicktime alternative\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\programfiler\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\programfiler\adobe\reader 8.0\reader\Reader_sl.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\master\start-~1\progra~1\oppstart\intern~1.lnk - c:\programfiler\internet explorer\iexplore.exe IE: Download Links As… - file://c:\windows\system32\page.htm IE: Download Target(s) As… - file://c:\windows\system32\link.htm IE: Download with GetRight Pro - c:\programfiler\getright\GRdownload.htm IE: E&ksporter til Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000 IE: Link to &MidpX - c:\programfiler\kwyshell\midpx\jadinvoker\extent\jad_wrap.htm IE: Open with GetRight Pro Browser - c:\programfiler\getright\GRbrowse.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\programfiler\java\jre1.6.0_05\bin\ssv.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\programfiler\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office11\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\felles~1\skype\SKYPE4~1.DLL Name-Space Handler: ftp\DownloadMage - {99488E3C-CC26-4854-ABCD-9F462E1129F3} - Name-Space Handler: http\DownloadMage - {99488E3C-CC26-4854-ABCD-9F462E1129F3} - ================= FIREFOX =================== FF - ProfilePath - —- FIREFOX POLICIES —- c:\programfiler\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); ============= SERVICES / DRIVERS =============== R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-7-1 34312] R3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\rtl8180.sys [2009-1-5 173184] S3 hitmanpro3;Hitman Pro 3 Support Driver;\??\c:\windows\system32\drivers\hitmanpro3.sys –> c:\windows\system32\drivers\hitmanpro3.sys [?] S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-10-27 7808] S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2009-2-24 32000] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-06-02 21:52 –d—– c:\documents and settings\master\.SunDownloadManager 2009-05-27 17:28 –d—– c:\docume~1\master\progra~1\Malwarebytes 2009-05-27 17:28 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-27 17:28 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-05-27 17:28 –d—– c:\docume~1\alluse~1.win\progra~1\Malwarebytes 2009-05-27 17:28 –d—– c:\programfiler\Malwarebytes' Anti-Malware 2009-05-26 19:46 –d—– C:\Virus removal 2009-05-14 18:30 –d—– c:\docume~1\alluse~1.win\progra~1\Hitman Pro 2009-05-14 18:30 –d—– c:\programfiler\Hitman Pro 3 2009-05-14 18:30 –d—– c:\docume~1\alluse~1.win\progra~1\Hitman Pro 3 ==================== Find3M ==================== 2009-06-06 16:54 22,528 a——- c:\windows\system32\drivers\nhcDriver.sys 2009-05-25 17:01 402,324 a——- c:\windows\system32\perfh014.dat 2009-05-25 17:01 68,462 a——- c:\windows\system32\perfc014.dat 2008-01-27 22:45 32 a——- c:\docume~1\alluse~1.win\progra~1\ezsid.dat ============= FINISH: 17:04:13.25 ===============
Rooter: Microsoft Windows XP Professional (5.1.2600) Service Pack 2 C:\ [Fixed] - NTFS - (Total:38146 Mo/Free:1631 Mo) D:\ [CD-Rom] (Total:12 Mo/Free:0 Mo) E:\ [Removable] (Total:0 Mo/Free:0 Mo) 08.06.2009|17:19 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\Ati2evxx.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\Programfiler\Notebook Hardware Control\nhc.exe ———- C:\Programfiler\ESET\ESET NOD32 Antivirus\egui.exe ———- C:\Programfiler\Fellesfiler\LogiShrd\LComMgr\LVComSX.exe ———- C:\Programfiler\iTunes\iTunesHelper.exe ———- C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Programfiler\Internet Explorer\iexplore.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ———- C:\Programfiler\Bonjour\mDNSResponder.exe ———- C:\Programfiler\ESET\ESET NOD32 Antivirus\ekrn.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\wdfmgr.exe ———- C:\Programfiler\iPod\bin\iPodService.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\system32\wuauclt.exe ———- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe ———- C:\Programfiler\Tele2 Mobile Partner\Tele2 Mobile Partner.exe ———- C:\Programfiler\Windows Live\Messenger\usnsvc.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! ———————-\\ Cracks & Keygens.. C:\DOCUME~1\Master\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\61UD898H\Microsoft-Office-2007-Keygenand33-t36213[1].htm C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\win32\802ether.exe C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\win32\aircrack.exe C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\win32\airodump.exe C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\win32\wzcook.exe C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\ALS_100combo.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\combo.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\girlname.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\guyname.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\log000.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\password.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\password1.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack\wordlist.txt C:\DOCUME~1\Master\Mine dokumenter\Hack\Rapidshare\rapidshare.depremiumaccountgeneratorcrack\rh_SOFTARCHIVE.NET\RapidshareHacking.exe 1 - "C:\Rooter$\Rooter_1.txt" - 08.06.2009|17:22 ———————-\\ Scan completed at 17:22
slasherkill,

Well… I think we've found why your infected. You download hacks and cracks.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\DOCUME~1\Master\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\61UD898H\Microsoft-Office-2007-Keygenand33-t36213[1].htm
    C:\DOCUME~1\Master\Mine dokumenter\Hack
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
========== PROCESSES ========== Process explorer.exe killed successfully. ========== FILES ========== C:\DOCUME~1\Master\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\61UD898H\Microsoft-Office-2007-Keygenand33-t36213[1].htm moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\wwwhack\cache moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\wwwhack moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Wordlist moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\spoof moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\rpc412 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Rapidshare\rapidshare.depremiumaccountgeneratorcrack\rh_SOFTARCHIVE.NET moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Rapidshare\rapidshare.depremiumaccountgeneratorcrack moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Rapidshare\RapidShare Time Resetter moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Rapidshare moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Proxylist moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Proxy list checking\filterfiles moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Proxy list checking moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\newwwwhack\Kenna moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\newwwwhack\cache moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\newwwwhack moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\john-16w\john-16\run moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\john-16w\john-16\doc moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\john-16w\john-16 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\john-16w moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\hackWebCrack moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\ALS_Novice moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\win32 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1\docs moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1\aircrack-2.1 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\aircrack-2.1 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Wordlist moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Template moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Sounds moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Options moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\IP2Country moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\GFX\Banners moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\GFX moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\WORDS moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\WLeechStorage moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\WeakDebug moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\URL\Patterns moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\URL moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\Temp moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\SnapShots moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\ProxyStates moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\ProxyHunter moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\PPUB moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\Leecher moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\JOBLog moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\FORMDebug moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache\CodeLog moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver\Cache moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\Accessdiver moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\3D Traceroute 1.6\CACHE moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack\3D Traceroute 1.6 moved successfully. C:\DOCUME~1\Master\Mine dokumenter\Hack moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\TMP16.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\TMP3C4.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF3CA1.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF4FC4.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF52EA.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF5F1A.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF6131.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\SJRQ32JL\ToastFull[3].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\SJRQ32JL\ToastMini[3].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\N29UIO4O\rtm[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\N1B0ZRNP\=GL_MetaViewWatchSearch_9800;seg=GL_MetaViewWatchSearch_293;seg=GL_MetaView WatchSearch_58058;sz=728x90;ord=1244475428044;dcopt=ist;tile=1;um=2;us=11;[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\KZXKV7BG\MSN_virus_link_t103531[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\KHQRSXY3\- A1 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\K16N45QR\- B1 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\eBayISAPI[5].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\iframe[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\notify[1].wav scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\EDQL8AH1\Default[5].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\CF3Z6W9T\- A1 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\BUMJLD9Q\eBayISAPI[6].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\BUMJLD9Q\eBayISAPI[7].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\8XQ3OH6F\- A1 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\89SBUDEX\- B2 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\6G2NP9JP\openhand_8_8[1].bmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\5R3355KA\- B1 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\543PC8DX\maps[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\default[6].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\eBayISAPI[4].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\home3[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\im[4].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3WBPF4VT\8to29;seg=GL_MetaViewWatchSearch_9800;seg=GL_MetaViewWatchSearch_293;seg=GL _MetaViewWatchSearch_58058;sz=160x600;ord=1244475428044;tile=2;um=2;us=11;[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3WBPF4VT\InboxLight[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3BY0SP09\index[4].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTM by OldTimer - Version 2.1.0.0 log created on 06082009_215745 Files moved on Reboot… C:\DOCUME~1\Master\LOKALE~1\Temp\TMP16.tmp moved successfully. C:\DOCUME~1\Master\LOKALE~1\Temp\TMP3C4.tmp moved successfully. C:\DOCUME~1\Master\LOKALE~1\Temp\~DF3CA1.tmp moved successfully. File C:\DOCUME~1\Master\LOKALE~1\Temp\~DF4FC4.tmp not found! File C:\DOCUME~1\Master\LOKALE~1\Temp\~DF52EA.tmp not found! File C:\DOCUME~1\Master\LOKALE~1\Temp\~DF5F1A.tmp not found! File C:\DOCUME~1\Master\LOKALE~1\Temp\~DF6131.tmp not found! C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\SJRQ32JL\ToastFull[3].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\SJRQ32JL\ToastMini[3].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\N29UIO4O\rtm[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\N1B0ZRNP\=GL_MetaViewWatchSearch_9800;seg=GL_MetaViewWatchSearch_293;seg=GL_MetaView WatchSearch_58058;sz=728x90;ord=1244475428044;dcopt=ist;tile=1;um=2;us=11;[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\KZXKV7BG\MSN_virus_link_t103531[2].htm moved successfully. File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\KHQRSXY3\- A1 not found! File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\K16N45QR\- B1 not found! C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\eBayISAPI[5].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\iframe[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\I0BQ7HV9\notify[1].wav moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\EDQL8AH1\Default[5].htm moved successfully. File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\CF3Z6W9T\- A1 not found! C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\BUMJLD9Q\eBayISAPI[6].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\BUMJLD9Q\eBayISAPI[7].htm moved successfully. File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\8XQ3OH6F\- A1 not found! File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\89SBUDEX\- B2 not found! C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\6G2NP9JP\openhand_8_8[1].bmp moved successfully. File C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\5R3355KA\- B1 not found! C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\543PC8DX\maps[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\default[6].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\eBayISAPI[4].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\home3[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\4TM37LJY\im[4].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3WBPF4VT\8to29;seg=GL_MetaViewWatchSearch_9800;seg=GL_MetaViewWatchSearch_293;seg=GL _MetaViewWatchSearch_58058;sz=160x600;ord=1244475428044;tile=2;um=2;us=11;[1].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3WBPF4VT\InboxLight[2].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\Content.IE5\3BY0SP09\index[4].htm moved successfully. C:\Documents and Settings\Master\Lokale innstillinger\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully. Registry entries deleted on Reboot…
slasherkill,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
One problem: You need to install Java version 1.5 or later to run Kaspersky Online Scanner 7.0. It did not download fully last time. So I asked for a new link. Could you give me one? Or tell me what to do? As the last link does not work anymore.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI