This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] A little help

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

recently my computer has been acting strange, it's like when your body is sick even if you can't describe some of the symptoms you just feel like something isn't right. then my search started messing up, redirecting me constantly. for no reason at all my computer began crashing to a blue screen, i didnt understand most of what was on it but it referenced that it could be due to new software/hardware. i actually did uninstall the recent software that i had installed, but to no avail. now every time i run world of warcraft, about 30 seconds after logging in it crashes. i assume wow isnt actually the cause because it definitely isnt new software. i installed that last update more than a month ago i believe, and this just started this week. anything you guys can do to help would be greatly appreciated. i probably won't be back on here until around midnight im leaving for work so hopefully ill have some instructions when i get back. thanks.



okay so i ran malware bytes once and it removed several things. here is that log.


Malwarebytes' Anti-Malware 1.38
Database version: 2335
Windows 5.1.2600 Service Pack 2

6/25/2009 5:16:44 PM
mbam-log-2009-06-25 (17-16-38).txt

Scan type: Quick Scan
Objects scanned: 89214
Time elapsed: 2 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{ca68f5c4-08ab-412f-a9a0-6aa2441bf62d} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ca68f5c4-08ab-412f-a9a0-6aa2441bf62d} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca68f5c4-08ab-412f-a9a0-6aa2441bf62d} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Rootkit.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ftnet2k (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ftnet2k (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ftnet2k (Trojan.Agent) -> No action taken.

Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Worm.Autorun) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ftn2ksv (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\config\systemprofile\protect.dll (Worm.Autorun) -> No action taken.
c:\WINDOWS\system32\ak1.exe (Spyware.OnlineGames) -> No action taken.
c:\WINDOWS\system32\loader266.exe (Rogue.Installer) -> No action taken.
c:\WINDOWS\system32\rn.tmp (Trojan.Downloader) -> No action taken.
c:\WINDOWS\system32\winglsetup.exe (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ftn2ksv.exe (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\ovfsthktifmnceqhbyvqdleonqltoiqnqscmfo.dat (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\ovfsthsurpvnhjtdrivskpvpkxbrhsqakilbrw.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\nefapifa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yazowazo.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\msonlinebb.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\ruwamumi.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\zoyokuvu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\drivers\ftnet2k.sys (Trojan.Agent) -> No action taken.

after the restart i ran it again and here is that log.

Malwarebytes' Anti-Malware 1.38
Database version: 2335
Windows 5.1.2600 Service Pack 2

6/25/2009 5:34:25 PM
mbam-log-2009-06-25 (17-34-25).txt

Scan type: Quick Scan
Objects scanned: 89217
Time elapsed: 2 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)







here's my hijackthis log after the 2nd run of malware bytes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:33:50 PM, on 6/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6071210
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [busilayevu] Rundll32.exe "C:\WINDOWS\system32\giwoluju.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [busilayevu] Rundll32.exe "C:\WINDOWS\system32\giwoluju.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\vl1de6yt.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\vl1de6yt.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} (Enlite 2.x Simulation Engine Installer) - http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\zodihuri.dll,C:\WINDOWS\system32\hegohami.dll c:\windows\system32\nuvujori.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

–
End of file - 9087 bytes
Hi,

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please disable Symantec via the System Tray.

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
okay here is the combofix log

ComboFix 09-06-26.02 - Jeremy 06/26/2009 15:28.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1013.642 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Mozilla Firefox\extensions\{FD1DC027-54DD-4E79-91B5-1D4B9A9E4F6B}
c:\program files\Mozilla Firefox\extensions\{FD1DC027-54DD-4E79-91B5-1D4B9A9E4F6B}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{FD1DC027-54DD-4E79-91B5-1D4B9A9E4F6B}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{FD1DC027-54DD-4E79-91B5-1D4B9A9E4F6B}\install.rdf
c:\windows\system32\bvrlrf.dll
c:\windows\system32\drivers\SKYNETyfydenpa.sys
c:\windows\system32\hubahoro.dll
c:\windows\system32\jaheyuva.dll
c:\windows\system32\rivuvabo.dll
c:\windows\system32\simageme.dll
c:\windows\system32\SKYNETbalkkwyu.dll
c:\windows\system32\SKYNETlcfexbwk.dat
c:\windows\system32\SKYNETtpyxdpmu.dll
c:\windows\system32\SKYNETuhedjsrl.dat
c:\windows\system32\sodujele.dll
c:\windows\system32\tinomejo.dll
c:\windows\system32\ulesuvuj.ini
c:\windows\system32\wunibuhi.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETyrqjdskk
——-\Service_ovfsthwyahilucaxtobwhnnnrfjonwljkifnfs


((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-06-26 )))))))))))))))))))))))))))))))
.

2009-06-25 21:53 . 2009-06-25 21:53 ——– d—–w- c:\program files\ERUNT
2009-06-16 08:30 . 2009-06-16 09:51 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\FullTiltPoker
2009-06-16 08:29 . 2009-06-25 21:30 ——– d—–w- c:\program files\Full Tilt Poker
2009-06-07 20:13 . 2009-06-07 20:13 ——– d—–w- c:\program files\STOPzilla!
2009-05-30 03:47 . 2009-06-25 22:31 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\CurseClient
2009-05-30 03:46 . 2009-05-30 03:46 ——– d—–w- c:\program files\Curse
2009-05-28 19:16 . 2009-05-28 19:16 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-05-28 19:15 . 2009-05-28 19:15 294912 —-a-r- c:\windows\system32\SZBase5.dll
2009-05-28 19:14 . 2009-05-28 19:14 540672 —-a-r- c:\windows\system32\SZComp5.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 20:33 . 2007-12-25 02:21 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-26 20:33 . 2008-07-09 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-06-25 22:12 . 2009-01-13 18:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-25 22:12 . 2009-01-20 15:45 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 21:31 . 2007-12-27 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-25 21:31 . 2008-08-25 03:30 ——– d—–w- c:\program files\Viewpoint
2009-06-25 21:31 . 2007-12-10 06:04 ——– d—–w- c:\program files\CyberLink
2009-06-25 21:31 . 2007-12-10 05:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-25 21:28 . 2008-07-09 19:58 ——– d—–w- c:\program files\Diablo II
2009-06-17 16:27 . 2009-01-13 18:44 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2009-01-13 18:44 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 03:39 . 2007-12-25 03:19 ——– d—–w- c:\program files\World of Warcraft
2009-05-19 03:03 . 2008-07-09 01:24 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2009-05-12 19:13 . 2009-05-12 19:13 61328 —-a-r- c:\windows\system32\drivers\SZKG.sys
2009-03-11 14:18 . 2009-03-11 14:18 2098 –sh–w- c:\windows\system32\badufega.dll
2009-03-15 14:37 . 2009-03-15 14:37 2098 –sh–w- c:\windows\system32\basibezo.dll
2009-03-09 02:17 . 2009-03-09 02:17 2098 –sh–w- c:\windows\system32\biranoma.dll
2009-03-08 02:16 . 2009-03-08 02:16 2098 –sh–w- c:\windows\system32\bokabero.dll
2009-03-16 02:37 . 2009-03-16 02:37 2098 –sh–w- c:\windows\system32\dezupiye.dll
2009-03-24 09:49 . 2009-03-24 09:49 2098 –sh–w- c:\windows\system32\dikijowa.exe
2009-03-09 14:17 . 2009-03-09 14:17 2098 –sh–w- c:\windows\system32\dikutime.dll
2009-03-09 02:17 . 2009-03-09 02:17 2098 –sh–w- c:\windows\system32\duloteko.dll
2009-03-08 14:16 . 2009-03-08 14:16 2098 –sh–w- c:\windows\system32\fugopuno.dll
2009-03-15 02:37 . 2009-03-15 02:37 2098 –sh–w- c:\windows\system32\furoyuwe.dll
2009-03-10 02:17 . 2009-03-10 02:17 2098 –sh–w- c:\windows\system32\gapiyivi.dll
2009-03-08 02:16 . 2009-03-08 02:16 2098 –sh–w- c:\windows\system32\genohije.dll
2009-03-08 02:16 . 2009-03-08 02:16 2098 –sh–w- c:\windows\system32\gizitefo.dll
2009-03-16 14:38 . 2009-03-16 14:38 2098 –sh–w- c:\windows\system32\goluwuwe.dll
2009-03-15 14:37 . 2009-03-15 14:37 2098 –sh–w- c:\windows\system32\gosotopu.dll
2009-03-10 02:17 . 2009-03-10 02:17 2098 –sh–w- c:\windows\system32\hewalote.dll
2009-03-11 14:18 . 2009-03-11 14:18 2098 –sh–w- c:\windows\system32\hewipali.dll
2009-03-25 03:50 . 2009-03-25 03:50 2098 –sh–w- c:\windows\system32\hodeheba.exe
2009-03-11 14:18 . 2009-03-11 14:18 2098 –sh–w- c:\windows\system32\huvizuba.dll
2009-03-06 02:15 . 2009-03-06 02:15 2098 –sh–w- c:\windows\system32\javisenu.dll
2009-03-13 02:18 . 2009-03-13 02:18 2098 –sh–w- c:\windows\system32\jekegoke.dll
2009-03-10 14:17 . 2009-03-10 14:17 2098 –sh–w- c:\windows\system32\juhumuyo.dll
2009-03-06 14:15 . 2009-03-06 14:15 2098 –sh–w- c:\windows\system32\kawuruji.dll
2009-03-12 14:18 . 2009-03-12 14:18 2098 –sh–w- c:\windows\system32\kazovovi.dll
2009-03-21 20:45 . 2009-03-21 20:45 2098 –sh–w- c:\windows\system32\kisebuyu.exe
2009-03-21 02:44 . 2009-03-21 02:44 2098 –sh–w- c:\windows\system32\kovibele.exe
2009-03-15 02:37 . 2009-03-15 02:37 2098 –sh–w- c:\windows\system32\kusumiwi.dll
2009-03-07 14:16 . 2009-03-07 14:16 2098 –sh–w- c:\windows\system32\lemowate.dll
2009-03-07 14:16 . 2009-03-07 14:16 2098 –sh–w- c:\windows\system32\lubiguwi.dll
2009-03-08 14:16 . 2009-03-08 14:16 2098 –sh–w- c:\windows\system32\mapodaba.dll
2009-03-11 02:17 . 2009-03-11 02:17 2098 –sh–w- c:\windows\system32\marotiri.dll
2009-03-17 02:43 . 2009-03-17 02:43 75244 –sha-w- c:\windows\system32\moyomego.dll
2009-03-18 14:43 . 2009-03-18 14:43 2098 –sh–w- c:\windows\system32\nepodolu.exe
2009-03-12 14:18 . 2009-03-12 14:18 2098 –sh–w- c:\windows\system32\niketota.dll
2009-03-23 15:48 . 2009-03-23 15:48 2098 –sh–w- c:\windows\system32\nobetalu.exe
2009-03-12 02:18 . 2009-03-12 02:18 2098 –sh–w- c:\windows\system32\nohijubi.dll
2009-03-07 02:16 . 2009-03-07 02:16 2098 –sh–w- c:\windows\system32\patevape.dll
2009-03-06 02:15 . 2009-03-06 02:15 2098 –sh–w- c:\windows\system32\pemukevu.dll
2009-03-17 20:42 . 2009-03-17 20:42 2098 –sh–w- c:\windows\system32\penosika.exe
2009-03-12 14:18 . 2009-03-12 14:18 2098 –sh–w- c:\windows\system32\pigirayo.dll
2009-03-08 14:16 . 2009-03-08 14:16 2098 –sh–w- c:\windows\system32\redutuye.dll
2009-03-11 02:17 . 2009-03-11 02:17 2098 –sh–w- c:\windows\system32\rehenano.dll
2009-03-07 14:16 . 2009-03-07 14:16 2098 –sh–w- c:\windows\system32\rehikuru.dll
2009-03-12 02:18 . 2009-03-12 02:18 2098 –sh–w- c:\windows\system32\ritimubu.dll
2009-03-09 14:17 . 2009-03-09 14:17 2098 –sh–w- c:\windows\system32\sefinemu.dll
2009-03-20 08:42 . 2009-03-20 08:42 2098 –sh–w- c:\windows\system32\segaleni.exe
2009-03-06 14:15 . 2009-03-06 14:15 2098 –sh–w- c:\windows\system32\sohirobe.dll
2009-03-16 02:37 . 2009-03-16 02:37 2098 –sh–w- c:\windows\system32\tatoyame.dll
2009-03-15 02:37 . 2009-03-15 02:37 2098 –sh–w- c:\windows\system32\tawulani.dll
2009-03-06 02:15 . 2009-03-06 02:15 2098 –sh–w- c:\windows\system32\tobogibi.dll
2009-03-07 02:16 . 2009-03-07 02:16 2098 –sh–w- c:\windows\system32\vakefiyo.dll
2009-03-16 14:38 . 2009-03-16 14:38 2098 –sh–w- c:\windows\system32\vetagama.dll
2009-03-13 02:18 . 2009-03-13 02:18 2098 –sh–w- c:\windows\system32\vubumega.dll
2009-03-10 14:17 . 2009-03-10 14:17 2098 –sh–w- c:\windows\system32\wirahahe.dll
2009-03-13 02:18 . 2009-03-13 02:18 2098 –sh–w- c:\windows\system32\wuputile.dll
2009-03-16 14:38 . 2009-03-16 14:38 2098 –sh–w- c:\windows\system32\yalomito.dll
2009-03-16 02:37 . 2009-03-16 02:37 2098 –sh–w- c:\windows\system32\yenafute.dll
2009-03-06 14:15 . 2009-03-06 14:15 2098 –sh–w- c:\windows\system32\yurowebo.dll
2009-03-15 14:37 . 2009-03-15 14:37 2098 –sh–w- c:\windows\system32\zavegasa.dll
2009-03-09 02:17 . 2009-03-09 02:17 2098 –sh–w- c:\windows\system32\zeguyezo.dll
2009-03-07 02:16 . 2009-03-07 02:16 2098 –sh–w- c:\windows\system32\zetonadu.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 84640]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-09-06 26248]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-29 136600]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-26 16132608]

c:\documents and settings\Jeremy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\Symantec Shared\\AppCore\\AppSvc32.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/25/2007 2:30 PM 112688]
.
Contents of the 'Scheduled Tasks' folder

2009-06-20 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Jeremy.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-09-07 06:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
Trusted Zone: aol.com\kdc.uas
FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\4h69vi0i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-26 15:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(768)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\savedump.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
.
**************************************************************************
.
Completion time: 2009-06-26 15:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-26 20:36

Pre-Run: 199,920,480,256 bytes free
Post-Run: 199,866,978,304 bytes free

212 — E O F — 2008-07-07 00:25


and here is the new hjt log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:37:52 PM, on 6/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6071210
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1245991674359
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} (Enlite 2.x Simulation Engine Installer) - http://myitlab.pearsoned.com/Pegasus/Modul…ces/ax/stub.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

–
End of file - 8593 bytes


thanks for this it is greatly appreciated. let me know if there's more i need to do. im off to work again so ill be back on around 1 am to check and see.
there you go man Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 8.1.0 Adobe Shockwave Player AppCore Apple Software Update AutoUpdate AV ccCommon Conexant D850 56K V.9x DFVc Modem Curse Client Dell DataSafe Online Dell Driver Reset Tool Dell Resource CD Dell System Restore Digital Line Detect DivX Codec DivX Converter DivX Player DivX Web Player Documentation & Support Launcher ERUNT 1.1j ESET Online Scanner FoxyTunes for Firefox Games, Music, & Photos Launcher High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Internet Service Offers Launcher Java™ 6 Update 11 LiveUpdate Notice (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Software Update for Web Folders (English) 12 Microsoft Works Modem Diagnostic Tool Mozilla ActiveX Control v1.7.12 Mozilla Firefox (3.0.5) MSRedist MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) NetWaiting Norton AntiVirus Norton Confidential Browser Component Norton Confidential Web Protection Component Norton Internet Security Norton Internet Security (Symantec Corporation) Norton Protection Center QuickTime Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler Roxio MyDVD DE Roxio Update Manager Security Update for Step By Step Interactive Training (KB923723) Sonic Activation Module SPBBC 32bit STOPzilla Symantec Real Time Storage Protection Component SymNet WebFldrs XP Windows Media Format Runtime Windows Media Player 10 WinRAR archiver World of Warcraft
Hi, thanks for that.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.whatthetech.com/little_help_t104530.html

Collect::
c:\windows\system32\badufega.dll
c:\windows\system32\basibezo.dll
c:\windows\system32\biranoma.dll
c:\windows\system32\bokabero.dll
c:\windows\system32\dezupiye.dll
c:\windows\system32\dikijowa.exe
c:\windows\system32\dikutime.dll
c:\windows\system32\duloteko.dll
c:\windows\system32\fugopuno.dll
c:\windows\system32\furoyuwe.dll
c:\windows\system32\gapiyivi.dll
c:\windows\system32\genohije.dll
c:\windows\system32\gizitefo.dll
c:\windows\system32\goluwuwe.dll
c:\windows\system32\gosotopu.dll
c:\windows\system32\hewalote.dll
c:\windows\system32\hewipali.dll
c:\windows\system32\hodeheba.exe
c:\windows\system32\huvizuba.dll
c:\windows\system32\javisenu.dll
c:\windows\system32\jekegoke.dll
c:\windows\system32\juhumuyo.dll
c:\windows\system32\kawuruji.dll
c:\windows\system32\kazovovi.dll
c:\windows\system32\kisebuyu.exe
c:\windows\system32\kovibele.exe
c:\windows\system32\kusumiwi.dll
c:\windows\system32\lemowate.dll
c:\windows\system32\lubiguwi.dll
c:\windows\system32\mapodaba.dll
c:\windows\system32\marotiri.dll
c:\windows\system32\moyomego.dll
c:\windows\system32\nepodolu.exe
c:\windows\system32\niketota.dll
c:\windows\system32\nobetalu.exe
c:\windows\system32\nohijubi.dll
c:\windows\system32\patevape.dll
c:\windows\system32\pemukevu.dll
c:\windows\system32\penosika.exe
c:\windows\system32\pigirayo.dll
c:\windows\system32\redutuye.dll
c:\windows\system32\rehenano.dll
c:\windows\system32\rehikuru.dll
c:\windows\system32\ritimubu.dll
c:\windows\system32\sefinemu.dll
c:\windows\system32\segaleni.exe
c:\windows\system32\sohirobe.dll
c:\windows\system32\tatoyame.dll
c:\windows\system32\tawulani.dll
c:\windows\system32\tobogibi.dll
c:\windows\system32\vakefiyo.dll
c:\windows\system32\vetagama.dll
c:\windows\system32\vubumega.dll
c:\windows\system32\wirahahe.dll
c:\windows\system32\wuputile.dll
c:\windows\system32\yalomito.dll
c:\windows\system32\yenafute.dll
c:\windows\system32\yurowebo.dll
c:\windows\system32\zavegasa.dll
c:\windows\system32\zeguyezo.dll
c:\windows\system32\zetonadu.dll

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\drivers\\svchost.exe"=-

FileLook::
c:\windows\system32\drivers\SZKG.sys
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt.

Please update your Java, then run the following online scan.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know how things are running now.
okay here's the new combofix

ComboFix 09-06-26.02 - Jeremy 06/28/2009 16:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1013.717 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeremy\Desktop\CFScript.txt

file zipped: c:\windows\system32\badufega.dll
file zipped: c:\windows\system32\basibezo.dll
file zipped: c:\windows\system32\biranoma.dll
file zipped: c:\windows\system32\bokabero.dll
file zipped: c:\windows\system32\dezupiye.dll
file zipped: c:\windows\system32\dikijowa.exe
file zipped: c:\windows\system32\dikutime.dll
file zipped: c:\windows\system32\duloteko.dll
file zipped: c:\windows\system32\fugopuno.dll
file zipped: c:\windows\system32\furoyuwe.dll
file zipped: c:\windows\system32\gapiyivi.dll
file zipped: c:\windows\system32\genohije.dll
file zipped: c:\windows\system32\gizitefo.dll
file zipped: c:\windows\system32\goluwuwe.dll
file zipped: c:\windows\system32\gosotopu.dll
file zipped: c:\windows\system32\hewalote.dll
file zipped: c:\windows\system32\hewipali.dll
file zipped: c:\windows\system32\hodeheba.exe
file zipped: c:\windows\system32\huvizuba.dll
file zipped: c:\windows\system32\javisenu.dll
file zipped: c:\windows\system32\jekegoke.dll
file zipped: c:\windows\system32\juhumuyo.dll
file zipped: c:\windows\system32\kawuruji.dll
file zipped: c:\windows\system32\kazovovi.dll
file zipped: c:\windows\system32\kisebuyu.exe
file zipped: c:\windows\system32\kovibele.exe
file zipped: c:\windows\system32\kusumiwi.dll
file zipped: c:\windows\system32\lemowate.dll
file zipped: c:\windows\system32\lubiguwi.dll
file zipped: c:\windows\system32\mapodaba.dll
file zipped: c:\windows\system32\marotiri.dll
file zipped: c:\windows\system32\moyomego.dll
file zipped: c:\windows\system32\nepodolu.exe
file zipped: c:\windows\system32\niketota.dll
file zipped: c:\windows\system32\nobetalu.exe
file zipped: c:\windows\system32\nohijubi.dll
file zipped: c:\windows\system32\patevape.dll
file zipped: c:\windows\system32\pemukevu.dll
file zipped: c:\windows\system32\penosika.exe
file zipped: c:\windows\system32\pigirayo.dll
file zipped: c:\windows\system32\redutuye.dll
file zipped: c:\windows\system32\rehenano.dll
file zipped: c:\windows\system32\rehikuru.dll
file zipped: c:\windows\system32\ritimubu.dll
file zipped: c:\windows\system32\sefinemu.dll
file zipped: c:\windows\system32\segaleni.exe
file zipped: c:\windows\system32\sohirobe.dll
file zipped: c:\windows\system32\tatoyame.dll
file zipped: c:\windows\system32\tawulani.dll
file zipped: c:\windows\system32\tobogibi.dll
file zipped: c:\windows\system32\vakefiyo.dll
file zipped: c:\windows\system32\vetagama.dll
file zipped: c:\windows\system32\vubumega.dll
file zipped: c:\windows\system32\wirahahe.dll
file zipped: c:\windows\system32\wuputile.dll
file zipped: c:\windows\system32\yalomito.dll
file zipped: c:\windows\system32\yenafute.dll
file zipped: c:\windows\system32\yurowebo.dll
file zipped: c:\windows\system32\zavegasa.dll
file zipped: c:\windows\system32\zeguyezo.dll
file zipped: c:\windows\system32\zetonadu.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\badufega.dll
c:\windows\system32\basibezo.dll
c:\windows\system32\biranoma.dll
c:\windows\system32\bokabero.dll
c:\windows\system32\dezupiye.dll
c:\windows\system32\dikijowa.exe
c:\windows\system32\dikutime.dll
c:\windows\system32\drivers\SKYNETjetkdwqi.sys
c:\windows\system32\duloteko.dll
c:\windows\system32\fugopuno.dll
c:\windows\system32\furoyuwe.dll
c:\windows\system32\gapiyivi.dll
c:\windows\system32\genohije.dll
c:\windows\system32\gizitefo.dll
c:\windows\system32\goluwuwe.dll
c:\windows\system32\gosotopu.dll
c:\windows\system32\hewalote.dll
c:\windows\system32\hewipali.dll
c:\windows\system32\hodeheba.exe
c:\windows\system32\huvizuba.dll
c:\windows\system32\javisenu.dll
c:\windows\system32\jekegoke.dll
c:\windows\system32\juhumuyo.dll
c:\windows\system32\kawuruji.dll
c:\windows\system32\kazovovi.dll
c:\windows\system32\kisebuyu.exe
c:\windows\system32\kovibele.exe
c:\windows\system32\kusumiwi.dll
c:\windows\system32\lemowate.dll
c:\windows\system32\lubiguwi.dll
c:\windows\system32\mapodaba.dll
c:\windows\system32\marotiri.dll
c:\windows\system32\moyomego.dll
c:\windows\system32\nepodolu.exe
c:\windows\system32\niketota.dll
c:\windows\system32\nobetalu.exe
c:\windows\system32\nohijubi.dll
c:\windows\system32\patevape.dll
c:\windows\system32\pemukevu.dll
c:\windows\system32\penosika.exe
c:\windows\system32\pigirayo.dll
c:\windows\system32\redutuye.dll
c:\windows\system32\rehenano.dll
c:\windows\system32\rehikuru.dll
c:\windows\system32\ritimubu.dll
c:\windows\system32\sefinemu.dll
c:\windows\system32\segaleni.exe
c:\windows\system32\SKYNETnmfwxbfp.dat
c:\windows\system32\SKYNETntymothe.dll
c:\windows\system32\SKYNETpyxenill.dll
c:\windows\system32\SKYNETxuxxvrev.dat
c:\windows\system32\sohirobe.dll
c:\windows\system32\tatoyame.dll
c:\windows\system32\tawulani.dll
c:\windows\system32\tobogibi.dll
c:\windows\system32\vakefiyo.dll
c:\windows\system32\vetagama.dll
c:\windows\system32\vubumega.dll
c:\windows\system32\wirahahe.dll
c:\windows\system32\wuputile.dll
c:\windows\system32\yalomito.dll
c:\windows\system32\yenafute.dll
c:\windows\system32\yurowebo.dll
c:\windows\system32\zavegasa.dll
c:\windows\system32\zeguyezo.dll
c:\windows\system32\zetonadu.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETpfvkosrr


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
.

2009-06-28 02:38 . 2009-06-28 02:38 152576 —-a-w- c:\documents and settings\Jeremy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-26 20:35 . 2009-06-26 20:35 ——– dc—-w- c:\windows\system32\dllcache\cache
2009-06-25 21:53 . 2009-06-25 21:53 ——– d—–w- c:\program files\ERUNT
2009-06-16 08:30 . 2009-06-16 09:51 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\FullTiltPoker
2009-06-16 08:29 . 2009-06-25 21:30 ——– d—–w- c:\program files\Full Tilt Poker
2009-06-07 20:13 . 2009-06-07 20:13 ——– d—–w- c:\program files\STOPzilla!
2009-05-30 03:47 . 2009-06-25 22:31 ——– d—–w- c:\documents and settings\Jeremy\Local Settings\Application Data\CurseClient
2009-05-30 03:46 . 2009-05-30 03:46 ——– d—–w- c:\program files\Curse

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 21:16 . 2008-07-09 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-06-28 21:16 . 2009-06-27 06:26 1120 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-06-28 21:16 . 2009-06-27 09:05 424 —-a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-06-28 02:38 . 2007-12-10 05:56 ——– d—–w- c:\program files\Java
2009-06-27 06:25 . 2007-12-25 02:21 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-27 06:25 . 2007-12-25 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-25 22:12 . 2009-01-13 18:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-25 22:12 . 2009-01-20 15:45 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 21:31 . 2007-12-27 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-25 21:31 . 2008-08-25 03:30 ——– d—–w- c:\program files\Viewpoint
2009-06-25 21:31 . 2007-12-10 06:04 ——– d—–w- c:\program files\CyberLink
2009-06-25 21:31 . 2007-12-10 05:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-25 21:28 . 2008-07-09 19:58 ——– d—–w- c:\program files\Diablo II
2009-06-17 16:27 . 2009-01-13 18:44 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2009-01-13 18:44 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 03:39 . 2007-12-25 03:19 ——– d—–w- c:\program files\World of Warcraft
2009-05-28 19:16 . 2009-05-28 19:16 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-05-28 19:15 . 2009-05-28 19:15 294912 —-a-r- c:\windows\system32\SZBase5.dll
2009-05-28 19:14 . 2009-05-28 19:14 540672 —-a-r- c:\windows\system32\SZComp5.dll
2009-05-21 16:33 . 2009-01-29 00:45 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-19 03:03 . 2008-07-09 01:24 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2009-05-12 19:13 . 2009-05-12 19:13 61328 —-a-r- c:\windows\system32\drivers\SZKG.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

— c:\windows\system32\drivers\SZKG.sys —
Company: iS3 Inc.
File Description: szkg Device Driver
File Version: 2.40.0
Product Name: Stopzilla
Copyright: Copyright ©2005-2009 iS3 Inc . All rights reserved.
Original Filename: szkg.sys
File size: 61328
Created time: 2009-05-12 19:13
Modified time: 2009-05-12 19:13
MD5: 2BB7C951BF74183A67EFAAF614823076
SHA1: 428F29DB82ED6BB490F3D3F5E0E7D2EA9659393F


((((((((((((((((((((((((((((( SnapShot@2009-06-26_20.33.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 21:17 . 2009-06-28 21:17 16384 c:\windows\temp\Perflib_Perfdata_198.dat
+ 2009-06-26 20:35 . 2008-10-16 19:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2007-12-25 02:09 . 2009-06-27 09:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-25 02:09 . 2009-06-27 09:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-25 02:09 . 2009-06-27 09:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-12-25 02:09 . 2009-06-26 05:07 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-28 02:39 . 2009-05-21 16:34 148888 c:\windows\system32\javaws.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 148888 c:\windows\system32\javaws.exe
+ 2009-06-28 02:39 . 2009-05-21 16:34 144792 c:\windows\system32\javaw.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 144792 c:\windows\system32\javaw.exe
+ 2009-06-28 02:39 . 2009-05-21 16:34 144792 c:\windows\system32\java.exe
- 2009-01-29 00:45 . 2009-01-29 00:45 144792 c:\windows\system32\java.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-26 20:35 . 2006-03-04 03:33 658432 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 577024 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-26 20:35 . 2004-08-04 11:00 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-26 20:35 . 2004-08-04 10:00 983552 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-26 20:35 . 2004-08-04 10:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-27 06:26 . 2009-06-27 06:26 180224 c:\windows\ERDNT\AutoBackup\6-27-2009\Users\00000002\UsrClass.dat
+ 2009-06-27 06:26 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\6-27-2009\ERDNT.EXE
+ 2009-06-26 20:35 . 2004-08-04 10:00 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-26 20:35 . 2005-03-30 01:21 2135552 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-26 20:35 . 2005-03-30 01:01 2015232 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-26 20:35 . 2004-08-04 10:00 1032192 c:\windows\system32\dllcache\cache\explorer.exe
+ 2009-06-27 06:26 . 2009-06-27 06:26 4599808 c:\windows\ERDNT\AutoBackup\6-27-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-26 16132608]

c:\documents and settings\Jeremy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-10 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\DivX\\DivX Converter\\Converter.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
Trusted Zone: aol.com\kdc.uas
FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\4h69vi0i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-28 16:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(764)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
.
Completion time: 2009-06-28 16:21
ComboFix-quarantined-files.txt 2009-06-28 21:21
ComboFix2.txt 2009-06-26 20:36

Pre-Run: 200,164,208,640 bytes free
Post-Run: 200,248,819,712 bytes free

304 — E O F — 2008-07-07 00:25

and here's the kaspersky

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, June 29, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, June 28, 2009 19:46:54
Records in database: 2399841
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 48202
Threat name: 2
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 00:55:20


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\bvrlrf.dll.vir Infected: Packed.Win32.Krap.q 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tinomejo.dll.vir Infected: Packed.Win32.Krap.q 1
C:\WINDOWS\system32\5ea8300c6cc5f15fbaec217721755fc0.szcpf Infected: not-a-virus:AdWare.Win32.SuperJuan.twy 1

The selected area was scanned.


its running okay but still seems like something is wrong.
Hi,

Delete this file:
C:\WINDOWS\system32\5ea8300c6cc5f15fbaec217721755fc0.szcpf

its running okay but still seems like something is wrong

Can you explain what you mean? What is wrong?
actually the symptoms i was whining about have all gone away thanks. the only thing now is stopzilla weirdly will not open. nor does it autostart anymore. but you did fix the problem i was initially complaining about so thanks a ton.
Hi,

Glad to hear things are running better :thumbup:

Re-installing StopZilla may fix the problem, but if you want to switch to a different AntiSpyware program there are a few listed below.

Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis. You should install thelatest service pack for Windows XP - Service Pack 3.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Keep your Java Runtime Environment up-to-date, as older versions can be exploited.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI