This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer slow... pop ups are attacking my screen

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is slow and popups keep coming up. I noticed when I search for particular keywords on mozilla, like hijackthis for example, it will close out of it. That's about the jist of my problems. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 21:30:43.65 on Mon 08/24/2009 Internet Explorer: 6.0.2900.2180 ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie TB: McAfee VirusScan: {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar4.dll uRun: [PhotoShow Deluxe Media Manager] c:\progra~1\ahead\neroph~1\data\xtras\mssysmgr.exe uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe" –force_start_minimized uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [] c:\windows\temp\g5l057.exe uRun: [hsf7husjnfg98gi498aejhiugjkdg4] c:\windows\temp\g5l057.exe uRun: [Windows System Recover!] c:\docume~1\colby\locals~1\temp\csrss.exe uRun: [braviax] c:\windows\system32\braviax.exe uRun: [AntiSpyware Service] c:\docume~1\colby\locals~1\temp\rqu35k6.exe mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\mcupdate.exe mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ALServ] "c:\program files\altec lansing\ams\ALServ.exe" mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_06\bin\jusched.exe mRun: [WinampAgent] c:\program files\winamp\winampa.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [PC Antispyware 2010] "c:\program files\pc_antispyware2010\PC_Antispyware2010.exe" /hide mRun: [braviax] braviax.exe uPolicies-explorer: NoFolderOptions = 1 (0x1) uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) uPolicies-system: DisableRegistryTools = 1 (0x1) IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: bccecdbdfb - c:\windows\system32\bccecdbdfb.dll Notify: fdcceddbbbe - c:\windows\system32\fdcceddbbbe.dll AppInit_DLLs: cru629.dat STS: c:\windows\system32\gsf83iujid.dll: {b2c7b2a1-00f3-42bd-f434-00aaba2c8952} - c:\windows\system32\gsf83iujid.dll STS: c:\windows\system32\tajf83ikdmf.dll: {bf56a325-23f2-42ad-f4e4-00aac39caa53} - c:\windows\system32\tajf83ikdmf.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\colby\applic~1\mozilla\firefox\profiles\2iznnypq.default\ FF - plugin: c:\documents and settings\colby\application data\mozilla\firefox\profiles\2iznnypq.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-08-23 09:51 16,794 a——- c:\docume~1\alluse~1\applic~1\vutivyn.dat 2009-08-20 15:29 15,000 a——- c:\windows\system32\tajf83ikdmf.dll 2009-08-19 09:10 –d—– c:\documents and settings\colby\LocalLow 2009-08-19 09:10 –d—– c:\docume~1\alluse~1\applic~1\TVU Networks 2009-08-18 10:42 19,145 a——- c:\program files\common files\uripokociq.dll 2009-08-18 10:42 18,091 a——- c:\windows\jyriwoseqa.scr 2009-08-18 10:42 17,797 a——- c:\windows\aquma.scr 2009-08-18 10:42 17,487 a——- c:\windows\alahyk.dl 2009-08-18 10:42 16,781 a——- c:\docume~1\alluse~1\applic~1\etesymaduv.dll 2009-08-18 10:42 14,275 a——- c:\windows\ojeryd._dl 2009-08-18 10:42 13,260 a——- c:\windows\uxeduroki.db 2009-08-18 10:42 12,667 a——- c:\docume~1\colby\applic~1\yqoky.reg 2009-08-18 10:42 12,094 a——- c:\windows\tijufej.db 2009-08-18 10:42 11,673 a——- c:\windows\zymas.reg 2009-08-18 10:42 11,601 a——- c:\docume~1\alluse~1\applic~1\ydykux.bin 2009-08-18 10:42 11,145 a——- c:\program files\common files\opipeb.dat 2009-08-18 10:42 10,750 a——- c:\windows\lucoxyqaxu.vbs 2009-08-18 10:42 10,745 a——- c:\windows\icola.scr 2009-08-18 10:42 347,741 a——- c:\windows\system32\_scui.cpl 2009-08-18 10:42 –d—– c:\program files\PC_Antispyware2010 2009-08-18 10:36 11,264 a——- c:\windows\braviax.exe 2009-08-18 10:36 6,144 a——- c:\windows\system32\cru629.dat 2009-08-18 10:36 6,144 a——- c:\windows\cru629.dat 2009-08-18 10:34 190,157 a——- c:\windows\system32\wisdstr.exe 2009-08-18 10:34 11,264 a——- c:\windows\system32\braviax.exe 2009-08-12 01:44 –d—– c:\windows\ServicePackFiles 2009-08-08 10:37 150,544 a——- c:\windows\system32\8cd3622e9eccb3a66b1d6babb8c0d96f.exe 2009-08-08 10:37 124,448 a——- c:\windows\system32\4d46fc928d7cf583a3f2b0127e04ace8.exe 2009-08-08 10:37 244,752 a——- c:\windows\system32\840b7737de16d27435105dd116bb5541.exe 2009-08-06 08:58 192,529 a——- c:\windows\system32\kdpini.dll 2009-08-05 08:58 150,544 a——- c:\windows\system32\dcc9e00f18fa13f3f715eb37aae32d0b.exe 2009-08-05 08:58 124,448 a——- c:\windows\system32\e76d0594a148ecfad424835b3aa7ec65.exe 2009-08-05 08:58 244,752 a——- c:\windows\system32\22d6fce7c2438ae8134cf6f9c2962650.exe 2009-08-01 16:24 150,544 a——- c:\windows\system32\d68a6b66bd72932970a94d415229b821.exe 2009-08-01 16:24 124,448 a——- c:\windows\system32\060fb5624b8c0bda040b568a8eba1cc4.exe 2009-08-01 16:24 244,752 a——- c:\windows\system32\4a5b4dbedcb0fcab49ec7bd50b05f7fa.exe 2009-07-29 23:11 –d—– c:\windows\scratch_recording 2009-07-28 00:17 116,224 ——– c:\windows\system32\fdcceddbbbe.dll ==================== Find3M ==================== 2009-08-18 10:34 29,184 a——- c:\windows\system32\drivers\beep.sys 2009-08-13 16:51 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-08-05 04:11 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-17 13:55 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 02:18 233,472 a——- c:\windows\system32\wmpdxm.dll 2009-06-26 11:18 659,456 a——- c:\windows\system32\wininet.dll 2009-06-26 11:18 81,920 a——- c:\windows\system32\ieencode.dll 2009-06-18 19:55 0 a——- C:\jswohrrf.exe 2009-06-18 19:55 8,704 a——- C:\ngamcx.exe 2009-06-18 19:54 184,848 a——- C:\dtnln.exe 2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll 2009-06-12 06:50 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 09:21 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 01:32 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-08 16:30 629,760 a——- c:\windows\ElectricSheep_2_7b17.scr 2009-06-05 02:42 655,872 a——- c:\windows\system32\mstscax.dll 2009-06-05 02:01 9,214,464 a——- c:\windows\avcodec-52.dll 2009-06-05 02:01 745,984 a——- c:\windows\avformat-52.dll 2009-06-05 02:01 218,624 a——- c:\windows\swscale-0.dll 2009-06-05 02:01 70,144 a——- c:\windows\avutil-50.dll 2009-06-03 14:27 1,290,752 a——- c:\windows\system32\quartz.dll ============= FINISH: 21:32:40.56 =============== ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/24 21:38 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: d687ef078237ccde711cf10ae711031f.sys Image Path: d687ef078237ccde711cf10ae711031f.sys Address: 0xF8546000 Size: 57344 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF66C6000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8AAC000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF4B9E000 Size: 49152 File Visible: No Signed: - Status: - Name: win32k.sys:1 Image Path: C:\WINDOWS\win32k.sys:1 Address: 0xF88F6000 Size: 20480 File Visible: No Signed: - Status: - Name: win32k.sys:2 Image Path: C:\WINDOWS\win32k.sys:2 Address: 0xF395A000 Size: 53248 File Visible: No Signed: - Status: - Processes ——————- Path: C:\WINDOWS\system32\braviax.exe PID: 1828 Status: Hidden from the Windows API! SSDT ——————- #: 173 Function Name: NtQuerySystemInformation Status: Hooked by "C:\WINDOWS\System32\Drivers\Beep.SYS" at address 0xf86781a0 Hidden Services ——————- Service Name: d687ef078237ccde711cf10ae711031f Image Path: system32\d687ef078237ccde711cf10ae711031f.sys ==EOF==

Attachments:

Hi there, welcome to WhatTheTech :)

You are pretty heavily infected. Before we can begin the full cleaning process, we first need to remove a nasty Rootkit that will prevent most of our cleaning tools from running. To do this, I first need to ask you to download (to your Desktop) and run this diagnostic tool:
http://ad13.geekstogo.com/Win32kDiag.exe

It shall create a log on your Desktop, please post the contents of this log.

Thanks.
Log file is located at: C:\Documents and Settings\Colby\Desktop\Win32kDiag.txt WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Finished! I'm thinking this isn't what you were hoping for in this log :unsure: Thanks for responding so soon!
It wasn't what I was expecting, but then again there's always a chance that the infection has already been part killed. Let's begin cleaning and see if we encounter any problems.

If you already have a copy of ComboFix please delete it.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
There were some windows security program in the system tray that would not open or would let me right click it. I went on with the scan….

ComboFix 09-08-31.03 - Colby 08/31/2009 22:02.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.373 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - netcfgx.dll: deleted 49152 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Colby\LOCALS~1\Temp\csrss.exe
c:\docume~1\Colby\LOCALS~1\Temp\lsass.exe
c:\docume~1\Colby\LOCALS~1\Temp\services.exe
c:\docume~1\Colby\LOCALS~1\Temp\svchost.exe
c:\docume~1\Colby\LOCALS~1\Temp\taskmgr.exe
c:\docume~1\Colby\LOCALS~1\Temp\winlogon.exe
c:\documents and settings\All Users\Application Data\etesymaduv.dll
c:\documents and settings\All Users\Application Data\gibyj.inf
c:\documents and settings\All Users\Application Data\ydykux.bin
c:\documents and settings\All Users\Desktop\nudetube.com.lnk
c:\documents and settings\All Users\Desktop\pornotube.com.lnk
c:\documents and settings\All Users\Desktop\youporn.com.lnk
c:\documents and settings\All Users\Documents\axavybivip.vbs
c:\documents and settings\All Users\Documents\zedese.ban
c:\documents and settings\Colby\Application Data\fekaj.dl
c:\documents and settings\Colby\Application Data\qygo._sy
c:\documents and settings\Colby\Application Data\uxadowave.ban
c:\documents and settings\Colby\Application Data\yqoky.reg
c:\documents and settings\Colby\Cookies\mufehofag.sys
c:\documents and settings\Colby\Cookies\yvumec.reg
c:\documents and settings\Colby\Local Settings\Application Data\fofi.dll
c:\documents and settings\Colby\Local Settings\Application Data\ixomuvidal.inf
c:\documents and settings\Colby\Local Settings\Application Data\lafotegiq.bat
c:\documents and settings\Colby\Local Settings\Temporary Internet Files\cozu.dat
c:\documents and settings\Colby\Local Settings\Temporary Internet Files\ebahizoxis.dl
C:\jswohrrf.exe
C:\ngamcx.exe
c:\program files\Common Files\uripokociq.dll
c:\windows\alahyk.dl
c:\windows\aquma.scr
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Fonts\WPHV07NB.TTF
c:\windows\icola.scr
c:\windows\jyriwoseqa.scr
c:\windows\lucoxyqaxu.vbs
c:\windows\ojeryd._dl
c:\windows\pthreadGC2.dll
c:\windows\system32\_scui.cpl
c:\windows\system32\22d6fce7c2438ae8134cf6f9c2962650.exe
c:\windows\system32\4a5b4dbedcb0fcab49ec7bd50b05f7fa.exe
c:\windows\system32\840b7737de16d27435105dd116bb5541.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\UACodysgyvaoo.sys
c:\windows\system32\fdcceddbbbe.dll
c:\windows\system32\kdpini.dll
c:\windows\system32\tajf83ikdmf.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjqdpfytvnk.dll
c:\windows\system32\UACnhvcbjjiii.dll
c:\windows\system32\UACssdxbidken.dat
c:\windows\system32\UACuvmmrirwbv.dll
c:\windows\system32\UACymwdhmlbjp.dll
c:\windows\system32\wisdstr.exe
c:\windows\system32\wscsvc32.exe
c:\windows\system32\xwreg32.dll
c:\windows\Temp\2478207198.exe
c:\windows\zymas.reg

c:\windows\system32\drivers\beep.sys . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.

2009-09-01 01:59 . 2009-09-01 01:59 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-08-31 01:38 . 2009-08-31 01:44 ——– d—–w- c:\documents and settings\Colby\Application Data\TrueCrypt
2009-08-31 01:34 . 2009-08-31 01:34 217664 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-08-31 01:34 . 2009-08-31 01:34 ——– d—–w- c:\program files\TrueCrypt
2009-08-24 01:25 . 2009-08-24 01:25 ——– d—–w- c:\program files\ERUNT
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\Colby\LocalLow
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\Colby\Local Settings\Application Data\TVU Networks
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-08-19 14:09 . 2009-08-06 18:11 2492728 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\npTVUAx.dll
2009-08-19 14:09 . 2008-03-04 23:52 286720 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\libcurl.dll
2009-08-19 14:09 . 2007-10-31 14:39 59904 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\zlib1.dll
2009-08-19 14:09 . 2007-05-17 18:58 143360 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\libexpatw.dll
2009-08-19 14:09 . 2006-10-18 22:32 499712 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\msvcp71.dll
2009-08-19 14:09 . 2006-10-18 22:32 348160 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\msvcr71.dll
2009-08-19 14:09 . 2006-10-16 23:44 196608 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\ssleay32.dll
2009-08-19 14:09 . 2006-10-16 23:44 1028096 —-a-w- c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\libeay32.dll
2009-08-18 15:42 . 2009-08-18 15:42 16459 —-a-w- c:\documents and settings\Colby\Local Settings\Application Data\watutymi.dat
2009-08-18 15:42 . 2009-08-18 15:42 11145 —-a-w- c:\program files\Common Files\opipeb.dat
2009-08-12 06:44 . 2009-08-12 06:44 ——– d—–w- c:\windows\ServicePackFiles
2009-08-08 15:37 . 2009-08-08 15:37 150544 —-a-w- c:\windows\system32\8cd3622e9eccb3a66b1d6babb8c0d96f.exe
2009-08-08 15:37 . 2009-08-08 15:37 124448 —-a-w- c:\windows\system32\4d46fc928d7cf583a3f2b0127e04ace8.exe
2009-08-05 13:58 . 2009-08-05 13:58 150544 —-a-w- c:\windows\system32\dcc9e00f18fa13f3f715eb37aae32d0b.exe
2009-08-05 13:58 . 2009-08-05 13:58 124448 —-a-w- c:\windows\system32\e76d0594a148ecfad424835b3aa7ec65.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 14:51 . 2009-08-23 14:51 16794 —-a-w- c:\documents and settings\All Users\Application Data\vutivyn.dat
2009-08-19 14:10 . 2006-03-10 05:59 40336 -c–a-w- c:\documents and settings\Colby\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 07:23 . 2006-09-04 00:48 ——– d—–w- c:\documents and settings\Colby\Application Data\BitTorrent
2009-08-13 21:51 . 2006-09-04 22:43 56 –sh–r- c:\windows\system32\6C9745DDD8.sys
2009-08-13 21:51 . 2006-04-25 21:00 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-05 09:11 . 2004-08-04 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 01:12 . 2009-08-02 01:12 0 —-a-w- c:\windows\nsreg.dat
2009-08-01 21:24 . 2009-08-01 21:24 150544 —-a-w- c:\windows\system32\d68a6b66bd72932970a94d415229b821.exe
2009-08-01 21:24 . 2009-08-01 21:24 124448 —-a-w- c:\windows\system32\060fb5624b8c0bda040b568a8eba1cc4.exe
2009-07-17 18:55 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 07:18 . 2004-08-04 12:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 19:42 . 2009-07-10 19:42 ——– d—–w- c:\documents and settings\Colby\Application Data\Snapfish
2009-06-26 16:18 . 2004-08-04 12:00 659456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-06-19 00:54 . 2009-06-19 00:54 184848 —-a-w- C:\dtnln.exe
2009-06-16 14:55 . 2004-08-04 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2004-08-04 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2004-08-04 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2004-08-04 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-08 21:30 . 2009-06-08 21:30 629760 —-a-w- c:\windows\ElectricSheep_2_7b17.scr
2009-06-05 07:42 . 2006-03-10 05:48 655872 —-a-w- c:\windows\system32\mstscax.dll
2009-06-05 07:01 . 2009-06-05 07:01 9214464 —-a-w- c:\windows\avcodec-52.dll
2009-06-05 07:01 . 2009-06-05 07:01 745984 —-a-w- c:\windows\avformat-52.dll
2009-06-05 07:01 . 2009-06-05 07:01 70144 —-a-w- c:\windows\avutil-50.dll
2009-06-05 07:01 . 2009-06-05 07:01 218624 —-a-w- c:\windows\swscale-0.dll
2009-06-03 19:27 . 2004-08-04 12:00 1290752 —-a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2004-11-12 212992]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2006-11-16 43008]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 212992]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"ALServ"="c:\program files\Altec Lansing\AMS\ALServ.exe" [1998-05-26 87040]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-3-27 122880]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bccecdbdfb]
2003-08-01 06:19 312847 ——w- c:\windows\system32\bccecdbdfb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

.
- - - - ORPHANS REMOVED - - - -

BHO-{BF56A325-23F2-42AD-F4E4-00AAC39CAA53} - (no file)
HKCU-Run-Protection System - c:\program files\Protection System\psystem.exe
HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
FF - ProfilePath - c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\
FF - plugin: c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 22:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\d687ef078237ccde711cf10ae711031f.sys 39936 bytes executable
c:\windows\system32\_d687ef078237ccde711cf10ae711031f.sys_.vir 39936 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d687ef078237ccde711cf10ae711031f]
"ImagePath"="system32\d687ef078237ccde711cf10ae711031f.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(592)
c:\windows\system32\bccecdbdfb.dll
.
———————— Other Running Processes ————————
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\VSO\McShield.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\program files\McAfee.com\VSO\oasclnt.exe
c:\program files\McAfee.com\VSO\mcvsshld.exe
c:\program files\McAfee.com\VSO\mcmnhdlr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\devldr32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-09-01 22:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-01 03:13

Pre-Run: 39,454,224,384 bytes free
Post-Run: 40,012,324,864 bytes free

243 — E O F — 2009-08-26 08:00
Hi,

jpshortstuff is indisposed at the moment and asked if I could look after you till he gets back….



Please do the following:
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Computer_slow_pop_ups_attacking_my_screen_t106431.html&view=findpost&p=592335#entry592335

Collect::
c:\documents and settings\Colby\Local Settings\Application Data\watutymi.dat
c:\program files\Common Files\opipeb.dat
c:\documents and settings\All Users\Application Data\vutivyn.dat
c:\windows\system32\bccecdbdfb.dll
c:\windows\system32\8cd3622e9eccb3a66b1d6babb8c0d96f.exe
c:\windows\system32\4d46fc928d7cf583a3f2b0127e04ace8.exe
c:\windows\system32\dcc9e00f18fa13f3f715eb37aae32d0b.exe
c:\windows\system32\e76d0594a148ecfad424835b3aa7ec65.exe
c:\windows\system32\d68a6b66bd72932970a94d415229b821.exe
c:\windows\system32\060fb5624b8c0bda040b568a8eba1cc4.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bccecdbdfb]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d687ef078237ccde711cf10ae711031f]

Rootkit::
c:\windows\system32\d687ef078237ccde711cf10ae711031f.sys

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

I have requested some files to be uploaded after this fix, it will open an upload window automatically, please make sure you have a connection and ALLOW the files to be submitted.

Note: If combofix askes to update and install the Recovery Console, please ALLOW it to do so.
ComboFix 09-09-05.02 - Colby 09/05/2009 23:10.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.110 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Colby\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

file zipped: c:\documents and settings\All Users\Application Data\vutivyn.dat
file zipped: c:\documents and settings\Colby\Local Settings\Application Data\watutymi.dat
file zipped: c:\program files\Common Files\opipeb.dat
file zipped: c:\windows\system32\060fb5624b8c0bda040b568a8eba1cc4.exe
file zipped: c:\windows\system32\4d46fc928d7cf583a3f2b0127e04ace8.exe
file zipped: c:\windows\system32\8cd3622e9eccb3a66b1d6babb8c0d96f.exe
file zipped: c:\windows\system32\bccecdbdfb.dll
file zipped: c:\windows\system32\d68a6b66bd72932970a94d415229b821.exe
file zipped: c:\windows\system32\dcc9e00f18fa13f3f715eb37aae32d0b.exe
file zipped: c:\windows\system32\e76d0594a148ecfad424835b3aa7ec65.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\vutivyn.dat
c:\documents and settings\Colby\Local Settings\Application Data\watutymi.dat
c:\program files\Common Files\opipeb.dat
c:\windows\system32\060fb5624b8c0bda040b568a8eba1cc4.exe
c:\windows\system32\4d46fc928d7cf583a3f2b0127e04ace8.exe
c:\windows\system32\8cd3622e9eccb3a66b1d6babb8c0d96f.exe
c:\windows\system32\bccecdbdfb.dll
c:\windows\system32\d68a6b66bd72932970a94d415229b821.exe
c:\windows\system32\dcc9e00f18fa13f3f715eb37aae32d0b.exe
c:\windows\system32\e76d0594a148ecfad424835b3aa7ec65.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_d687ef078237ccde711cf10ae711031f


((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 )))))))))))))))))))))))))))))))
.

2009-09-01 03:06 . 2009-09-06 04:13 39936 —-a-w- c:\windows\system32\_d687ef078237ccde711cf10ae711031f.sys_.vir
2009-09-01 01:59 . 2009-09-01 01:59 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-08-31 01:38 . 2009-08-31 01:44 ——– d—–w- c:\documents and settings\Colby\Application Data\TrueCrypt
2009-08-31 01:34 . 2009-08-31 01:34 217664 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-08-31 01:34 . 2009-08-31 01:34 ——– d—–w- c:\program files\TrueCrypt
2009-08-24 01:25 . 2009-08-24 01:25 ——– d—–w- c:\program files\ERUNT
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\Colby\LocalLow
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\Colby\Local Settings\Application Data\TVU Networks
2009-08-19 14:10 . 2009-08-19 14:10 ——– d—–w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-08-12 06:44 . 2009-08-12 06:44 ——– d—–w- c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 14:10 . 2006-03-10 05:59 40336 -c–a-w- c:\documents and settings\Colby\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 07:23 . 2006-09-04 00:48 ——– d—–w- c:\documents and settings\Colby\Application Data\BitTorrent
2009-08-13 21:51 . 2006-09-04 22:43 56 –sh–r- c:\windows\system32\6C9745DDD8.sys
2009-08-13 21:51 . 2006-04-25 21:00 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-05 09:11 . 2004-08-04 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 01:12 . 2009-08-02 01:12 0 —-a-w- c:\windows\nsreg.dat
2009-07-17 18:55 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 07:18 . 2004-08-04 12:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 19:42 . 2009-07-10 19:42 ——– d—–w- c:\documents and settings\Colby\Application Data\Snapfish
2009-06-26 16:18 . 2004-08-04 12:00 659456 ——w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-06-19 00:54 . 2009-06-19 00:54 184848 —-a-w- C:\dtnln.exe
2009-06-16 14:55 . 2004-08-04 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2004-08-04 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2004-08-04 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2004-08-04 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-08 21:30 . 2009-06-08 21:30 629760 —-a-w- c:\windows\ElectricSheep_2_7b17.scr
.

((((((((((((((((((((((((((((( SnapShot@2009-09-01_03.10.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-01 03:12 . 2008-10-16 19:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 13824 c:\windows\system32\dllcache\cache\wscntfy.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 71680 c:\windows\system32\dllcache\cache\ssdpsrv.dll
+ 2009-09-01 03:12 . 2005-06-10 23:53 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 59904 c:\windows\system32\dllcache\cache\regsvc.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 89088 c:\windows\system32\dllcache\cache\rasauto.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 52224 c:\windows\system32\dllcache\cache\mspmsnsv.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 33792 c:\windows\system32\dllcache\cache\msgsvc.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 22016 c:\windows\system32\dllcache\cache\lpk.dll
+ 2009-09-01 03:12 . 2005-09-01 01:41 19968 c:\windows\system32\dllcache\cache\linkinfo.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 55808 c:\windows\system32\dllcache\cache\eventlog.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 60416 c:\windows\system32\dllcache\cache\cryptsvc.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 77312 c:\windows\system32\dllcache\cache\browser.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\cache\asyncmac.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 11648 c:\windows\system32\dllcache\cache\acpiec.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\cache\sfc.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 2944 c:\windows\system32\dllcache\cache\null.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 129536 c:\windows\system32\dllcache\cache\xmlprov.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-09-01 03:12 . 2009-06-26 16:18 659456 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-09-01 03:12 . 2007-03-08 15:36 577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-09-01 03:12 . 2007-02-05 20:17 185344 c:\windows\system32\dllcache\cache\upnphost.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-09-01 03:12 . 2008-06-20 10:45 360320 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-09-01 03:12 . 2005-07-08 16:27 249344 c:\windows\system32\dllcache\cache\tapisrv.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 170496 c:\windows\system32\dllcache\cache\srsvc.dll
+ 2009-09-01 03:12 . 2006-12-19 21:52 134656 c:\windows\system32\dllcache\cache\shsvcs.dll
+ 2009-09-01 03:12 . 2009-02-06 17:14 110592 c:\windows\system32\dllcache\cache\services.exe
+ 2009-09-01 03:12 . 2004-08-04 12:00 190976 c:\windows\system32\dllcache\cache\schedsvc.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 180224 c:\windows\system32\dllcache\cache\scecli.dll
+ 2009-09-01 03:12 . 2009-02-09 10:20 399360 c:\windows\system32\dllcache\cache\rpcss.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 382464 c:\windows\system32\dllcache\cache\qmgr.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 435200 c:\windows\system32\dllcache\cache\ntmssvc.dll
+ 2009-09-01 03:12 . 2007-02-09 11:10 574464 c:\windows\system32\dllcache\cache\ntfs.sys
+ 2009-09-01 03:12 . 2005-08-22 18:29 197632 c:\windows\system32\dllcache\cache\netman.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 407040 c:\windows\system32\dllcache\cache\netlogon.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-09-01 03:12 . 2008-06-20 17:41 245248 c:\windows\system32\dllcache\cache\mswsock.dll
+ 2009-09-01 03:12 . 2006-11-01 19:17 927504 c:\windows\system32\dllcache\cache\mfc40u.dll
+ 2009-09-01 03:12 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-09-01 03:12 . 2008-07-07 20:32 253952 c:\windows\system32\dllcache\cache\es.dll
+ 2009-09-01 03:12 . 2004-08-04 12:00 792064 c:\windows\system32\dllcache\cache\comres.dll
+ 2009-09-01 03:12 . 2006-08-25 15:45 617472 c:\windows\system32\dllcache\cache\comctl32.dll
+ 2009-09-01 03:12 . 2006-02-15 00:22 142464 c:\windows\system32\dllcache\cache\aec.sys
+ 2009-09-01 03:12 . 2004-08-04 12:00 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-09-01 03:12 . 2009-02-06 17:24 2180480 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-09-01 03:12 . 2009-02-06 16:49 2057728 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-09-01 03:12 . 2009-07-18 16:20 3062272 c:\windows\system32\dllcache\cache\mshtml.dll
+ 2009-09-01 03:12 . 2007-06-13 10:23 1033216 c:\windows\system32\dllcache\cache\explorer.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2004-11-12 212992]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2006-11-16 43008]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"ALServ"="c:\program files\Altec Lansing\AMS\ALServ.exe" [1998-05-26 87040]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-3-27 122880]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
FF - ProfilePath - c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\
FF - plugin: c:\documents and settings\Colby\Application Data\Mozilla\Firefox\Profiles\2iznnypq.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-05 23:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\VSO\McShield.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\program files\McAfee.com\Agent\mcagent.exe
c:\program files\McAfee.com\VSO\oasclnt.exe
c:\program files\McAfee.com\VSO\mcvsshld.exe
c:\windows\system32\devldr32.exe
c:\program files\McAfee.com\VSO\mcmnhdlr.exe
c:\program files\McAfee.com\Shared\mghtml.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-06 23:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-06 04:19
ComboFix2.txt 2009-09-01 03:13

Pre-Run: 39,973,261,312 bytes free
Post-Run: 39,943,856,128 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

236 — E O F — 2009-08-26 08:00
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Computer_slow_pop_ups_attacking_my_screen_t106431.html&view=findpost&p=593645#entry593645

Collect::
c:\windows\system32\wingenocx.dll

File::
c:\windows\system32\_d687ef078237ccde711cf10ae711031f.sys_.vir

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT


The previous request for file submission, did not go through as planned - please allow an upload to go through at the end of the ComboFix run.

We need to submit the upload from the previous run manually.


Please do the following:

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Computer_slow_pop_ups_attacking_my_screen_t106431.html&view=findpost&p=593645#entry593645

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_09/05/2009_23:10.zip (the date and time will be very close to what is there)
Select this file and click Open
In the Largest box please put
File Requested By CatByte
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI