This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need help with a very nasty virus

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i got a really nasty virus that has me stumped big time. i noticed my PC was acting strange so i went to check virus scanner(avast antivirus) and noticed it was no longer running. so i ran the ATF Cleaner with no problem and went to run malwarebytes antimalware but it would not work. so i tried spybot search and destroy and it would not run. basically whatever i got shut down my virus protection and any progam used to get rid of it. i was able to use my virus scan by going through program files but after it was done and said it removed it, after reboot i still could not use anything and still had the virus. i am at a loss cause this has never happened before. i know it said it was a trojan and assume it is hid somewhere and keeps coming back at reboot. I have windows xp with sp3 and IE7.here is a hijack this logfile if that helps any………………….

C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Kodak\AiO\center\KodakSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Owner.jeff\Desktop\Security\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: (no name) - {ABC42510-9B22-41c1-9DCD-8182A2D07C63} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O3 - Toolbar: RefresherBand Class - {B24BA06E-FB7B-4757-95C2-DC01125F750E} - C:\PROGRA~1\YREFRE~1\YREFRE~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner.jeff\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /ini "uinstaller.ini" /fromrun /starthidden
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229370334716
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1241638790843
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://webcam1.pgharts.org/activex/AMC.cab
O18 - Filter: text/html - {3462dd96-49b7-44c4-9c5c-02371ffafdd3} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\AiO\center\KodakSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Hi,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
there is a problem, the DDS thing ran ok but the GMER is not working. i downloaded and extrated to desktop but it seems like the virus is blocking it from running, just like it won't let spybot and malwarebytes to woork. i double clicked and it will not resond at all, here is the 2 DDS text files UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/2/2007 2:44:45 PM System Uptime: 12/10/2009 10:20:27 AM (0 hours ago) Motherboard: Intel Corporation | | D101GGC Processor: Intel® Pentium® 4 CPU 3.00GHz | | 3000/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 144 GiB total, 113.244 GiB free. D: is FIXED (FAT32) - 5 GiB total, 3.405 GiB free. E: is CDROM () G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP987: 9/11/2009 5:17:21 AM - System Checkpoint RP988: 9/12/2009 5:27:41 AM - System Checkpoint RP989: 9/13/2009 6:35:03 AM - System Checkpoint RP990: 9/14/2009 6:49:17 AM - System Checkpoint RP991: 9/14/2009 8:52:01 PM - Cleaned registry with Windows Live OneCare safety scanner RP992: 9/16/2009 4:47:16 AM - System Checkpoint RP993: 9/16/2009 4:37:10 PM - Configured VeohTV BETA RP994: 9/16/2009 4:53:02 PM - Cleaned registry with Windows Live OneCare safety scanner RP995: 9/17/2009 2:25:16 PM - Created By FixIEDef RP996: 9/17/2009 2:30:57 PM - Software Distribution Service 3.0 RP997: 9/19/2009 4:57:33 AM - System Checkpoint RP998: 9/19/2009 9:33:11 PM - Cleaned registry with Windows Live OneCare safety scanner RP999: 9/20/2009 10:30:26 PM - System Checkpoint RP1000: 9/22/2009 4:13:56 AM - System Checkpoint RP1001: 9/22/2009 3:24:03 PM - Cleaned registry with Windows Live OneCare safety scanner RP1002: 9/23/2009 5:24:29 PM - System Checkpoint RP1003: 9/24/2009 8:49:01 PM - System Checkpoint RP1004: 9/25/2009 9:11:25 PM - System Checkpoint RP1005: 9/26/2009 8:56:06 PM - Cleaned registry with Windows Live OneCare safety scanner RP1006: 9/27/2009 9:02:08 PM - System Checkpoint RP1007: 9/29/2009 4:44:13 AM - System Checkpoint RP1008: 9/30/2009 4:48:02 AM - System Checkpoint RP1009: 10/1/2009 5:07:07 AM - System Checkpoint RP1010: 10/2/2009 5:31:49 AM - System Checkpoint RP1011: 10/3/2009 7:03:12 AM - System Checkpoint RP1012: 10/4/2009 7:58:49 AM - System Checkpoint RP1013: 10/4/2009 9:23:26 PM - Cleaned registry with Windows Live OneCare safety scanner RP1014: 10/6/2009 5:09:48 AM - System Checkpoint RP1015: 10/7/2009 5:20:29 AM - System Checkpoint RP1016: 10/7/2009 9:08:59 PM - Cleaned registry with Windows Live OneCare safety scanner RP1017: 10/8/2009 9:10:39 PM - System Checkpoint RP1018: 10/10/2009 4:59:32 AM - System Checkpoint RP1019: 10/11/2009 6:42:06 AM - System Checkpoint RP1020: 10/12/2009 8:12:53 AM - System Checkpoint RP1021: 10/13/2009 8:17:28 AM - System Checkpoint RP1022: 10/14/2009 5:49:04 PM - System Checkpoint RP1023: 10/14/2009 9:47:40 PM - Software Distribution Service 3.0 RP1024: 10/16/2009 4:42:05 AM - System Checkpoint RP1025: 10/16/2009 2:15:26 PM - Cleaned registry with Windows Live OneCare safety scanner RP1026: 10/17/2009 2:32:07 PM - System Checkpoint RP1027: 10/18/2009 8:21:28 PM - System Checkpoint RP1028: 10/18/2009 9:23:56 PM - Cleaned registry with Windows Live OneCare safety scanner RP1029: 10/19/2009 9:39:10 PM - System Checkpoint RP1030: 10/21/2009 4:37:58 AM - System Checkpoint RP1031: 10/22/2009 6:16:24 AM - System Checkpoint RP1032: 10/23/2009 7:03:20 AM - System Checkpoint RP1033: 10/24/2009 9:05:46 AM - System Checkpoint RP1034: 10/25/2009 9:26:31 AM - System Checkpoint RP1035: 10/26/2009 9:48:22 AM - System Checkpoint RP1036: 10/27/2009 10:09:25 AM - System Checkpoint RP1037: 10/28/2009 5:35:22 PM - System Checkpoint RP1038: 10/29/2009 9:24:08 PM - System Checkpoint RP1039: 10/31/2009 3:13:57 AM - System Checkpoint RP1040: 11/1/2009 5:39:55 AM - System Checkpoint RP1041: 11/2/2009 5:44:07 AM - System Checkpoint RP1042: 11/3/2009 7:05:51 AM - System Checkpoint RP1043: 11/4/2009 7:23:12 AM - System Checkpoint RP1044: 11/5/2009 7:29:57 AM - System Checkpoint RP1045: 11/5/2009 11:51:50 AM - Cleaned registry with Windows Live OneCare safety scanner RP1046: 11/6/2009 6:20:01 PM - System Checkpoint RP1047: 11/7/2009 8:43:45 PM - System Checkpoint RP1048: 11/8/2009 8:15:38 PM - System Checkpoint RP1049: 11/9/2009 9:16:23 PM - System Checkpoint RP1050: 11/11/2009 4:17:35 AM - System Checkpoint RP1051: 11/12/2009 4:46:29 AM - System Checkpoint RP1052: 11/13/2009 4:46:49 AM - System Checkpoint RP1053: 11/14/2009 5:13:38 AM - System Checkpoint RP1054: 11/14/2009 10:18:29 PM - Cleaned registry with Windows Live OneCare safety scanner RP1055: 11/16/2009 4:21:43 AM - System Checkpoint RP1056: 11/17/2009 5:07:21 AM - System Checkpoint RP1057: 11/18/2009 6:05:39 AM - System Checkpoint RP1058: 11/19/2009 6:15:14 AM - System Checkpoint RP1059: 11/20/2009 7:23:24 AM - System Checkpoint RP1060: 11/20/2009 1:58:59 PM - Created By FixIEDef RP1061: 11/21/2009 2:18:39 PM - System Checkpoint RP1062: 11/22/2009 2:55:44 PM - System Checkpoint RP1063: 11/22/2009 8:30:05 PM - Cleaned registry with Windows Live OneCare safety scanner RP1064: 11/22/2009 8:37:00 PM - Software Distribution Service 3.0 RP1065: 11/23/2009 9:10:21 PM - System Checkpoint RP1066: 11/24/2009 11:08:30 PM - System Checkpoint RP1067: 11/26/2009 5:07:17 AM - System Checkpoint RP1068: 11/27/2009 5:08:47 AM - System Checkpoint RP1069: 11/28/2009 1:52:18 AM - Cleaned registry with Windows Live OneCare safety scanner RP1070: 11/29/2009 4:56:02 AM - System Checkpoint RP1071: 11/30/2009 7:50:32 AM - System Checkpoint RP1072: 12/1/2009 9:17:34 AM - System Checkpoint RP1073: 12/1/2009 11:51:17 PM - Cleaned registry with Windows Live OneCare safety scanner RP1074: 12/3/2009 3:35:28 AM - System Checkpoint RP1075: 12/4/2009 4:19:46 AM - System Checkpoint RP1076: 12/5/2009 5:41:14 AM - System Checkpoint RP1077: 12/6/2009 6:25:21 AM - System Checkpoint RP1078: 12/7/2009 7:18:29 AM - System Checkpoint RP1079: 12/8/2009 7:31:54 AM - System Checkpoint RP1080: 12/9/2009 4:24:12 PM - System Checkpoint ==== Installed Programs ====================== 7-Zip 4.42 a-squared Free 2.1 a-squared HiJackFree 2.1 ABC (remove only) Ad-Aware Adobe Flash Player 10 ActiveX Adobe Reader 7.0 Adobe Shockwave Player 11.5 aiofw aioprnt aioscnnr Ares 2.0.1 ATI Display Driver avast! Antivirus AXIS Media Control Embedded Bonjour CCleaner center Comcast Universal Installer v1.2 Critical Update for Windows Media Player 11 (KB959772) Digital Media Reader DivX Plus Web Player DVD Solution ESPN Java Check ffdshow [rev 1523] [2007-10-09] GetDiz 3.0 Google Desktop Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB888111 HijackThis 1.99.1 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) iolo technologies' System Mechanic 6 J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 9 Java™ 6 Update 3 Java™ 6 Update 7 K-Lite Codec Pack 2.82 Full KODAK AiO Home Center ksDIP Logitech Audio Echo Cancellation Component Logitech Legacy USB Camera Driver Package Logitech QuickCam Logitech QuickCam Driver Package Logitech Video Enumerator Madden NFL 2004 Malwarebytes' Anti-Malware Micro Innovations Wireless Laser Mouse Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Starter Edition 2006 Microsoft Digital Image Starter Edition 2006 Editor Microsoft Digital Image Starter Edition 2006 Library Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2000 Premium Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Works Move Media Player MP3 Checker 1.08 MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MVision My Wal-Mart Digital Photo Center Napster Burn Engine Paint Shop Pro 7 Anniversary Edition PeerGuardian 2.0 PKR Power2Go 4.0 PowerDVD PreReq QuickTime Alternative 2.9.0 REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver Recovery Software Suite eMachines Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Soft Data Fax Modem with SmartCP Sonic Encoders SopCast 1.1.2 Spybot - Search & Destroy SpywareBlaster 4.2 SpywareGuard v2.2 TVUPlayer [removed] Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 VC80CRTRedist - 8.0.50727.4053 WebFldrs XP Winamp Windows Genuine Advantage Validation Tool (KB892130) Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinRAR archiver Wise Disk Cleaner 2.7 Yahoo! Internet Mail Yahoo! Messenger Yrefresher 1.00 ==== End Of File =========================== DS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 10:34:15.06 on Thu 12/10/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.423 [GMT -5:00] AV: avast! antivirus 4.8.1368 [VPS 091203-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Digital Media Reader\readericon45G.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe svchost.exe c:\program files\a-squared free\a2service.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Kodak\AiO\center\KodakSvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Owner.jeff\Desktop\dds.pif ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://www.yahoo.com/ uWindow Title = uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: {ABC42510-9B22-41c1-9DCD-8182A2D07C63} - No File BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll TB: RefresherBand Class: {b24ba06e-fb7b-4757-95c2-dc01125f750e} - c:\progra~1\yrefre~1\YREFRE~1.DLL TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [SMSystemAnalyzer] "c:\program files\iolo\system mechanic 6\SMSystemAnalyzer.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Universal Installer] "c:\program files\comcastui\universal installer\uinstaller.exe" /fromrun /starthidden uRun: [cdloader] "c:\documents and settings\owner.jeff\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Desktop Software] "c:\program files\comcastui\universal installer\uinstaller.exe" /ini "uinstaller.ini" /fromrun /starthidden uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [readericon] c:\program files\digital media reader\readericon45G.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [FLMOFFICE4DMOUSE] c:\program files\micro innovations\wireless laser mouse\moffice.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime StartupFolder: c:\docume~1\owner~1.jef\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE uPolicies-system: EnableProfileQuota = 1 (0x1) IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229370334716 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1241638790843 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam1.pgharts.org/activex/AMC.cab Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll Hosts: 127.0.0.1 www.spywareinfo.com ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-1 114768] R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2007-6-11 1858144] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-1 20560] R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2009-5-4 279960] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2009-4-17 32768] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-1-2 138680] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-1-2 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-1-2 352920] S3 ldiskl;ldiskl;\??\c:\docume~1\owner~1.jef\locals~1\temp\ldiskl.sys –> c:\docume~1\owner~1.jef\locals~1\temp\ldiskl.sys [?] S3 ProtoWall;ProtoWall Defender;c:\windows\system32\drivers\protowall.sys –> c:\windows\system32\drivers\ProtoWall.sys [?] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-12-10 03:01:40 0 d—–w- c:\docume~1\owner~1.jef\applic~1\AVG8 2009-12-09 02:39:37 196 —-a-w- c:\windows\system32\srcr.dat ==================== Find3M ==================== 2009-12-03 21:14:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-03 21:13:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2008-11-18 19:12:52 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008111820081119\index.dat ============= FINISH: 10:35:01.35 ===============
Hi,
Please do the following:

Download Combofix from either of the links below but rename it to combo.com before saving it to your desktop.


Link 1
Link 2


——————————————————————–

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
NOTE: Very Important! - Please disable all your security programs before running ComboFix as they will interfere
ok , not sure what it means but my my virus scanner did come on when combofix rebooted my PC. anyway here is the combofix log file………

ComboFix 09-12-09.04 - Owner 12/10/2009 13:28:33.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.463 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
AV: avast! antivirus 4.8.1368 [VPS 091203-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common
c:\program files\Common\_helper.sig
c:\program files\driver
c:\program files\Shared
c:\windows\kb913800.exe
c:\windows\system32\drivers\H8SRTxobrfvdrwu.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\h8srtcfg.dat
c:\windows\system32\H8SRTiurqrgwwqj.dll
c:\windows\system32\H8SRTolemxkqirf.dat
c:\windows\system32\H8SRTqjwcpbitet.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\srcr.dat
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys
——-\Legacy_DRIVER
——-\Legacy_DRIVERDRV


((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.

2009-12-10 18:33 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2009-12-10 18:33 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-12-10 03:01 . 2009-12-10 03:01 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\AVG8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-10 18:01 . 2008-03-01 12:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-10 04:10 . 2007-03-04 18:48 ——– d—–w- c:\program files\a-squared Free
2009-12-09 15:04 . 2007-01-04 22:34 ——– d—–w- c:\program files\Windows Live Safety Center
2009-12-09 14:54 . 2009-04-10 22:43 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\mjusbsp
2009-12-09 04:11 . 2009-06-29 18:03 ——– d—–w- c:\program files\SpywareGuard
2009-12-09 04:05 . 2007-01-03 01:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-09 03:56 . 2007-01-03 01:30 ——– d—–w- c:\program files\SpywareBlaster
2009-12-09 03:20 . 2008-02-03 20:28 ——– d—–w- c:\program files\PeerGuardian2
2009-12-06 02:54 . 2008-07-05 14:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-06 02:54 . 2009-06-19 18:15 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-03 21:14 . 2009-06-19 18:15 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2008-07-05 14:15 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 00:19 . 2009-10-15 19:46 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\Temp
2009-11-24 23:54 . 2007-01-02 22:50 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2007-01-02 22:50 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2007-01-02 22:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-04-02 01:37 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-04-02 01:37 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2007-01-02 22:50 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2007-01-02 22:50 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2007-01-02 22:50 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2007-01-02 22:50 97480 —-a-w- c:\windows\system32\AVASTSS.scr
2009-11-23 01:37 . 2007-03-26 02:26 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-11-20 15:37 . 2007-09-29 01:57 ——– d—–w- c:\program files\DivX
2009-11-19 04:46 . 2009-11-19 04:46 5562672 —-a-w- c:\documents and settings\Owner.jeff\Application Data\TVU networks\AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-11-19 04:46 . 2008-08-24 06:56 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\TVU networks
2009-11-12 04:40 . 2007-01-03 01:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-10-16 20:57 . 2009-10-16 20:57 ——– d—–w- c:\documents and settings\All Users\Application Data\kds_kodak
2009-10-15 19:55 . 2009-10-15 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kodak
2009-10-15 19:50 . 2009-10-15 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Eastman Kodak Company
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\program files\Kodak
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\program files\Bonjour
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-09-29 15:03 . 2009-09-29 15:03 127872 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\uninstall.exe
2009-09-29 15:02 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-09-29 15:02 . 2009-09-29 15:02 1686272 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe
2009-09-20 02:45 . 2009-09-20 02:43 5519752 —-a-w- c:\documents and settings\Owner.jeff\Application Data\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.7.2.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Owner.jeff\Application Data\mjusbsp\cdloader2.exe MAGICJACK" [X]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 557056]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-18 39408]
"Desktop Software"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-05 16120832]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"FLMOFFICE4DMOUSE"="c:\program files\Micro Innovations\Wireless Laser Mouse\moffice.exe" [2007-01-02 806912]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-07-31 1626112]

c:\documents and settings\Owner.jeff\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic 6\\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 20:37 2178832 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Ad Muncher\\AdMunch.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Owner.jeff\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\EA SPORTS\\Madden NFL 2004\\Updater.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\sopvod.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Owner.jeff\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/1/2008 8:37 PM 114768]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [6/11/2007 7:58 PM 1858144]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/1/2008 8:37 PM 20560]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKDiscovery.exe [5/4/2009 11:15 AM 279960]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\AiO\Center\KodakSvc.exe [4/17/2009 11:08 AM 32768]
S3 ldiskl;ldiskl;\??\c:\docume~1\OWNER~1.JEF\LOCALS~1\Temp\ldiskl.sys –> c:\docume~1\OWNER~1.JEF\LOCALS~1\Temp\ldiskl.sys [?]
S3 ProtoWall;ProtoWall Defender;c:\windows\system32\DRIVERS\ProtoWall.sys –> c:\windows\system32\DRIVERS\ProtoWall.sys [?]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam1.pgharts.org/activex/AMC.cab
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -

BHO-{ABC42510-9B22-41c1-9DCD-8182A2D07C63} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-10 13:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(6192)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Micro Innovations\Wireless Laser Mouse\MOUDL32A.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\RTHDCPL.EXE
c:\program files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-12-10 13:48:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-10 18:48
ComboFix2.txt 2008-07-05 20:46

Pre-Run: 121,495,928,832 bytes free
Post-Run: 121,630,334,976 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - BDE4A6E17B492654EF170DDD59D62B4B
Hi,

AVG8
a-squared Free
avast!
McAfee VirusScan

All show up in your log, have you tried to uninstall three of them and there are remnants? Or a couple are just downloaded but not installed?
Which Antivirus are you using? The others need to be completely uninstalled.


NEXT


Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Driver::
ldiskl

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Avast is the only antivrus i use, avg,a-squared, and mcafee must only be remnats cause they are not installed. anyway here are the log files……………..

COMBOFIX:
ComboFix 09-12-09.04 - Owner 12/11/2009 12:47:12.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.354 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.com
Command switches used :: c:\docume~1\OWNER~1.JEF\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 091209-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_LDISKL
——-\Service_ldiskl


((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.

2009-12-10 18:33 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2009-12-10 18:33 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-12-10 03:01 . 2009-12-10 03:01 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\AVG8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 17:30 . 2008-03-01 12:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-10 04:10 . 2007-03-04 18:48 ——– d—–w- c:\program files\a-squared Free
2009-12-09 15:04 . 2007-01-04 22:34 ——– d—–w- c:\program files\Windows Live Safety Center
2009-12-09 14:54 . 2009-04-10 22:43 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\mjusbsp
2009-12-09 04:11 . 2009-06-29 18:03 ——– d—–w- c:\program files\SpywareGuard
2009-12-09 04:05 . 2007-01-03 01:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-09 03:56 . 2007-01-03 01:30 ——– d—–w- c:\program files\SpywareBlaster
2009-12-09 03:20 . 2008-02-03 20:28 ——– d—–w- c:\program files\PeerGuardian2
2009-12-06 02:54 . 2008-07-05 14:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-06 02:54 . 2009-06-19 18:15 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-03 21:14 . 2009-06-19 18:15 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2008-07-05 14:15 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 00:19 . 2009-10-15 19:46 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\Temp
2009-11-24 23:54 . 2007-01-02 22:50 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2007-01-02 22:50 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2007-01-02 22:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-04-02 01:37 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-04-02 01:37 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2007-01-02 22:50 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2007-01-02 22:50 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2007-01-02 22:50 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2007-01-02 22:50 97480 —-a-w- c:\windows\system32\AVASTSS.scr
2009-11-23 01:37 . 2007-03-26 02:26 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-11-20 15:37 . 2007-09-29 01:57 ——– d—–w- c:\program files\DivX
2009-11-19 04:46 . 2009-11-19 04:46 5562672 —-a-w- c:\documents and settings\Owner.jeff\Application Data\TVU networks\AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-11-19 04:46 . 2008-08-24 06:56 ——– d—–w- c:\documents and settings\Owner.jeff\Application Data\TVU networks
2009-11-12 04:40 . 2007-01-03 01:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-10-16 20:57 . 2009-10-16 20:57 ——– d—–w- c:\documents and settings\All Users\Application Data\kds_kodak
2009-10-15 19:55 . 2009-10-15 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kodak
2009-10-15 19:50 . 2009-10-15 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Eastman Kodak Company
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\program files\Kodak
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\program files\Bonjour
2009-10-15 19:48 . 2009-10-15 19:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-09-29 15:03 . 2009-09-29 15:03 127872 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\uninstall.exe
2009-09-29 15:02 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-09-29 15:02 . 2009-09-29 15:02 1686272 —-a-w- c:\documents and settings\Owner.jeff\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe
2009-09-20 02:45 . 2009-09-20 02:43 5519752 —-a-w- c:\documents and settings\Owner.jeff\Application Data\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.7.2.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Owner.jeff\Application Data\mjusbsp\cdloader2.exe MAGICJACK" [X]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 557056]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-18 39408]
"Desktop Software"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-05 16120832]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"FLMOFFICE4DMOUSE"="c:\program files\Micro Innovations\Wireless Laser Mouse\moffice.exe" [2007-01-02 806912]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-07-31 1626112]

c:\documents and settings\Owner.jeff\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic 6\\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 20:37 2178832 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Ad Muncher\\AdMunch.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Owner.jeff\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\EA SPORTS\\Madden NFL 2004\\Updater.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\sopvod.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Owner.jeff\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/1/2008 8:37 PM 114768]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [6/11/2007 7:58 PM 1858144]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/1/2008 8:37 PM 20560]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKDiscovery.exe [5/4/2009 11:15 AM 279960]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\AiO\Center\KodakSvc.exe [4/17/2009 11:08 AM 32768]
S3 ProtoWall;ProtoWall Defender;c:\windows\system32\DRIVERS\ProtoWall.sys –> c:\windows\system32\DRIVERS\ProtoWall.sys [?]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam1.pgharts.org/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{ABC42510-9B22-41c1-9DCD-8182A2D07C63} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-11 12:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3092)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Micro Innovations\Wireless Laser Mouse\MOUDL32A.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\RTHDCPL.EXE
c:\program files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\iolo\SYSTEM~1\SysMech6.exe
.
**************************************************************************
.
Completion time: 2009-12-11 13:05:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-11 18:05
ComboFix2.txt 2009-12-10 18:48
ComboFix3.txt 2008-07-05 20:46

Pre-Run: 121,685,504,000 bytes free
Post-Run: 121,727,180,800 bytes free

- - End Of File - - 626C7769A853D9BD398F359FFD7D1A0C


MALWAREBYTES:
Malwarebytes' Anti-Malware 1.42
Database version: 3346
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

12/11/2009 1:16:14 PM
mbam-log-2009-12-11 (13-16-14).txt

Scan type: Quick Scan
Objects scanned: 114729
Time elapsed: 5 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


KASPERSKY:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, December 11, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, December 11, 2009 18:49:23
Records in database: 3359532
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 85312
Threats found: 2
Infected objects found: 3
Suspicious objects found: 0
Scan duration: 03:02:14


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTiurqrgwwqj.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP1080\A0141869.dll Infected: Packed.Win32.TDSS.aa 1
D:\i386\Apps\App17981\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1

Selected area has been scanned.
Hi,

You are clean,

Just need to do some housekeeping now:

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI