This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Combo Fix Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Below is the log following a Combofix application. Do I need to do anything else?

ComboFix 10-01-14.02 - Mike 01/15/2010 0:11.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.104 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
FW: eTrust EZ Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mike\My Documents\ZbThumbnail.info
c:\windows\Fonts\acrsec.fon
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\25667.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\bszip.dll
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\SYSTEM32\oVDNoUtv.ini
c:\windows\SYSTEM32\oVDNoUtv.ini2
c:\windows\system32\smss32.exe
c:\windows\system32\srcr.dat
c:\windows\system32\warning.html
c:\windows\system32\windows.txt
c:\windows\system32\winlogon32.exe
c:\windows\uguqahivafecuj.dll
c:\windows\unins000.dat
c:\windows\unins000.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.

2010-01-15 04:58 . 2009-05-13 21:30 13360 —-a-w- c:\windows\system32\drivers\sbaphd.sys
2010-01-15 02:29 . 2010-01-15 02:29 ——– d–h–w- c:\windows\PIF
2010-01-15 02:24 . 2009-08-11 00:06 69936 —-a-w- c:\windows\system32\drivers\sbapifs.sys
2010-01-14 14:15 . 2010-01-14 14:15 0 —-a-w- c:\windows\Vhizoxutu.bin
2010-01-14 14:15 . 2010-01-15 04:49 120 —-a-w- c:\windows\Lgeruxe.dat
2010-01-14 14:15 . 2010-01-14 14:15 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
2010-01-13 08:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-13 03:23 . 2010-01-13 03:23 ——– d—–w- c:\program files\gs
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\program files\PlotSoft
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2010-01-09 02:06 . 2010-01-09 02:06 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Unity
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\documents and settings\Mike\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\program files\PCPitstop
2010-01-06 13:52 . 2010-01-06 13:52 ——– d-sh–w- c:\documents and settings\Mike\IECompatCache
2010-01-05 12:55 . 2010-01-05 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-01-05 03:05 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 03:05 . 2010-01-05 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-05 03:05 . 2010-01-05 12:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 03:05 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 22:02 . 2010-01-04 22:02 27984 —-a-w- c:\windows\system32\sbbd.exe
2010-01-04 14:10 . 2010-01-04 14:10 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-01-04 00:44 . 2010-01-04 00:44 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-30 20:26 . 2009-12-30 20:26 ——– d—–w- c:\program files\Mars
2009-12-20 00:55 . 2009-12-20 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-18 01:10 . 2009-12-18 01:10 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2009-12-18 00:57 . 2009-12-18 00:57 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-18 00:55 . 2009-12-18 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 20:27 . 2009-12-30 20:27 8854 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\UNINST_Uninstall_M_574736E157BD413B8CA82945F94185CE.exe
2009-12-30 20:27 . 2009-12-30 20:27 40960 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\ARPPRODUCTICON.exe
2009-12-25 02:38 . 2009-10-09 00:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-18 01:09 . 2005-04-14 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-18 00:55 . 2009-12-18 00:55 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-13 22:03 . 2009-06-06 11:58 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-11-25 13:36 . 2009-11-25 13:36 ——– d—–w- c:\documents and settings\Mike\Application Data\EPSON
2009-11-21 16:05 . 2008-03-29 00:45 56412 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51 . 2004-08-04 10:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-21 14:52 . 2005-04-30 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Apple Computer
2009-11-21 14:30 . 2009-11-21 14:29 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-21 14:30 . 2007-09-18 02:15 ——– d—–w- c:\program files\iTunes
2009-11-21 14:30 . 2005-04-30 12:54 ——– d—–w- c:\program files\iPod
2009-11-21 14:30 . 2007-08-03 15:24 ——– d—–w- c:\program files\Common Files\Apple
2009-11-21 14:27 . 2007-08-03 15:26 ——– d—–w- c:\program files\QuickTime
2009-11-21 14:21 . 2009-11-21 14:21 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-20 11:08 . 2009-12-18 00:58 38784 —-a-w- c:\documents and settings\Mike\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 11:08 . 2009-12-18 00:57 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2006-12-03 19:10 . 2006-11-02 02:46 56 –sha-r- c:\windows\SYSTEM32\95AC9DE08A.sys
2009-08-23 13:27 . 2006-11-02 02:41 3402 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe

2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\bak\isuspm.exe
2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

2005-05-05 22:38 . 2005-05-05 22:38 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

2004-01-07 06:01 . 2004-01-07 06:01 110592 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe

2005-04-08 05:31 . 2004-10-12 21:54 57344 c:\program files\CyberLink\PowerDVD\bak\DVDLauncher.exe

2007-03-15 15:09 . 2007-03-15 15:09 460784 c:\program files\DellSupport\bak\DSAgnt.exe

2005-06-21 22:55 . 2005-05-18 18:49 282624 c:\program files\DIGStream\bak\digstream.exe

2005-06-21 22:56 . 2005-05-19 17:55 101888 c:\program files\ESPNRunTime\bak\DIGServices.exe

2007-09-07 20:55 . 2007-09-07 20:55 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2009-11-12 21:33 . 2009-11-12 21:33 141600 c:\program files\iTunes\iTunesHelper.exe

2007-03-04 13:36 . 2006-12-15 08:23 75520 c:\program files\Java\jre1.5.0_11\bin\bak\jusched.exe

2005-05-07 02:51 . 2005-03-12 11:25 11776 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe

2005-04-08 05:44 . 2005-03-12 11:25 110592 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe

2005-10-06 02:31 . 2005-10-06 02:31 335872 c:\program files\Picasa2\bak\PicasaMediaDetector.exe

2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2009-11-11 04:08 . 2009-11-11 04:08 417792 c:\program files\QuickTime\QTTask.exe

2007-03-15 16:57 . 2007-03-15 16:57 356197 c:\program files\SlySoft\AnyDVD\bak\AnyDVD.exe

2003-01-31 10:20 . 2005-10-18 19:33 1921024 c:\program files\Support.com\bin\bak\tgcmd.exe

2007-08-17 13:17 . 2006-05-02 19:51 3334144 c:\program files\Yahoo!\Messenger\bak\YAHOOM~1.EXE

2006-06-22 20:21 . 2006-06-22 20:21 5541888 c:\program files\Yahoo!\Yahoo! Music Engine\bak\YahooMusicEngine.exe

2004-08-04 10:00 . 2004-08-04 10:00 15360 c:\windows\SYSTEM32\bak\ctfmon.exe
2004-08-04 10:00 . 2008-04-14 00:12 15360 c:\windows\SYSTEM32\ctfmon.exe

1980-01-01 05:00 . 2005-10-14 18:46 77824 c:\windows\SYSTEM32\bak\hkcmd.exe
2004-08-20 20:51 . 2004-08-20 20:51 118784 c:\windows\SYSTEM32\hkcmd.exe

2005-10-14 18:50 . 2005-10-14 18:50 114688 c:\windows\SYSTEM32\bak\igfxpers.exe

1980-01-01 05:00 . 2005-10-14 18:49 94208 c:\windows\SYSTEM32\bak\igfxtray.exe
2004-08-20 20:55 . 2004-08-20 20:55 155648 c:\windows\SYSTEM32\igfxtray.exe

2005-04-08 05:48 . 2004-12-06 06:05 127035 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"TCOYFReminder"="c:\progra~1\TCOYF\tcoyftray.exe" [2006-09-19 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"weiyuan"="c:\windows\system32\weiyuan.exe" [N/A]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"igfxpers"="c:\windows\system32\igfxpers.exe" [N/A]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]
"Frusaji"="c:\windows\uguqahivafecuj.dll" [N/A]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2010-01-04 959824]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-4-8 24576]
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex Enhanced G USB Network Adapter\DynexWCUI.exe [2009-2-28 1462272]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-23 278528]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2004-08-20 20:51 118784 —-a-w- c:\windows\SYSTEM32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2004-08-20 20:55 155648 —-a-w- c:\windows\SYSTEM32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 sbaphd;sbaphd;c:\windows\SYSTEM32\DRIVERS\sbaphd.sys [01/14/2010 11:58 PM 13360]
R1 sbtis;sbtis;c:\windows\SYSTEM32\DRIVERS\sbtis.sys [01/12/2009 9:48 PM 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [01/04/2010 5:02 PM 1012080]
R2 sbapifs;sbapifs;c:\windows\SYSTEM32\DRIVERS\sbapifs.sys [01/14/2010 9:24 PM 69936]
R2 SVKP;SVKP;c:\windows\SYSTEM32\SVKP.sys [10/26/2006 9:04 PM 2368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [01/10/2007 9:45 PM 24652]
R3 NdisWDM;Dynex Enhanced Wireless G USB Network Adapter Service;c:\windows\SYSTEM32\DRIVERS\NdisWDM.sys [02/28/2009 1:51 PM 198144]
S2 phnvcx;phnvcx;c:\windows\system32\svchost.exe -k phnvcx [08/04/2004 5:00 AM 14336]
S2 ProtectsStore;RtoAutos;c:\program files\NetMeeting\smss.exe –> c:\program files\NetMeeting\smss.exe [?]
S2 PssInsv;Prints Spoolers Services;c:\program files\System\svchost.exe –> c:\program files\System\svchost.exe [?]
S2 yhnvcxjc;yhnvcxjc;\??\c:\windows\system32\drivers\xbllsk.sys –> c:\windows\system32\drivers\xbllsk.sys [?]
S3 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [10/13/2009 8:22 AM 95024]
S3 zsi_fmw;Stiletto Firmware Recovery;c:\windows\SYSTEM32\DRIVERS\zsi_fmw.sys [08/18/2009 8:02 PM 34176]
S3 zsi_fw;Stiletto 100 Firmware Upgrade Driver;c:\windows\SYSTEM32\DRIVERS\zsi_fw.sys [07/31/2006 10:32 PM 16768]
S3 zsi_zap;Stiletto ZAP Recovery Driver;c:\windows\SYSTEM32\DRIVERS\zsi_zap.sys [07/29/2006 5:22 PM 16896]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [01/06/2010 9:31 AM 85504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
phnvcx REG_MULTI_SZ phnvcx
.
Contents of the 'Scheduled Tasks' folder

2010-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: doginhispen.com
Trusted Zone: whataboutadog.com
Trusted Zone: musicmatch.com\online
DPF: ESPNJavaUtilsCab - hxxp://espn.go.com/livedraft/ESPNJavaUtils.cab
DPF: {81449547-EB5D-422E-8730-932DC5E412C8} - hxxp://www.howardstern.com/install/uvuplayer.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\y1x13hd9.default\
FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {5093D286-E7B3-452F-B4AF-628E916F0B0D} - c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
.
- - - - ORPHANS REMOVED - - - -

BHO-{7C4DEBE7-FB8A-43C7-B81B-808424465C10} - c:\windows\system32\vtUoNDVo.dll
ShellExecuteHooks-{FB703367-5B9A-4F41-B5C6-85F618DD9A57} - (no file)
AddRemove-Giggles-Shapes_is1 - c:\program files\Giggles Computer Funtime For Baby\Giggles-Shapes\unins000.exe
AddRemove-{184EB198-1DBA-46DB-B728-7A5FC13D5C2B}_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 00:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
weiyuan = c:\windows\system32\weiyuan.exe?????????????????X???????8?????A~?`??????|???P??????????|p??|????m??|

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(792)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(1668)
c:\windows\system32\WININET.dll
c:\program files\Sunbelt Software\VIPRE\oehook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
.
———————— Other Running Processes ————————
.
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-15 00:30:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 05:30

Pre-Run: 38,433,792,000 bytes free
Post-Run: 40,025,231,360 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 5427D6D2B3A84C3359013BCF9429C171
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI