This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio Virus Plays Random Advertisements

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, recently I have started to experience a problem where random Audio Advertisements will play, with no windows popping at all. Also my "Wave" section on my master volume panel goes down to completely silent randomly too. This all happened randomly last night and I can not find a way to get rid of it. I have ran AVG, Spybot and Adware removal and they all find nothing.

Here is my HiJackthis Log File:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:53:29 PM, on 6/23/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\System Volume Information\Microsoft\services.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\System Volume Information\Microsoft\smss.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1151188401\ee\AOLSoftware.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\Optimus\My Documents\Downloads\HijackThis.exe

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151188401\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://lioncam1.lmu.edu/activex/AMC.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1ca93522f1c590e) (gupdate1ca93522f1c590e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7494 bytes



I also ran Malware Bytes, and it deleted a few files but I ran again this morning and it found nothing. Thank you for your help, I greatly appreciate it.
Hi and Welcome,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT




Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you for your help, I really appreciate it! I have attached the DDS results under DDS NOTEPAD and DDS ATTACHMENT. I can't give you the Rookit Scanner saved page because everytime I start the scan, my computer restarts 2-3 minutes into it. Sorry for that I'll keep trying to figure it out. Thank you again!!
Here is my DDS in case attachments didnt work. DDS Attachment DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 6/24/2006 2:08:27 PM System Uptime: 6/23/2010 3:30:41 PM (1 hours ago) Motherboard: Gigabyte Technology Co., Ltd. | | G41M-ES2L Processor: Intel Pentium III Xeon processor | Socket 775 | 2666/333mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 153 GiB total, 26.249 GiB free. D: is CDROM (UDF) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 6/23/2010 3:34:09 PM - System Checkpoint RP2: 6/23/2010 3:37:00 PM - Installed Windows Installer Clean Up ==== Installed Programs ====================== AAC Decoder Acrobat.com Ad-Aware SE Personal Adobe AIR Adobe Download Manager 2.0 (Remove Only) Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1 Adobe Shockwave Player Adobe® Photoshop® Album Starter Edition 3.0 Age of Empires III AIM 6 America's Army 3 AOL Uninstaller (Choose which Products to Remove) Apple Mobile Device Support Apple Software Update AutoUpdate AVG Free 8.5 CCleaner CP_CalendarTemplates1 cp_OnlineProjectsConfig CP_Package_Basic1 CP_Panorama1Config cp_PosterPrintConfig Crysis® CustomerResearchQFolder Dawn of War - Soulstorm Demo DeviceFunctionQFolder DeviceManagementQFolder DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Plus Web Player DivX Version Checker eSupportQFolder FullDPAppQFolder GameSpy Comrade getPlus® for Adobe Guild Wars H.264 Decoder Heroes of Newerth HijackThis 2.0.2 Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Deskjet 6900 series HP Extended Capabilities 6.0 HP Imaging Device Functions 6.0 HP Photosmart Premier Software 6.0 HP Solution Center and Imaging Support Tools 6.0 hpf_ProductContext HPProductAssistant IGN Download Manager 2.2.2 InstantShareDevices iPod for Windows 2006-03-23 iPod for Windows 2006-06-28 iTunes Java™ 6 Update 11 Left 4 Dead Demo LP6980_Help LP6980Trb Malwarebytes' Anti-Malware MarketResearch Medieval Total War Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft VC9 runtime libraries MKV Splitter Mozilla Firefox (3.5.9) MSXML 4.0 SP2 (KB973688) Nero PhotoShow Express Norton Security Scan NVIDIA Drivers NVIDIA PhysX Oblivion OpenOffice.org 2.2 PhotoGallery PunkBuster Services RandMap Readme REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB982312) Security Update for 2007 Microsoft Office System (KB982331) Security Update for Microsoft Office Excel 2007 (KB982308) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB982135) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976325) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB982381) SkinsHP1 SolutionCenter Spybot - Search & Destroy Spybot - Search & Destroy 1.4 Status Steam Team Fortress 2 The Battle for Middle-earth ™ II TrayApp Unload Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office OneNote 2007 (KB980729) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Update for Windows XP (KB978207) Update for Windows XP (KB980182) VC80CRTRedist - 8.0.50727.4053 Ventrilo Client Viewpoint Media Player Warcraft III: All Products Warhammer 40,000: Dawn Of War - Gold Edition WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer Clean Up Windows Media Format Runtime Windows Media Player 10 Windows XP Service Pack 3 World of Warcraft ==== Event Viewer Messages From Past Week ======== 6/23/2010 1:30:59 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 6/22/2010 6:54:37 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 6/22/2010 6:39:28 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 6/22/2010 6:39:28 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. ==== End Of File =========================== DDS NOTEPAD DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 16:33:18.34 on Wed 06/23/2010 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2314 [GMT -7:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\AOL\1151188401\ee\AOLSoftware.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Optimus\My Documents\Downloads\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1 uRun: [Steam] c:\program files\steam\Steam.exe -silent uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [igndlm.exe] c:\program files\ign\download manager\DLM.exe /windowsstart /startifwork uRun: [H/PC Connection Agent] "c:\progra~1\mi3aa1~1\wcescomm.exe" uRun: [Aim6] mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HostManager] c:\program files\common files\aol\1151188401\ee\AOLSoftware.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" StartupFolder: c:\docume~1\optimus\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe StartupFolder: c:\documents and settings\optimus\start menu\programs\startup\PowerReg Scheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://lioncam1.lmu.edu/activex/AMC.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\optimus\applic~1\mozilla\firefox\profiles\5oxadeo9.default\ FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;= FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\ign\download manager\npfpdlm.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-13 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-13 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-13 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-13 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-13 297752] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-8 24652] =============== Created Last 30 ================ 2010-06-23 22:37:01 0 d—–w- c:\program files\Windows Installer Clean Up 2010-06-23 08:23:44 0 d—–w- c:\docume~1\optimus\applic~1\Malwarebytes 2010-06-23 08:23:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-23 08:23:37 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-06-23 08:23:37 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-06-23 08:23:37 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-22 23:58:43 452440 —-a-w- c:\windows\system32\d3dx10_40.dll 2010-06-22 23:58:43 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll 2010-06-22 23:58:42 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll 2010-06-22 23:58:35 0 d—–w- c:\windows\Logs 2010-06-22 23:58:21 0 d—–w- c:\program files\Heroes of Newerth ==================== Find3M ==================== 2010-05-08 03:49:28 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2010-05-02 05:22:50 1851264 —-a-w- c:\windows\system32\win32k.sys 2010-04-20 05:30:08 285696 —-a-w- c:\windows\system32\atmfd.dll 2010-04-16 16:09:09 667136 —-a-w- c:\windows\system32\wininet.dll 2010-04-16 16:09:05 81920 —-a-w- c:\windows\system32\ieencode.dll ============= FINISH: 16:33:51.35 ===============
Hi,

Please try this one instead:

Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".

Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.

Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.

Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.

Finally, please open this report with Notepad, and post it here.
Here it is. Thank you again for replying I greatly appreciate it! The problem that might be messing with my scans is that when you tell me to shut down all other windows/programs running, the virus makes it difficult because it starts up ieexplorer in the background with no window, or modifies my volume control by turning down the "wave" section all the way down. I don't know if it affects the scan in anyway just letting you know in case :). Thank you!!! ROOTREPEAL © AD, 2007-2010 ================================================== Report Save Time: 2010/06/24 11:05 Program Version: Version 2.0.0.0 Windows Version: Windows XP SP3 ================================================== STEALTH CODE ——————- System 0xe1e62c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_CLOSE] System 0xe1e62c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_CREATE] System 0xe1e62c30 - Hidden Code [Driver: prodrv06, IRP: IRP_MJ_DEVICE_CONTROL] System 0xe101f838 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_CLOSE] System 0xe101f838 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_CREATE] System 0xe101f838 - Hidden Code [Driver: prohlp02, IRP: IRP_MJ_DEVICE_CONTROL]
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thank you again for your help !!

ComboFix 10-06-24.01 - Optimus 06/24/2010 18:20:30.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2621 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-05-25 to 2010-06-25 )))))))))))))))))))))))))))))))
.

2010-06-23 22:37 . 2010-06-23 22:37 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\Optimus\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-22 23:58 . 2008-10-10 11:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-06-22 23:58 . 2010-06-22 23:58 ——– d—–w- c:\windows\Logs
2010-06-22 23:58 . 2010-06-22 23:59 ——– d—–w- c:\program files\Heroes of Newerth

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-25 01:33 . 2006-07-27 20:12 ——– d—–w- c:\program files\Steam
2010-06-25 00:22 . 2007-10-26 22:00 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-06-24 18:51 . 2006-06-24 21:44 ——– d—–w- c:\program files\Warcraft III
2010-06-23 22:37 . 2010-06-23 22:37 3584 —-a-r- c:\documents and settings\Optimus\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-06-23 22:36 . 2009-12-16 22:48 ——– d—–w- c:\program files\MSECACHE
2010-06-23 22:23 . 2007-06-20 04:34 ——– d—–w- c:\program files\Google
2010-06-23 21:56 . 2006-06-24 21:13 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-23 21:56 . 2006-06-24 21:21 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-23 21:51 . 2006-06-26 23:54 ——– d—–w- c:\program files\Java
2010-06-23 08:16 . 2009-08-26 04:53 ——– d—–w- c:\program files\LimeWire
2010-06-23 08:12 . 2006-11-08 05:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-23 08:00 . 2009-05-15 00:12 ——– d—–w- c:\program files\CCleaner
2010-06-23 01:57 . 2006-06-25 21:38 ——– d—–w- c:\program files\WC3Banlist
2010-06-23 01:55 . 2006-11-18 22:57 ——– d—–w- c:\program files\Electronic Arts
2010-06-17 06:57 . 2006-06-25 16:34 ——– d—–w- c:\program files\World of Warcraft
2010-06-09 08:15 . 2007-09-10 06:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-08 03:49 . 2010-05-08 03:49 ——– d—–w- c:\documents and settings\Optimus\Application Data\SPORE
2010-05-08 03:49 . 2006-08-14 21:19 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 17:50 . 2006-08-29 03:39 ——– d—–w- c:\documents and settings\Optimus\Application Data\OpenOffice.org2
2010-04-20 05:30 . 2004-08-04 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2004-08-04 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-04-14 15:57 . 2009-11-09 19:46 79488 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-05-08 1238352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2009-05-15 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HostManager"="c:\program files\Common Files\AOL\1151188401\ee\AOLSoftware.exe" [2006-05-10 50760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\[removed]\\team fortress classic\\hl.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6108-to-2.0.2.6144-enUS-downloader.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6144-to-2.0.2.6178-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.3.6282-to-2.0.3.6299-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead demo\\left4dead.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"2720:UDP"= 2720:UDP:Windows Media Format SDK (iexplore.exe)
"2721:UDP"= 2721:UDP:Windows Media Format SDK (iexplore.exe)
"2729:UDP"= 2729:UDP:Windows Media Format SDK (iexplore.exe)
"2728:UDP"= 2728:UDP:Windows Media Format SDK (iexplore.exe)
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/8/2009 8:12 PM 24652]
.
Contents of the 'Scheduled Tasks' folder

2010-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]

2010-06-25 c:\windows\Tasks\Norton Security Scan for Optimus.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 14:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://lioncam1.lmu.edu/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;=
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-HP Software Update - c:\program files\HP\HP Software Update\HPWuSchd2.exe
Notify-avgrsstarter - (no file)
AddRemove-KB913433 - c:\windows\system32\MacroMed\Flash\genuinst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-24 18:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:26,fc,c1,ca,41,a1,9b,41,7b,e3,87,70,66,de,ee,2c,f2,f2,7c,49,5c,5f,54,
16,04,c6,27,74,f4,bc,e6,df,83,9d,a4,79,f6,2a,21,f3,9a,8a,b7,a0,b4,8a,78,32,\
"??"=hex:f0,21,15,d4,32,f9,f5,39,34,a4,1c,86,43,ce,d9,df

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:8b,f7,b7,24,e0,f4,3b,7c,50,28,8c,77,aa,e3,23,9b,fd,4c,23,5b,36,
7a,c4,21,4a,55,8a,2e,37,93,88,0f,f5,e6,71,fd,7d,79,fb,ac,2d,c6,7f,81,1d,00,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
———————— Other Running Processes ————————
.
c:\system volume information\Microsoft\services.exe
c:\windows\system32\nvsvc32.exe
c:\system volume information\Microsoft\smss.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\msiexec.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2010-06-24 18:38:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-25 01:38

Pre-Run: 28,356,505,600 bytes free
Post-Run: 28,269,768,704 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 0182B44A659F819115A3A84559B79994
Hi,

Did you set these protocols yourself?

"2720:UDP"= 2720:UDP:Windows Media Format SDK (iexplore.exe)
"2721:UDP"= 2721:UDP:Windows Media Format SDK (iexplore.exe)
"2729:UDP"= 2729:UDP:Windows Media Format SDK (iexplore.exe)
"2728:UDP"= 2728:UDP:Windows Media Format SDK (iexplore.exe)



Please do the following:

  • Open your Malwarebytes' Anti-Malware program and select the update tab, select update now
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi, Thank you again, to answer your question no I did not set any of those protocols, I don't even know what protocols are to set them up :blush: Here is the mbam report: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4239 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 6/25/2010 11:10:28 AM mbam-log-2010-06-25 (11-10-28).txt Scan type: Quick scan Objects scanned: 121918 Time elapsed: 5 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And here is the Kaspersky: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, June 25, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, June 25, 2010 14:56:40 Records in database: 4301363 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 107222 Threats found: 3 Infected objects found: 8 Suspicious objects found: 0 Scan duration: 02:20:50 File name / Threat / Threats count C:\Backup\MusicMP3\LimeWireWin.exe Infected: not-a-virus:AdWare.Win32.TopMoxie.c 1 C:\Documents and Settings\Optimus\Incomplete\T-5516057-heat 50 cent extended version.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\Optimus\Incomplete\T-5970745-rock soundtrack hans zimmerman new single.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\Optimus\Shared\birthday sex fast new single.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\Optimus\Shared\birthday sex fast [club mix].mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\Optimus\Shared\canon camera commercial song (unreleased live record).mp3 Infected: Trojan-Downloader.WMA.GetCodec.af 1 C:\Documents and Settings\Optimus\Shared\###### da police nwa - bonus track.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\Optimus\Shared\michael montes new single.mp3 Infected: Trojan-Downloader.WMA.GetCodec.af 1 Selected area has been scanned.
Hi,

Please do the following:

note

one of the titles has a bunch of ####### in the title name, I suspect that is a swear word that forum software has bleeped out…please change it to the correct word for the fix or it will not be deleted.




  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Backup\MusicMP3\LimeWireWin.exe 
C:\Documents and Settings\Optimus\Incomplete\T-5516057-heat 50 cent extended version.mp3 
C:\Documents and Settings\Optimus\Incomplete\T-5970745-rock soundtrack hans zimmerman new single.mp3 
C:\Documents and Settings\Optimus\Shared\birthday sex fast new single.mp3 I
C:\Documents and Settings\Optimus\Shared\birthday sex fast [club mix].mp3 
C:\Documents and Settings\Optimus\Shared\canon camera commercial song (unreleased live record).mp3
C:\Documents and Settings\Optimus\Shared\###### da police nwa - bonus track.mp3 
C:\Documents and Settings\Optimus\Shared\michael montes new single.mp3 

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2720:UDP"=-
"2721:UDP"=-
"2729:UDP"=-
"2728:UDP"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise how your computer is running now and if there are any outstanding issues.
Hi,

Thank you for your continued help!! I did the scan and for 20 minutes there have been no audio advertisements, or pop ups, or an uncontrolled change in the audio control. I will let you know if this positive outcome continues. Here is the log you asked for:

ComboFix 10-06-25.04 - Optimus 06/26/2010 11:17:08.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2552 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Optimus\Desktop\CFScript.txt

FILE ::
"c:\backup\MusicMP3\LimeWireWin.exe"
"c:\documents and settings\Optimus\Incomplete\T-5516057-heat 50 cent extended version.mp3"
"c:\documents and settings\Optimus\Incomplete\T-5970745-rock soundtrack hans zimmerman new single.mp3"
"c:\documents and settings\Optimus\Shared\birthday sex fast [club mix].mp3"
"c:\documents and settings\Optimus\Shared\birthday sex fast new single.mp3 I"
"c:\documents and settings\Optimus\Shared\canon camera commercial song (unreleased live record).mp3"
"c:\documents and settings\Optimus\Shared\hug da police nwa - bonus track.mp3"
"c:\documents and settings\Optimus\Shared\michael montes new single.mp3"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\backup\MusicMP3\LimeWireWin.exe
c:\documents and settings\Optimus\Incomplete\T-5516057-heat 50 cent extended version.mp3
c:\documents and settings\Optimus\Incomplete\T-5970745-rock soundtrack hans zimmerman new single.mp3
c:\documents and settings\Optimus\Shared\birthday sex fast [club mix].mp3
c:\documents and settings\Optimus\Shared\canon camera commercial song (unreleased live record).mp3
c:\documents and settings\Optimus\Shared\hug da police nwa - bonus track.mp3
c:\documents and settings\Optimus\Shared\michael montes new single.mp3

.
((((((((((((((((((((((((( Files Created from 2010-05-26 to 2010-06-26 )))))))))))))))))))))))))))))))
.

2010-06-23 22:37 . 2010-06-23 22:37 3584 —-a-r- c:\documents and settings\Optimus\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-06-23 22:37 . 2010-06-23 22:37 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\Optimus\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-23 08:23 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-22 23:58 . 2008-10-10 11:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll
2010-06-22 23:58 . 2008-10-10 11:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-06-22 23:58 . 2010-06-22 23:58 ——– d—–w- c:\windows\Logs
2010-06-22 23:58 . 2010-06-22 23:59 ——– d—–w- c:\program files\Heroes of Newerth

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-26 17:57 . 2006-07-27 20:12 ——– d—–w- c:\program files\Steam
2010-06-25 00:22 . 2007-10-26 22:00 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-06-24 18:51 . 2006-06-24 21:44 ——– d—–w- c:\program files\Warcraft III
2010-06-23 22:36 . 2009-12-16 22:48 ——– d—–w- c:\program files\MSECACHE
2010-06-23 22:23 . 2007-06-20 04:34 ——– d—–w- c:\program files\Google
2010-06-23 21:56 . 2006-06-24 21:13 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-23 21:56 . 2006-06-24 21:21 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-23 21:51 . 2006-06-26 23:54 ——– d—–w- c:\program files\Java
2010-06-23 08:16 . 2009-08-26 04:53 ——– d—–w- c:\program files\LimeWire
2010-06-23 08:12 . 2006-11-08 05:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-23 08:00 . 2009-05-15 00:12 ——– d—–w- c:\program files\CCleaner
2010-06-23 01:57 . 2006-06-25 21:38 ——– d—–w- c:\program files\WC3Banlist
2010-06-23 01:55 . 2006-11-18 22:57 ——– d—–w- c:\program files\Electronic Arts
2010-06-17 06:57 . 2006-06-25 16:34 ——– d—–w- c:\program files\World of Warcraft
2010-06-09 08:15 . 2007-09-10 06:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-08 03:49 . 2010-05-08 03:49 ——– d—–w- c:\documents and settings\Optimus\Application Data\SPORE
2010-05-08 03:49 . 2006-08-14 21:19 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 17:50 . 2006-08-29 03:39 ——– d—–w- c:\documents and settings\Optimus\Application Data\OpenOffice.org2
2010-04-20 05:30 . 2004-08-04 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2004-08-04 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-04-14 15:57 . 2009-11-09 19:46 79488 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-05-08 1238352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2009-05-15 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HostManager"="c:\program files\Common Files\AOL\1151188401\ee\AOLSoftware.exe" [2006-05-10 50760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aim6.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\[removed]\\team fortress classic\\hl.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6108-to-2.0.2.6144-enUS-downloader.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6144-to-2.0.2.6178-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.3.6282-to-2.0.3.6299-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead demo\\left4dead.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Burning Crusade Closed Beta\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/8/2009 8:12 PM 24652]
.
Contents of the 'Scheduled Tasks' folder

2010-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]

2010-06-25 c:\windows\Tasks\Norton Security Scan for Optimus.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 14:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://lioncam1.lmu.edu/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;=
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-26 11:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:26,fc,c1,ca,41,a1,9b,41,7b,e3,87,70,66,de,ee,2c,f2,f2,7c,49,5c,5f,54,
16,04,c6,27,74,f4,bc,e6,df,83,9d,a4,79,f6,2a,21,f3,9a,8a,b7,a0,b4,8a,78,32,\
"??"=hex:f0,21,15,d4,32,f9,f5,39,34,a4,1c,86,43,ce,d9,df

[HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:8b,f7,b7,24,e0,f4,3b,7c,50,28,8c,77,aa,e3,23,9b,fd,4c,23,5b,36,
7a,c4,21,4a,55,8a,2e,37,93,88,0f,f5,e6,71,fd,7d,79,fb,ac,2d,c6,7f,81,1d,00,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
Completion time: 2010-06-26 11:23:43
ComboFix-quarantined-files.txt 2010-06-26 18:23
ComboFix2.txt 2010-06-25 01:38

Pre-Run: 28,094,042,112 bytes free
Post-Run: 28,238,163,968 bytes free

- - End Of File - - 31249598B734DBABF0793999B6917599
Hi,

Please do the following


Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 20 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 20 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



NEXT



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Download OTC to your desktop, double click the icon to run it.
  • Click on Clean Up!
  • Click Yes to begin the Cleanup process.
  • You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thank you for all your help I will do everything you just said, but the symptoms have returned. There are no pop ups, but I am window'd everytime I am running another program because on my sound control area the "wave" sections keep being muted. There is an iexplorer running in the background that always turns on by itself. thanks
can you please explain in more detail what you mean

what do you mean by window'd

what area are you referring to that is muted? can you get a screen shot?

please run the following programs:




Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.



next


Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".

Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.

Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.

Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.

Finally, please open this report with Notepad, and post it here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI