Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93105 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Pc Running Slow With Many Popups


  • This topic is locked This topic is locked
10 replies to this topic

#1 skoly

skoly

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 01 June 2007 - 07:18 PM

I am getting a constant barrage of popup ads, please help.

I ran Spybot, Adaware, Ewido, ATF Cleaner, Hijack this...

Logfile of HijackThis v1.99.1
Scan saved at 9:10:49 PM, on 6/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp3C.tmp.dll
O2 - BHO: SpoofBHO Class - {F67EEB12-AB09-11DB-A6F1-260856D89593} - C:\WINDOWS\se_spoof.dll (file missing)
O2 - BHO: (no name) - {fbcbe0d6-19ab-4e99-8a0b-9c148b1d6e31} - C:\WINDOWS\system32\kbdr32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\hgfddb.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: kbdr32 - C:\WINDOWS\SYSTEM32\kbdr32.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    Advertisements

Register to Remove


#2 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 02 June 2007 - 10:32 AM

Hi skoly ,

Welcome to Tom Coyote Forums

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
If you can do these things, everything should go smoothly.

Ready? Let's go.

*=========================*

Download Combofix by sUBs! from
http://download.blee...Bs/combofix.exe
Save it to your Desktop
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log C:\ComboFix.txt
Post that log in your next reply

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
*=========================*

Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*

Please post the following;

New hijackthis log
Combofix log
uninstall list

Thanks,

Rogue
Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

#3 skoly

skoly

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 02 June 2007 - 01:20 PM

Hi skoly ,

Welcome to Tom Coyote Forums

Please observe these rules while we work:

  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
If you can do these things, everything should go smoothly.

Ready? Let's go.

*=========================*

Download Combofix by sUBs! from
http://download.blee...Bs/combofix.exe
Save it to your Desktop
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log C:\ComboFix.txt
Post that log in your next reply

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
*=========================*

Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*

Please post the following;

New hijackthis log
Combofix log
uninstall list

Thanks,

Rogue


The combofix link you gave me was not working = 404 notfound

I have posted the New Hijackthis log and uninstall list.

Skoly

Logfile of HijackThis v1.99.1
Scan saved at 3:17:37 PM, on 6/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp13B.tmp.dll
O2 - BHO: SpoofBHO Class - {F67EEB12-AB09-11DB-A6F1-260856D89593} - C:\WINDOWS\se_spoof.dll (file missing)
O2 - BHO: (no name) - {fbcbe0d6-19ab-4e99-8a0b-9c148b1d6e31} - C:\WINDOWS\system32\kbdr32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\yaxvus.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: kbdr32 - C:\WINDOWS\SYSTEM32\kbdr32.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Ad-Aware SE Personal
Adobe Acrobat - Reader 6.0.2 Update
Adobe After Effects 7.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe ExtendScript Toolkit 1.0
Adobe Flash Player 9 ActiveX
Adobe Help Center 2.0
Adobe Photoshop CS
Adobe Photoshop CS2
Adobe Premiere Pro 2.0
Adobe Reader 6.0.1
Adobe Stock Photos 1.0
Adobe Stock Photos 1.0
AIM 6.0
ALPS Touch Pad Driver
AOL Instant Messenger
AOLIcon
Apple Software Update
AVG Anti-Spyware 7.5
BitComet 0.85
Broadcom Management Programs 2
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon ZoomBrowser EX (E)
CCleaner (remove only)
Conexant D110 MDC V.9x Modem
Corel Photo Album 6
Creative MediaSource
Creative MuVo N200 Media Explorer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
DellSupport
Digital Content Portal
Digital Line Detect
DivX
DivX Player
DivX Web Player
EducateU
ESPN Digital Games XGames Pro Boarder
ESPNMotion
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Intel® Graphics Media Accelerator Driver for Mobile
Intel® PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
IsoBuster 2.0
iTunes
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03
Java™ SE Runtime Environment 6 Update 1
Learn2 Player (Uninstall Only)
Macromedia Extension Manager
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8
Macromedia Flash Player 8 Plugin
Macromedia Shockwave Player
Mario Forever v 2.16 !
mCore
mDrWiFi
Media Center Extender
Media Center Extender
mHlpDell
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Premium
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
mIWA
mIWCA
mLogView
mMHouse
Modem Helper
Move Networks Player for Internet Explorer
Mpeg2Decoder 1.1
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
mToolkit
MuVo Driver
mWlsSafe
mXML
mZConfig
Need For Speed High Stakes
Nero Suite
NETGEAR Print Server Software
NetWaiting
Otto
Photo Loader 3.0E
PhotoNow! 1.0
PowerDirector
Quicklinks
QuickSet
QuickTime
RealPlayer
RollerCoaster Tycoon 3
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SmartSound Quicktracks Plugin
Sonic DLA
Sonic Encoders
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy 1.4
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WebCyberCoach 3.2 Dell
WinAce Archiver
Windows Defender
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890927
Windows XP Media Center Edition 2005 KB905589
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
WordPerfect Office 12

#4 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 02 June 2007 - 01:29 PM

My fault. Sorry
Try one of these two
http://www.techsuppo...Bs/ComboFix.exe
or
http://download.blee...Bs/ComboFix.exe
Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

#5 skoly

skoly

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 02 June 2007 - 02:27 PM

My fault. Sorry
Try one of these two
http://www.techsuppo...Bs/ComboFix.exe
or
http://download.blee...Bs/ComboFix.exe


Here is the Combofix results

Skoly

"Dan" - 2007-06-02 16:03:18 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Dan\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


"C:\WINDOWS\b.exe"
"C:\WINDOWS\system32\tmp10.tmp.dll"
"C:\WINDOWS\system32\tmp10E.tmp.dll"
"C:\WINDOWS\system32\tmp11D.tmp.dll"
"C:\WINDOWS\system32\tmp12.tmp.dll"
"C:\WINDOWS\system32\tmp13B.tmp.dll"
"C:\WINDOWS\system32\tmp16.tmp.dll"
"C:\WINDOWS\system32\tmp29.tmp.dll"
"C:\WINDOWS\system32\tmp3C.tmp.dll"
"C:\WINDOWS\system32\tmp59.tmp.dll"
"C:\WINDOWS\system32\tmp6E.tmp.dll"
"C:\WINDOWS\system32\tmp6E5.tmp.dll"
"C:\WINDOWS\system32\tmp87.tmp.dll"
"C:\WINDOWS\system32\tmp880.tmp.dll"
"C:\WINDOWS\system32\tmp881.tmp.dll"
"C:\WINDOWS\system32\tmp88E.tmp.dll"
"C:\WINDOWS\system32\tmp98.tmp.dll"
"C:\WINDOWS\system32\tmp9C.tmp.dll"
"C:\WINDOWS\system32\tmpD.tmp.dll"
"C:\WINDOWS\system32\tmpEC.tmp.dll"
"C:\WINDOWS\system32\tmpF9.tmp.dll"
"C:\WINDOWS\system32bez6n4r21.exe"


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_NETWORK_MONITOR
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS


((((((((((((((((((((((((((((((( Files Created from 2007-05-02 to 2007-06-02 ))))))))))))))))))))))))))))))))))


2007-06-02 15:10 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp13E.tmp.exe
2007-06-02 15:09 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp13C.tmp.exe
2007-06-02 15:09 106,455 --a------ C:\WINDOWS\yaxvus.dll
2007-06-02 12:13 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp11D.tmp.exe
2007-06-02 12:13 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp120.tmp.exe
2007-06-02 12:13 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp11E.tmp.exe
2007-06-02 11:35 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp111.tmp.exe
2007-06-02 11:34 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp10E.tmp.exe
2007-06-02 11:01 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpF9.tmp.exe
2007-06-02 10:50 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpF3.tmp.exe
2007-06-02 10:49 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpEC.tmp.exe
2007-06-02 10:49 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpED.tmp.exe
2007-06-02 10:49 106,583 --a------ C:\WINDOWS\mlmnmn.dll
2007-06-02 00:48 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp9F.tmp.exe
2007-06-02 00:47 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp9C.tmp.exe
2007-06-02 00:41 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp9B.tmp.exe
2007-06-02 00:40 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp98.tmp.exe
2007-06-02 00:18 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp87.tmp.exe
2007-06-02 00:18 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp8A.tmp.exe
2007-06-02 00:18 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp88.tmp.exe
2007-06-01 23:06 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp5C.tmp.exe
2007-06-01 23:05 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp59.tmp.exe
2007-06-01 23:05 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp5A.tmp.exe
2007-06-01 23:05 106,543 --a------ C:\WINDOWS\pmlkij.dll
2007-06-01 22:26 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp29.tmp.exe
2007-06-01 22:26 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp2C.tmp.exe
2007-06-01 22:26 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp2A.tmp.exe
2007-06-01 22:15 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp1B.tmp.exe
2007-06-01 22:14 233,695 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp1A.tmp.exe
2007-06-01 22:14 106,411 --a------ C:\WINDOWS\ljgdef.dll
2007-06-01 22:10 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp16.tmp.exe
2007-06-01 22:10 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp17.tmp.exe
2007-06-01 21:25 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp15.tmp.exe
2007-06-01 21:24 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp13.tmp.exe
2007-06-01 21:23 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp12.tmp.exe
2007-06-01 21:11 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp10.tmp.exe
2007-06-01 20:30 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-06-01 20:29 233,592 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp45.tmp.exe
2007-06-01 20:29 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp46.tmp.exe
2007-06-01 20:29 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp44.tmp.exe
2007-06-01 20:29 106,534 --a------ C:\WINDOWS\hgfddb.dll
2007-06-01 20:25 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp3C.tmp.exe
2007-06-01 20:04 49,664 --a------ C:\Program Files\ATF-Cleaner.exe
2007-06-01 20:03 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpD.tmp.exe
2007-06-01 20:03 233,556 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpE.tmp.exe
2007-06-01 20:03 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpF.tmp.exe
2007-06-01 20:02 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpB.tmp.exe
2007-06-01 17:27 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-01 14:48 233,646 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp70.tmp.exe
2007-06-01 14:48 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp71.tmp.exe
2007-06-01 14:48 106,524 --a------ C:\WINDOWS\jkhiih.dll
2007-06-01 14:47 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp6E.tmp.exe
2007-05-31 23:49 3,098,056 --a------ C:\Program Files\LimeWireWin.exe
2007-05-31 23:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-05-31 21:25 232,881 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp890.tmp.exe
2007-05-31 21:24 51,308 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp88E.tmp.exe
2007-05-31 19:07 232,910 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp883.tmp.exe
2007-05-31 19:07 106,393 --a------ C:\WINDOWS\cbxusr.dll
2007-05-31 19:06 50,861 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp881.tmp.exe
2007-05-31 19:06 50,861 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp880.tmp.exe
2007-05-31 18:09 233,709 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp6E9.tmp.exe
2007-05-31 18:08 50,946 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp6E5.tmp.exe
2007-05-31 17:58 48,015 --a------ C:\WINDOWS\system32\geedd.exe
2007-05-31 17:58 37,481 --a------ C:\WINDOWS\system32\kbdr32.dll
2007-05-31 17:56 <DIR> d--hs---- C:\UWA7P
2007-05-31 17:55 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor
2007-05-31 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
2007-05-31 17:53 12,494 --a------ C:\WINDOWS\system32\vtsqnml.dll
2007-05-31 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SMSI
2007-05-10 03:33 <DIR> d-------- C:\Program Files\DellSupport
2007-05-06 16:06 <DIR> d-------- C:\Program Files\Smart Projects


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-01 23:51:45 -------- d-----w C:\Program Files\Common Files\Companion Wizard
2007-06-01 21:29:12 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
2007-06-01 19:35:49 -------- d-----w C:\Program Files\Trend Micro
2007-06-01 18:43:44 -------- d-----w C:\Program Files\LimeWire
2007-05-20 15:41:45 56 --sh--r C:\WINDOWS\system32\B4AD4EF6ED.sys
2007-05-20 15:41:45 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-10 07:39:04 -------- d--h--w C:\DOCUME~1\Dan\APPLIC~1\Gtek
2007-04-30 01:25:46 -------- d-----w C:\DOCUME~1\Dan\APPLIC~1\AdobeUM
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-04 15:58:49 -------- d-----w C:\Program Files\GemMaster
2007-04-04 15:58:19 -------- d-----w C:\Program Files\PokerStars
2007-04-04 15:57:59 -------- d-----w C:\Program Files\Project64 1.6
2007-03-29 22:26:07 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll []
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{F67EEB12-AB09-11DB-A6F1-260856D89593}=C:\WINDOWS\se_spoof.dll []
{fbcbe0d6-19ab-4e99-8a0b-9c148b1d6e31}=C:\WINDOWS\system32\kbdr32.dll [2007-05-31 17:58]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 18:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"@"="" []
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 16:59]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-09-01 19:24]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-26 21:20]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbdr32]
kbdr32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-05-09 12:57:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-02 20:17:39 C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-02 16:15:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-06-02 16:18:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-02 16:18

--- E O F ---

#6 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 02 June 2007 - 03:16 PM

Hi skoly,

That's quite the collection of 'stuff'


Please Submit File to VirusTotal for analysis.

Click Virus Total Site

Use the "Browse" button and locate the following file on your computer:

C:\WINDOWS\system32\B4AD4EF6ED.sys

Click the "Submit" button.

Please copy and post (reply) with the results
Do the above steps for each file listed
*=========================*

Open Notepad and copy/paste the all text in the quotebox below into it:

File::
C:\DOCUME~1\Dan\APPLIC~1\tmp13E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp13C.tmp.exe
C:\WINDOWS\yaxvus.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp11D.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp120.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp11E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp111.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp10E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF3.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpEC.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpED.tmp.exe
C:\WINDOWS\mlmnmn.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp9F.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp9C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp9B.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp98.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp87.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp8A.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp88.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp5C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp59.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp5A.tmp.exe
C:\WINDOWS\pmlkij.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp29.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp2C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp2A.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp1B.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp1A.tmp.exe
C:\WINDOWS\ljgdef.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp17.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp15.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp13.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp12.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp10.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp45.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp46.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp44.tmp.exe
C:\WINDOWS\hgfddb.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp3C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpD.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpE.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpB.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp70.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp71.tmp.exe
C:\WINDOWS\jkhiih.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp6E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp890.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp88E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp883.tmp.exe
C:\WINDOWS\cbxusr.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp881.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp880.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp6E9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp6E5.tmp.exe
C:\WINDOWS\system32\geedd.exe
C:\WINDOWS\system32\kbdr32.dll
C:\WINDOWS\system32\vtsqnml.dll
C:\WINDOWS\se_spoof.dll
C:\WINDOWS\system32\kbdr32.dll

Folder::
C:\UWA7P
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F67EEB12-AB09-11DB-A6F1-260856D89593}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbcbe0d6-19ab-4e99-8a0b-9c148b1d6e31}]

Save this as ComboFix-Do.txt
Then drag the ComboFix-Do.txt into ComboFix.exe as you see in the screenshot below.
Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*

Post the following;

VirusTotal results
Combofix.txt
New hijackthis log

Thanks,

Rogue
Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

#7 skoly

skoly

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 02 June 2007 - 04:22 PM

Hi skoly,

That's quite the collection of 'stuff'


Please Submit File to VirusTotal for analysis.

Click Virus Total Site

Use the "Browse" button and locate the following file on your computer:

C:\WINDOWS\system32\B4AD4EF6ED.sys

Click the "Submit" button.

Please copy and post (reply) with the results
Do the above steps for each file listed
*=========================*

Open Notepad and copy/paste the all text in the quotebox below into it:

File::
C:\DOCUME~1\Dan\APPLIC~1\tmp13E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp13C.tmp.exe
C:\WINDOWS\yaxvus.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp11D.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp120.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp11E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp111.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp10E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF3.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpEC.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpED.tmp.exe
C:\WINDOWS\mlmnmn.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp9F.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp9C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp9B.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp98.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp87.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp8A.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp88.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp5C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp59.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp5A.tmp.exe
C:\WINDOWS\pmlkij.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp29.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp2C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp2A.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp1B.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp1A.tmp.exe
C:\WINDOWS\ljgdef.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp17.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp15.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp13.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp12.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp10.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp45.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp46.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp44.tmp.exe
C:\WINDOWS\hgfddb.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp3C.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpD.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpE.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpF.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpB.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp70.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp71.tmp.exe
C:\WINDOWS\jkhiih.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp6E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp890.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp88E.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp883.tmp.exe
C:\WINDOWS\cbxusr.dll
C:\DOCUME~1\Dan\APPLIC~1\tmp881.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp880.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp6E9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmp6E5.tmp.exe
C:\WINDOWS\system32\geedd.exe
C:\WINDOWS\system32\kbdr32.dll
C:\WINDOWS\system32\vtsqnml.dll
C:\WINDOWS\se_spoof.dll
C:\WINDOWS\system32\kbdr32.dll

Folder::
C:\UWA7P
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F67EEB12-AB09-11DB-A6F1-260856D89593}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbcbe0d6-19ab-4e99-8a0b-9c148b1d6e31}]

Save this as ComboFix-Do.txt
Then drag the ComboFix-Do.txt into ComboFix.exe as you see in the screenshot below.
Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*

Post the following;

VirusTotal results
Combofix.txt
New hijackthis log

Thanks,

Rogue


Ok, here is:

VirusTotal results
Combofix.txt
New hijackthis log

Skoly

Complete scanning result of "B4AD4EF6ED.SYS", received in VirusTotal at 06.02.2007, 23:39:29 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.5.31.2 06.01.2007 no virus found
AntiVir 7.4.0.29 06.01.2007 no virus found
Authentium 4.93.8 05.23.2007 no virus found
Avast 4.7.997.0 06.01.2007 no virus found
AVG 7.5.0.467 06.02.2007 no virus found
BitDefender 7.2 06.02.2007 no virus found
CAT-QuickHeal 9.00 06.02.2007 no virus found
ClamAV devel-20070416 06.02.2007 no virus found
DrWeb 4.33 06.02.2007 no virus found
eSafe 7.0.15.0 05.31.2007 no virus found
eTrust-Vet 30.7.3684 06.02.2007 no virus found
Ewido 4.0 06.02.2007 no virus found
FileAdvisor 1 06.02.2007 no virus found
Fortinet 2.85.0.0 06.02.2007 no virus found
F-Prot 4.3.2.48 06.01.2007 no virus found
F-Secure 6.70.13030.0 06.02.2007 no virus found
Ikarus T3.1.1.8 06.02.2007 no virus found
Kaspersky 4.0.2.24 06.02.2007 no virus found
McAfee 5044 06.01.2007 no virus found
Microsoft 1.2503 06.02.2007 no virus found
NOD32v2 2305 06.01.2007 no virus found
Norman 5.80.02 06.01.2007 no virus found
Panda 9.0.0.4 06.02.2007 no virus found
Prevx1 V2 06.02.2007 no virus found
Sophos 4.18.0 06.01.2007 no virus found
Sunbelt 2.2.907.0 05.30.2007 no virus found
Symantec 10 06.02.2007 no virus found
TheHacker 6.1.6.128 05.31.2007 no virus found
VBA32 3.12.0 06.02.2007 no virus found
VirusBuster 4.3.23:9 06.02.2007 no virus found
Webwasher-Gateway 6.0.1 06.02.2007 no virus found

"Dan" - 2007-06-02 18:05:26 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Dan\"
Command switches used :: ""C:\Documents and Settings\Dan\Desktop\ComboFix-Do.txt" "C:\Documents and Settings\Dan\Desktop\Duh.lnk""


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


"C:\WINDOWS\system32\tmp9.tmp.dll"
"C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\Abbr"
"C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ActivationCode"
"C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ProductCode"
"C:\DOCUME~1\Dan\APPLIC~1\tmp13E.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp13C.tmp.exe"
"C:\WINDOWS\yaxvus.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp11D.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp120.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp11E.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp111.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp10E.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpF9.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpF3.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpEC.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpED.tmp.exe"
"C:\WINDOWS\mlmnmn.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp9F.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp9C.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp9B.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp98.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp87.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp8A.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp88.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp5C.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp59.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp5A.tmp.exe"
"C:\WINDOWS\pmlkij.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp29.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp2C.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp2A.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp1B.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp1A.tmp.exe"
"C:\WINDOWS\ljgdef.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp16.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp17.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp15.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp13.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp12.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp10.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp45.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp46.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp44.tmp.exe"
"C:\WINDOWS\hgfddb.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp3C.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpD.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpE.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpF.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpB.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp70.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp71.tmp.exe"
"C:\WINDOWS\jkhiih.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp6E.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp890.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp88E.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp883.tmp.exe"
"C:\WINDOWS\cbxusr.dll"
"C:\DOCUME~1\Dan\APPLIC~1\tmp881.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp880.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp6E9.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmp6E5.tmp.exe"
"C:\WINDOWS\system32\geedd.exe"
"C:\WINDOWS\system32\vtsqnml.dll"
"C:\UWA7P"
"C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor"
"C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007"
"C:\WINDOWS\system32\kbdr32.dll"


((((((((((((((((((((((((((((((( Files Created from 2007-05-02 to 2007-06-02 ))))))))))))))))))))))))))))))))))


2007-06-02 17:39 50,970 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmp9.tmp.exe
2007-06-02 17:39 2,560 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpC.tmp.exe
2007-06-02 17:39 17,010 --a------ C:\DOCUME~1\Dan\APPLIC~1\tmpA.tmp.exe
2007-06-02 17:39 106,730 --a------ C:\WINDOWS\fcbaxw.dll
2007-06-02 16:18 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-01 20:30 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-06-01 20:04 49,664 --a------ C:\Program Files\ATF-Cleaner.exe
2007-06-01 17:27 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-31 23:49 3,098,056 --a------ C:\Program Files\LimeWireWin.exe
2007-05-31 23:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-05-31 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SMSI
2007-05-10 03:33 <DIR> d-------- C:\Program Files\DellSupport
2007-05-06 16:06 <DIR> d-------- C:\Program Files\Smart Projects


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-01 23:51:45 -------- d-----w C:\Program Files\Common Files\Companion Wizard
2007-06-01 21:29:12 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
2007-06-01 19:35:49 -------- d-----w C:\Program Files\Trend Micro
2007-06-01 18:43:44 -------- d-----w C:\Program Files\LimeWire
2007-05-20 15:41:45 56 --sh--r C:\WINDOWS\system32\B4AD4EF6ED.sys
2007-05-20 15:41:45 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-10 07:39:04 -------- d--h--w C:\DOCUME~1\Dan\APPLIC~1\Gtek
2007-04-30 01:25:46 -------- d-----w C:\DOCUME~1\Dan\APPLIC~1\AdobeUM
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-04 15:58:49 -------- d-----w C:\Program Files\GemMaster
2007-04-04 15:58:19 -------- d-----w C:\Program Files\PokerStars
2007-04-04 15:57:59 -------- d-----w C:\Program Files\Project64 1.6
2007-03-29 22:26:07 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll []
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 18:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"@"="" []
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 16:59]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-09-01 19:24]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-26 21:20]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbdr32]
kbdr32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-05-09 12:57:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-02 20:17:39 C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-02 18:13:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-06-02 18:15:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-02 18:15
C:\ComboFix2.txt ... 2007-06-02 16:18

--- E O F ---

Logfile of HijackThis v1.99.1
Scan saved at 6:20:03 PM, on 6/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: kbdr32 - kbdr32.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

#8 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 02 June 2007 - 04:37 PM

Not sure if I missed those or the tool has a line limit *shrugs*
Regardless we are getting close

Open Notepad and copy/paste the text in the quotebox below into it:

File::
C:\DOCUME~1\Dan\APPLIC~1\tmp9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpC.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpA.tmp.exe
C:\WINDOWS\fcbaxw.dll

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbdr32]

Save this as ComboFix-Do.txt
Then drag the ComboFix-Do.txt into ComboFix.exe as you see in the screenshot below.
Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*
Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

#9 skoly

skoly

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 02 June 2007 - 04:56 PM

Not sure if I missed those or the tool has a line limit *shrugs*
Regardless we are getting close

Open Notepad and copy/paste the text in the quotebox below into it:

File::
C:\DOCUME~1\Dan\APPLIC~1\tmp9.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpC.tmp.exe
C:\DOCUME~1\Dan\APPLIC~1\tmpA.tmp.exe
C:\WINDOWS\fcbaxw.dll

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbdr32]

Save this as ComboFix-Do.txt
Then drag the ComboFix-Do.txt into ComboFix.exe as you see in the screenshot below.
Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*


Ok, here are the Combofix and HijackThis Logs.

Skoly

"Dan" - 2007-06-02 18:40:08 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Dan\"
Command switches used :: ""C:\Documents and Settings\Dan\Desktop\ComboFix-Do.txt""


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


"C:\DOCUME~1\Dan\APPLIC~1\tmp9.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpC.tmp.exe"
"C:\DOCUME~1\Dan\APPLIC~1\tmpA.tmp.exe"
"C:\WINDOWS\fcbaxw.dll"


((((((((((((((((((((((((((((((( Files Created from 2007-05-02 to 2007-06-02 ))))))))))))))))))))))))))))))))))


2007-06-02 16:18 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-01 20:30 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-06-01 20:04 49,664 --a------ C:\Program Files\ATF-Cleaner.exe
2007-06-01 17:27 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-31 23:49 3,098,056 --a------ C:\Program Files\LimeWireWin.exe
2007-05-31 23:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-05-31 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SMSI
2007-05-10 03:33 <DIR> d-------- C:\Program Files\DellSupport
2007-05-06 16:06 <DIR> d-------- C:\Program Files\Smart Projects


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-01 23:51:45 -------- d-----w C:\Program Files\Common Files\Companion Wizard
2007-06-01 21:29:12 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
2007-06-01 19:35:49 -------- d-----w C:\Program Files\Trend Micro
2007-06-01 18:43:44 -------- d-----w C:\Program Files\LimeWire
2007-05-20 15:41:45 56 --sh--r C:\WINDOWS\system32\B4AD4EF6ED.sys
2007-05-20 15:41:45 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-10 07:39:04 -------- d--h--w C:\DOCUME~1\Dan\APPLIC~1\Gtek
2007-04-30 01:25:46 -------- d-----w C:\DOCUME~1\Dan\APPLIC~1\AdobeUM
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-04 15:58:49 -------- d-----w C:\Program Files\GemMaster
2007-04-04 15:58:19 -------- d-----w C:\Program Files\PokerStars
2007-04-04 15:57:59 -------- d-----w C:\Program Files\Project64 1.6
2007-03-29 22:26:07 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 18:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"@"="" []
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 16:59]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-09-01 19:24]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-26 21:20]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-05-09 12:57:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-02 22:15:47 C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-02 18:44:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-06-02 18:45:47
C:\ComboFix-quarantined-files.txt ... 2007-06-02 18:45
C:\ComboFix2.txt ... 2007-06-02 18:15
C:\ComboFix3.txt ... 2007-06-02 16:18

--- E O F ---

Logfile of HijackThis v1.99.1
Scan saved at 6:54:32 PM, on 6/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

#10 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 02 June 2007 - 05:05 PM

Hi Skoly
I don't see an AntiVirus so make sure you read the part below about AV's and install one of those listed below. All are free
Consider installing one of the firewalls also

Remove Programs
Please Click Start > Control Panel > Add/Remove Programs

Remove these programs by clicking Remove

J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03

If some programs listed are not present, please do not panic
*=========================*


Uninstall/Delete Unnecessary Tools/Files

combofix.exe from Desktop
C:\ComboFix.txt
ComboFix-Do.txt from desktop
Uninstall List
C:\qoobox <<< Folder

These were problem specific and were not intended for everyday use.

*========================*

Flush System Restore
Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a Restore Point, and then click Ok

Next, go to Start > Run and type in cleanmgr
Select the More Options tab
Choose the option to Clean Up System Restore and select OK.
This will remove all restore points except the new one you just created
*========================*

This is my post for when you are All Clean - which you seem to be.

But to help protect you against further infections, and also to help prevent criminals using your computer to infect other people's computers on the web, I recommend the following: (You may already have some of the items or completed steps)

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
Click here for more information on -> Computer Safety On line - Anti-Virus
In case you do NOT have any antivirus software installed in your computer or yours has expired, you may use one of the following.Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - this keeps your computer safe from hackers AS WELL AS from several computer viruses (mostly worms) which spread through the internet by using security holes of Windows. Have in mind that these are FREE FULL versions of the software and they lack of some features available in their shareware versions. Nevertheless, the FREE versions are capable of providing a basic firewall protection to your computer.Click here for more information on Firewalls -> Computer Safety On line - Software Firewalls


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Set up system to ensure a regular update of the Operating System.

Automatically:
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click on Automatic Updates
  • Check the option of choice (I use Automatic (Recommended)). If you use dial-up I would recommend using the
    Notify Me option so that you can download when you can afford the time and bandwidth overheads.
  • Select the Day/Time of choice
  • Click Apply
  • Click OK

Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly
  • Install Spybot© - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here: Click here for more info -->Instructions for - Spybot S & D and Ad-aware
  • Install Lavasofts© Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Click here for more info -->Instructions for - Spybot S & D and Ad-aware
  • Install Javacools© SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here: Click here for more info -->Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and you are less susceptible to attacks.


Safe Surfing,

Rogue

Edited by R0gue, 02 June 2007 - 05:06 PM.

Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

#11 Rogue

Rogue

    Authentic Member

  • Authentic Member
  • PipPip
  • 179 posts

Posted 03 June 2007 - 08:06 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Rogue
Trained at MalWare Removal University - A Cooperative Effort with WhatTheTech Classroom

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users