Hi Trevuren,
Hmm, something went wrong some where. I left my computer on (which i do usually) and when i got back, my anti-virus program was disabled. On top of that, i couldn't enable it. I had to go into safe mode and run the Flash_Disinfector.exe. Then, on top of that, a bunch of my normal running processors are not running. Last time i used to have like 54 processsors running, but now i have 34. I don't know if they were taken away because they slowed my computer down or something like that. I don't mind having less processors, just that, my usual prograns are not running. For example, Zone Alarm, Microsoft Activesync, Yahoo Messenger, Yahoo Widgets and quite a number more. I know they slow down my computer, but i need their services. Anyway, i did as you said and here's the combofix log.
ComboFix 07-06-21.3 - C:\Documents and Settings\Reuben\Desktop\ComboFix.exe
"Reuben" - 2007-06-24 0:32:22 - Service Pack 2
((((((((((((((((((((((((( Files Created from 2007-05-23 to 2007-06-23 )))))))))))))))))))))))))))))))
2007-06-23 22:39 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-06-23 22:39
drahs—- C:\autorun.inf
2007-06-23 15:45 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-06-22 15:26 d–hs—- C:\FOUND.001
2007-06-22 13:01 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-22 11:47 786,432 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-21 22:18 38,232 –a—— C:\WINDOWS\system32\cmdify.dll
2007-06-20 20:32 d–hs—- C:\FOUND.000
2007-06-18 11:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-06-18 11:25 d——– C:\Program Files\Tradewinds Legends
2007-06-18 11:25 d——– C:\Program Files\ReflexiveArcade
2007-06-15 10:15 d——– C:\Program Files\Shockwave.com
2007-06-14 23:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-06-14 23:23 d——– C:\Program Files\Tradewinds Full Game
2007-06-14 14:49 d——– C:\Program Files\DFX
2007-06-14 14:48 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-05 04:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy
2007-06-02 10:41 d——– C:\Program Files\Microsoft Voice Command
2007-06-01 14:05 d——– C:\Program Files\eMule
2007-06-01 14:05 d——– C:\DOCUME~1\Reuben\APPLIC~1\eMule
2007-05-28 03:24 d——– C:\DOCUME~1\Reuben\APPLIC~1\VoipCheapCom
2007-05-26 02:34 d——– C:\Program Files\MobiPocket.com
2007-05-26 02:08 d——– C:\Skyscape
2007-05-26 00:15 d——– C:\WINDOWS\Skyscape
2007-05-25 14:18 d——– C:\Program Files\Common Files\Mobipocket Shared
2007-05-24 18:46 d——– C:\Program Files\mIRCv2
2007-05-24 04:15 d——– C:\Program Files\skyscape
2007-05-24 04:05 d——– C:\Program Files\Common Files\Skyscape
2007-05-24 02:09 d——– C:\DOCUME~1\Reuben\APPLIC~1\Help
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-23 19:22:40 12 —-a-w C:\WINDOWS\bthservsdp.dat
2007-06-02 00:11:22 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-05-17 20:33:14 ——– d—–w C:\Program Files\Bible
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-11 10:20:24 ——– d—–w C:\DOCUME~1\Reuben\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-10 22:51:02 ——– d—–w C:\Program Files\Westwood
2007-05-10 16:39:14 ——– d—–w C:\Program Files\Teleport Pro
2007-05-10 14:25:06 ——– d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-08 18:26:50 ——– d—–w C:\Program Files\r2 Studios
2007-05-08 11:22:22 ——– d—–w C:\Program Files\Advanced Port Scanner
2007-05-03 23:51:26 ——– d—–w C:\DOCUME~1\Reuben\APPLIC~1\LimeWire
2007-05-03 23:50:20 ——– d—–w C:\Program Files\LimeWire
2007-04-27 09:54:54 ——– d—–w C:\Program Files\Valve
2007-04-25 14:21:16 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 19:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 19:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 19:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 19:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 19:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 19:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 19:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 19:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 19:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2007-04-14 13:04:00 471 —-a-w C:\WINDOWS\CLEANUP.CMD
2007-04-14 13:03:34 797 —-a-w C:\WINDOWS\HotFix.bat
2007-04-14 08:40:06 2,560 —-a-w C:\WINDOWS\_MSRSTRT.EXE
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\\vptray.exe" [2005-06-23 19:27]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cmdify]
cmdify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c928871-0638-11dc-a218-00c09fa4e666}]
Auto\command- pagefile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL pagefile.pif
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-24 00:33:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001101-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]
Completion time: 2007-06-24 0:35:16
C:\ComboFix3.txt … 2007-06-23 03:07
C:\ComboFix-quarantined-files.txt … 2007-06-24 00:34
C:\ComboFix2.txt … 2007-06-23 12:30
— E O F —
While doing combofix, my windows encountered an error, and they asked me to send a report to Microsoft. At that time, i couldn't get connected to the internet. So, i didn't send the report, and continued with HJT. Here's the log…
Logfile of HijackThis v1.99.1
Scan saved at 12:40:05 AM, on 6/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Reuben\Desktop\HJT\Hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: cmdify - C:\WINDOWS\SYSTEM32\cmdify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
I'm at wit's end with my computer. On one hand i want to reformat my computer, but it has too many things inside to reformat. Anyway, i hope you can help me out.
On a personal note, what is the best anti-virus and firewall? I'm currently using Symantec Corparate v10 and Zone Alarm Pro.
Regards,
Reuben