This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Hijackthis Log

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello again, a few months ago i posted a Hijackthis Log for a friend of mines and it turned out pretty bad so i guest he ended up buying a new computer. so recently my web browser has been acting up by scrolling up and down like a mad man from time to time and i don't now what is causeing it to do so. I ran spybot and AVG and nothing came up :scratch: , so now i have no clue on what to do.any help would be greatly appreciated.

my log thanks

Logfile of HijackThis v1.99.1
Scan saved at 1:49:19 AM, on 7/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\S3tray2.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.your-search.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Base error - {4D473CBF-24BB-A43D-4CE8-C8BF05E4A302} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_525f.dll
O2 - BHO: Curl Class - {A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} - C:\WINDOWS\System32\NDrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: (no name) - {D04E3D40-C766-4627-A56B-9316C5E1D71E} - (no file)
O3 - Toolbar: peak joy dent - {7FA0C206-4C68-6D35-DC7E-38D58EE0E78F} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe
O4 - HKLM\..\Run: [modedate] C:\PROGRA~1\BOOBAR~1\Exit Global.exe
O4 - HKLM\..\Run: [erkdaz] C:\WINDOWS\erkdaz.exe
O4 - HKLM\..\Run: [fJ3MPFM] C:\documents and settings\owner\local settings\temp\fJ3MPFM.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [AutoLoader4Fuo1OWKJaaK] "C:\WINDOWS\System32\xpsgr1.exe" /PC="AM.WILD" /HideUninstall
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
O4 - HKLM\..\Run: [nlwsrhqu] C:\WINDOWS\bvzzohd.exe
O4 - HKLM\..\Run: [4s5U34j] icwrsno.exe
O4 - HKLM\..\Run: [swinsckm] C:\WINDOWS\System32\swinsckm.exe
O4 - HKLM\..\Run: [shRmW] C:\WINDOWS\System32\shRmW.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_525f.dll"
O4 - HKLM\..\Run: [Whq] C:\windows\Whq.exe
O4 - HKLM\..\Run: [c0bFj] C:\windows\c0bFj.exe
O4 - HKLM\..\Run: [aOeZ] C:\documents and settings\owner\local settings\temp\aOeZ.exe
O4 - HKLM\..\Run: [FgJ3JHtB] C:\documents and settings\owner\local settings\temp\FgJ3JHtB.exe
O4 - HKLM\..\Run: [fT0t] C:\documents and settings\owner\local settings\temp\fT0t.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_525f.dll"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: VTAgentReboot.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX
O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX
O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU)
O15 - Trusted Zone: *.awmguild.com
O15 - Trusted Zone: *.vladzone.com
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {C8BAC37C-A8D2-425E-B7FC-80B9537FB14A} - http://www.spyblast.com/download/SBFullSInst.cab
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} -
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/mmed.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://E:\games\WebDriverFullInstall.exe
O19 - User stylesheet: (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
smurf :D

Welcome to the forum, let me explain how this forum works. You posted on May 3 2007 here –> http://forums.tomcoyote.org/Hijackthis_Logfile_t79059.html and your log was replied to by LDTate, you never replied back. We are all volunteers that use our own time to clean infected computers, the amount of logs we get each day is mind boggling, we really do not have the time to spend analyzing your log, working up a fix to have you not reply back.

With that said, I have to tell ya you have a very heavily infected computer, lets attack this first.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


I need to see the Combofix log and a New HJT log please.
"Owner" - 2007-07-22 15:51:05 - ComboFix 07-07-17.8 - Service Pack 1 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\#SharedObjects\6CV6BGJB\www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\#SharedObjects\6CV6BGJB\www.broadcaster.com\played_list.sol
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\#SharedObjects\6CV6BGJB\www.broadcaster.com\video_queue.sol
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\WINDOWS\system32\pcs


((((((((((((((((((((((((( Files Created from 2007-06-23 to 2007-07-23 )))))))))))))))))))))))))))))))


2007-07-22 15:49 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-22 15:48 1,180,958 –a—— C:\Program Files\ComboFix.exe
2007-07-21 08:20 d——– C:\Program Files\Red Kawa
2007-07-21 08:08 6,990,593 –a—— C:\Program Files\videoraipodconverter_Installer.exe
2007-07-18 08:55 83,024 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-07-18 08:55 57,424 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-07-18 08:55 53,840 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-07-18 08:55 39,376 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-07-18 08:55 29,264 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-07-18 08:54 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-07-18 08:54 d—-c— C:\DOCUME~1\Owner\APPLIC~1\PC Tools
2007-07-18 08:54 d——– C:\Program Files\Spyware Doctor
2007-07-18 07:24 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-18 07:23 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-18 07:19 d——– C:\Program Files\SpywareBlaster
2007-07-18 06:54 18,164,640 –a—— C:\Program Files\aaw20072.exe
2007-07-08 05:27 d—-c— C:\DOCUME~1\Owner\dwhelper


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-18 17:24:59 ——– d—–w C:\Program Files\Lavasoft
2007-07-18 15:34:58 ——– dc—-w C:\DOCUME~1\Owner\APPLIC~1\LimeWire
2007-07-17 12:46:52 ——– dc—-w C:\DOCUME~1\Owner\APPLIC~1\uTorrent
2007-06-10 12:09:22 ——– d—–w C:\Program Files\iTunes
2007-06-10 12:09:13 ——– d—–w C:\Program Files\iPod
2007-06-10 12:07:39 ——– d—–w C:\Program Files\QuickTime
2007-06-10 11:57:30 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-10 11:34:29 ——– dc—-w C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-06-10 10:54:51 ——– d—–w C:\Program Files\AviSynth 2.5
2007-06-10 10:52:08 ——– d—–w C:\Program Files\eRightSoft
2007-06-05 01:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-05 01:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-05 01:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-28 13:03:32 ——– d—–w C:\Program Files\EmEditor
2007-05-28 09:37:36 ——– d—–w C:\Program Files\GIMP-2.0
2003-08-28 00:19:18 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
2004-03-11 21:07:24 40,960 –sha-w C:\WINDOWS\lbbho.dll
2006-05-03 09:06:54 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4D473CBF-24BB-A43D-4CE8-C8BF05E4A302}]
C:\PROGRA~1\INSIDE~1\FORWMA.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{564FFB73-9EEF-4969-92FA-5FC4A92E2C2A}]
2005-02-23 19:59 225280 –a—— C:\WINDOWS\System32\sfg_525f.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50}]
C:\WINDOWS\System32\NDrv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"WCOLOREAL"="C:\Program Files\Coloreal\coloreal.exe" [2002-11-26 15:14]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 19:42]
"nwiz"="nwiz.exe" [2002-12-12 00:00 C:\WINDOWS\system32\nwiz.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"S3TRAY2"="S3tray2.exe" [2003-02-25 04:33 C:\WINDOWS\system32\S3tray2.exe]
"SM1BG"="C:\WINDOWS\SM1BG.EXE" [2003-08-27 14:20]
"Pcsv"="C:\WINDOWS\system32\pcs\pcsvc.exe" []
"modedate"="C:\PROGRA~1\BOOBAR~1\Exit Global.exe" []
"erkdaz"="C:\WINDOWS\erkdaz.exe" []
"fJ3MPFM"="C:\documents and settings\owner\local settings\temp\fJ3MPFM.exe" []
"AutoUpdater"="C:\Program Files\AutoUpdate\AutoUpdate.exe" []
"AutoLoader4Fuo1OWKJaaK"="C:\WINDOWS\System32\xpsgr1.exe" []
"Kazaa Download Accelerator Updater"="regsvr32 /s C:\WINDOWS\System32\kdpupd.dll" []
"Adstartup"="C:\WINDOWS\System32\automove.exe" []
"nlwsrhqu"="C:\WINDOWS\bvzzohd.exe" []
"4s5U34j"="icwrsno.exe" []
"swinsckm"="C:\WINDOWS\System32\swinsckm.exe" []
"shRmW"="C:\WINDOWS\System32\shRmW.exe" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2003-12-12 14:50]
"PCShield"="regsvr32 /s C:\WINDOWS\System32\sfg_525f.dll" []
"Whq"="C:\windows\Whq.exe" []
"c0bFj"="C:\windows\c0bFj.exe" []
"aOeZ"="C:\documents and settings\owner\local settings\temp\aOeZ.exe" []
"FgJ3JHtB"="C:\documents and settings\owner\local settings\temp\FgJ3JHtB.exe" []
"fT0t"="C:\documents and settings\owner\local settings\temp\fT0t.exe" []
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" []
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-20 09:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-12 01:58]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"AIM"="C:\Program Files\AIM95\aim.exe" [2004-08-10 05:37]
"\IEService.exe"="C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe" []
"Notn"="C:\Documents and Settings\Owner\Application Data\eber.exe" []
"PCShield"="regsvr32 /s C:\WINDOWS\System32\sfg_525f.dll" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

C:\DOCUME~1\Owner\STARTM~1\Programs\Startup
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-02-16 12:03:17]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup
-c–a-r 143,360 2001-10-08 12:11:30 C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\VTAgentReboot.exe
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2003-05-21 09:40:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 04:13]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
"C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{100675f2-85c8-11d7-82fa-806d6172696f}]
AutoRun\command- D:\Info.exe folder.htt 480 480

*Newly Created Service* - AAWSERVICE
*Newly Created Service* - IKFILEFLT
*Newly Created Service* - IKFILESEC
*Newly Created Service* - IKSYSFLT
*Newly Created Service* - IKSYSSEC
*Newly Created Service* - SDAUXSERVICE
*Newly Created Service* - SDCORESERVICE

Contents of the 'Scheduled Tasks' folder
2003-05-14 06:54:12 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-22 15:57:43
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\IEService.exe"="C:\\DOCUME~1\\ALLUSE~1\\APPLIC~1\\IESERV~1\\IEService.exe"

Completion time: 2007-07-22 16:00:03
C:\ComboFix-quarantined-files.txt … 2007-07-22 15:59

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 4:06:20 PM, on 7/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.your-search.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Base error - {4D473CBF-24BB-A43D-4CE8-C8BF05E4A302} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_525f.dll
O2 - BHO: Curl Class - {A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} - C:\WINDOWS\System32\NDrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: (no name) - {D04E3D40-C766-4627-A56B-9316C5E1D71E} - (no file)
O3 - Toolbar: peak joy dent - {7FA0C206-4C68-6D35-DC7E-38D58EE0E78F} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [modedate] C:\PROGRA~1\BOOBAR~1\Exit Global.exe
O4 - HKLM\..\Run: [fJ3MPFM] C:\documents and settings\owner\local settings\temp\fJ3MPFM.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [4s5U34j] icwrsno.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [aOeZ] C:\documents and settings\owner\local settings\temp\aOeZ.exe
O4 - HKLM\..\Run: [FgJ3JHtB] C:\documents and settings\owner\local settings\temp\FgJ3JHtB.exe
O4 - HKLM\..\Run: [fT0t] C:\documents and settings\owner\local settings\temp\fT0t.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_525f.dll"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: VTAgentReboot.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX
O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX
O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU)
O15 - Trusted Zone: *.awmguild.com
O15 - Trusted Zone: *.vladzone.com
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {C8BAC37C-A8D2-425E-B7FC-80B9537FB14A} - http://www.spyblast.com/download/SBFullSInst.cab
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} -
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/mmed.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://E:\games\WebDriverFullInstall.exe
O19 - User stylesheet: (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

:ph34r:
hello, ken545 i apologize for not responding to the first log and thank you also for helping me on this log. i greatly appreciate it sir thanks a million.
You have quite a collection of malware on this system, its going to require a few more scans with different programs. I suggest you uninstall Limewire as it brings some of this garbage with it.

Did you post the entire Combofix log ???

You need to enable windows to show all files and folders, instructions Here



We need to disable the Tea Timer in Spybot Search and Destroy as to not interfere with the fix.
  • Open Spybot and go to Mode> Advanced Mode> Tools> Resident and take the checkmark out of Tea Timer


Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.your-search.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Base error - {4D473CBF-24BB-A43D-4CE8-C8BF05E4A302} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_525f.dll
O2 - BHO: Curl Class - {A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} - C:\WINDOWS\System32\NDrv.dll (file missing)

O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: (no name) - {D04E3D40-C766-4627-A56B-9316C5E1D71E} - (no file)
O3 - Toolbar: peak joy dent - {7FA0C206-4C68-6D35-DC7E-38D58EE0E78F} - C:\PROGRA~1\INSIDE~1\FORWMA.dll (file missing)

O4 - HKLM\..\Run: [modedate] C:\PROGRA~1\BOOBAR~1\Exit Global.exe
O4 - HKLM\..\Run: [fJ3MPFM] C:\documents and settings\owner\local settings\temp\fJ3MPFM.exe
O4 - HKLM\..\Run: [4s5U34j] icwrsno.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [4s5U34j] icwrsno.exe
o4 - HKLM\..\Run: [aOeZ] C:\documents and settings\owner\local settings\temp\aOeZ.exe
O4 - HKLM\..\Run: [FgJ3JHtB] C:\documents and settings\owner\local settings\temp\FgJ3JHtB.exe
O4 - HKLM\..\Run: [fT0t] C:\documents and settings\owner\local settings\temp\fT0t.exe
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_525f.dll"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: VTAgentReboot.exe

O15 - Trusted Zone: *.awmguild.com
O15 - Trusted Zone: *.vladzone.com

O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {C8BAC37C-A8D2-425E-B7FC-80B9537FB14A} - http://www.spyblast.com/download/SBFullSInst.cab
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} -
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/mmed.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://E:\games\WebDriverFullInstall.exe

O19 - User stylesheet: (file missing)




Please Download No Lop to your desktop
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it
  • Now click the button labeled "Search and Destroy"
    <>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should pop-up from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log after completing the next steps.
–If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.





Make sure you follow these instructions correctly to Remove or Quarantine what it finds and also to save the report, without me seeing the report my hands are tied.
Download and install the 30 day trial of AVG Anti-Spyware 7.5.1.43 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware Free <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware Free by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system <–Don't forget this
  • make sure to remember where you saved that file, this is important, I need to see that log.
  • Close AVG Anti-Spyware Free

Still in Safemode, delete these

C:\Program Files\AutoUpdate
C:\WINDOWS\System32\sfg_525f.dll
C:\WINDOWS\System32\NDrv.dll
C:\DOCUMENTS AND SETTING\ALL USERS\APPLICATION DATA\IESERVICE
C:\Documents and Settings\Owner\Application Data\eber.exe



Download and Install CCleaner
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Let me see the NoLop log, the AVG Anti Spyware log and a new HJT log.
hello ken, i've done the HijackThis System Scan and fix all the problems then did the NoLop scan it found nothing (no infections), then did the AVG updating and settings that you asked, AVG took a while to load :scratch: after went to safemode did that and ran AVG to do a full system scan,took a while to load again.AVG found some stuff so i went to Apply all actions,then i checked the Reports icon and no reports where available?. i also went to check for: C:\Program Files\AutoUpdate C:\WINDOWS\System32\sfg_525f.dll C:\WINDOWS\System32\NDrv.dll C:\DOCUMENTS AND SETTING\ALL USERS\APPLICATION DATA\IESERVICE C:\Documents and Settings\Owner\Application Data\eber.exe and found non of them :scratch: did i do something wrong?. alot of new folders showed up also in the C:\ and C:\WINDOWS drive that wasn't there before.
Good Morning,


AVG may have removed some of those entries and files, Run this quick scan,

Download the Stand Alone Version of CWShredder to your desktop.
  • Open CWShredder
  • Check for Updates
  • Close out the program. <– Dont run it yet

    Boot your computer into Safemode
    • Go to Start> Shut Off your Computer> Restart
    • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
    • This will bring up a menu.
    • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
    • Then press the Enter on your Keyboard
    Tutorial if you need it How to boot into Safemode


    Open CWShredder
  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .

I need to see a new HJT log please and let me know if CWShredder found anything.
Good Morning to you to ken, CWShredder found nothing. Logfile of HijackThis v1.99.1 Scan saved at 2:41:28 AM, on 7/23/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\S3tray2.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\System32\taskmgr.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\nc25exo8.slt\prefs.js) O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\Coloreal\coloreal.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [AIM] C:\Program Fi les\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe O4 - Global Startup: VTAgentReboot.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX O9 - Extra button: Microsoft® JavaScript® Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU) O9 - Extra 'Tools' menuitem: JavaScript Console - {AD458CDD-8BF5-49A0-87C1-A9C40A9639E5} - C:\WINDOWS\system32\COMDLG32.OCX (HKCU) O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
smurf,

Log looks good :thumbup:


System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • You will have to be in Catagory View in the Control Panel to see this.
  • Go to Start> Control Panel> and up on the top left, make sure your in Catagory View
  • Go to Performance and Maintenance> System Restore> ( this will also be up on your top left ) then Create a New Restore Point
  • You can name the Restore Point anything you like
System Restore Tutorial <– If you need it


Your Operating System is out of date and letting a lot of this stuff in, you need to open IE and go to Tools> Windows update and download and install Service Pack 2, there are also critical updates to install beyond SP2, just do not install any Driver Files, just critical updates


How are things running now??
hello ken, eveything seems to be A ok i think.i have Created a new Restore Point :thumbup: . IE page cannot be displayed, i haven't used IE for a while now. i usually use netscape or firefox.
hello again sir ken, i followed all the steps to the link you gave me and still i can't get IE to connection, and just recently my broswer started acting up again by scrolling up and down like a mad man :scratch: ?. im very sorry for bugging you again sir and i thank you for all the help you've provided me with so far.
smurf,

Run this online scan using Internet Explorer:
Kaspersky Online Scanner from Kaspersky Online Virus Scanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan: Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Post the log along with a New HJT Log into your next reply.
Internet Explorer won't load the page or anyother, i keep getting (The page cannot be displayed) and on the bottom of the page (Cannot find server or DNS Error Internet Explorer ). i have no clue on what to do now sir sorry.
Smurf,

You have two anti virus programs running and this is a big no no, your call but you need to uninstall one of them via the add remove programs in the control panel. They sometimes cause all kinds of havoc.

AVG
Mcafee


At this point I would like you to post in our forum for Other Computer Problems Tell them you posted here and your log is clean. The windows techs in there are better equipped to help you . After you get it resolved, post back here and let me know, I will keep this thread open for you for a week or so. Once you get this ironed out, I need to give you instructions for updating your Operating System.

Ken :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI