[Resolved] Please Help Me!
19 min read
Welcome to Tom Coyote Forums
Please observe these rules while we work:
- Perform all actions in the order given.
- If you don't know, stop and ask! Don't keep going on.
- Please reply to this thread. Do not start a new topic.
- Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
I need to warn you that at some point you have had a bank information stealing trojan on your system. This is noted by the following line; O2 - BHO: H - {83E915D4-DDDB-4450-B957-7A3240E9CE66} - zoox1.dll (file missing)
While the file is no longer present I feel it is important for you to change your passwords to any online banking accounts you have. I cannot tell which bank it targets but please read the information contained in this link under Technical Details since it shows pictures of the banking login screens
The Trojan may also attempt to steal other details including: Windows protected storage passwords, Internet Explorer forms and auto-complete saved passwords and Email account details. I strongly suggest you change all of your passwords.
Please acknowledge you have read the link and this warning.
Secondly I do not see an Anti Virus program installed.
*=========================*
Download one of the following free anti virus applications
- AVG Free Edition
- Avast Home Edition
- BitDefender Free Edition
- ClamWin Free Antivirus
- A-Squared Free
- Antivir Personal Edition
- Active Virus Shield
Download the OTMoveIt by OldTimer.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
Save it to your Desktop.
*=========================*
Download SDFix and save it to your Desktop.
Double click SDFix.exe and choose Install to extract it to its own folder located at C:\SDFix
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
- In Safe Mode, navigate to the SDFix folder C:\SDFix.
- Open the folder and double click RunThis.bat to start the script.
- Type Y to begin the script.
- It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- Your system will take longer that normal to restart as the fixtool will be running and removing files.
- When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
- Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum
Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:
O2 - BHO: H - {83E915D4-DDDB-4450-B957-7A3240E9CE66} - zoox1.dll (file missing)
O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xhelper.dll
CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*
Please double-click OTMoveIt.exe to run it.
Copy the file paths in the quotebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.C:\WINDOWS\System32\wab.dat
C:\WINDOWS\System32\ps.dat
C:\WINDOWS\xhelper.dll
C:\WINDOWS\System32\cookie.dat
C:\WINDOWS\System32\boa.dat
C:\WINDOWS\System32\alog.txt
C:\WINDOWS\System32\commands.xml
C:\WINDOWS\System32\helper.sys
C:\WINDOWS\System32\helper.xml
C:\WINDOWS\System32\tns.dll
Click the red Moveit! button.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
When done, it will create a log (********_******.log – * stands for date and time) in folder: C:\_OTMoveIt\MovedFiles.
*=========================*
Run Kapersky Online AV Scanner
Using Internet Explore Go to http://www.kaspersky.com/virusscanner and click the Kaspersky Online Scanner button.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
- Read the Requirements and limitations before you click Accept.
- Allow the ActiveX download if necessary.
- Once the database has downloaded, click Next.
- Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
- Click on "My Computer" and then put the kettle on!
- When the scan has completed, click Save Report As…
- Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
- Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
*=========================*
Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*
Please post the following:
SDFix's Report.txt
OTMoveIt log
Kapersky Log
New hijackthis log
Uninstall list
Thanks,
Rogue
SD FIX :
SDFix: Version 1.94
Run by [removed] on Sun 07/29/2007 at 01:20 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
FCI
ImagePath:
C:\WINDOWS\System32\svchost.exe:ext.exe
FCI - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Service runtime2 - Deleted after Reboot
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\gmc.exe.exe - Deleted
C:\WINDOWS\spooldr.exe - Deleted
C:\WINDOWS\system32\alog.txt - Deleted
C:\WINDOWS\system32\drivers\asc3550u.sys - Deleted
C:\WINDOWS\system32\help.txt - Deleted
C:\WINDOWS\system32\ps.dat - Deleted
C:\WINDOWS\system32\spooldr.sys - Deleted
C:\WINDOWS\Temp\startdrv.exe - Deleted
C:\WINDOWS\system32\drivers\runtime2.sys - Deleted
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
—————
Backups Folder: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\Sharing Folders\[removed]\Thumbs.db
C:\Program Files\Image-Line\FL Studio 7\REX Shared Library.dll
Finished
Kaspersky Log :
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, July 29, 2007 2:59:43 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 29/07/2007
Kaspersky Anti-Virus database records: 369398
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 72045
Number of viruses found: 12
Number of infected objects: 38
Number of suspicious objects: 0
Duration of the scan process: 01:13:00
Infected Object Name / Virus Name / Last Action
C:\66.tmp Infected: Trojan.Win32.Inject.cj skipped
C:\6D.tmp Infected: Packed.Win32.Tibs.av skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__01 - Never Again.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__02 - One Minute.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__03 - Hole.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__04 - Sober.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__05 - Don't Waste Your Time.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__06 - Judas.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__07 - Haunted.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__08 - Be Still.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__09 - Maybe.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__10 - How I Feel.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__11 - Yeah.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__12 - Can I Have A Kiss.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__13 - Irvine.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__back.jpg Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__cd.jpg Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Kelly Clarkson - My December\__INCOMPLETE__front.jpg Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___(06) missed the boat.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___02-good_charlotte-misery (www wareztotal com ar).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___04 - fly away.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___04 dance floor anthem.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___04-chrisette_michele-best_of_me.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___05 over the counter.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___08-lmno-the_crecent_and_the_cross_(feat _chace_infinite)-gcp.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___09-digitalism-anything_new.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___10-my piano.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___12_majik.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___14 - lovedrug - casino clouds(3).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___14-ams_uno-standing_in_the_reign-ftd.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___15-the_pharcyde-clouds-cms.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___17-substantial-what_u_want-whoa.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___common-the_game_(feat _dj_premier).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___common-the_people_(feat _dwele)_(prod _by_kanye_west)-(rapgodfathers com).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___dead_prez__-__mind_sex.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___death cab for cutie - i will follow you into the dark.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___gym class heroes - the papercut chronicles - nothing boy vs the echo factor.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___kanye west - can't tell me nothing (chesbomb).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___kanye west - can't tell me nothing.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___lifehouse_first time.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___lloyd - you - promo - ekek - you (feat lil wayne) (dirty).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___pharoahe monch - push - new stuff 2006(2).mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___the linguistics - 13 - where did hip-hop go.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Desktop\Music\___ARESTRA___ti ft wyclef - you know what it is94.mp3 Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ahead\Nero Home\is2.db-journal Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ares\Data\TempDL\PBTHash_560D64D00F9FC0828875B456EAEE358059F5F170.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Ares\Data\TempDL\PBTHash_D45EC899375F6B3C64FFD04FE78766909DECA03E.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D6F4_A43F_F4A4_23A9\dfsr.db Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D6F4_A43F_F4A4_23A9\fsr.log Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D6F4_A43F_F4A4_23A9\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D6F4_A43F_F4A4_23A9\tmp.edb Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\History\History.IE5\MSHist012007072920070730\index.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temp\~DFF00F.tmp Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temp\~DFF01C.tmp Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temp\~DFFA07.tmp Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temp\~DFFA14.tmp Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\93S8IWY1\UserStatusChange[1].html Object is locked skipped
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Monta Bellrose\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Monta Bellrose\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe Infected: Virus.Win32.Agent.ab skipped
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe Infected: Virus.Win32.Agent.ab skipped
C:\SDFix\backups\backups.zip/backups/asc3550u.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\SDFix\backups\backups.zip/backups/gmc.exe.exe Infected: Packed.Win32.Tibs.ap skipped
C:\SDFix\backups\backups.zip/backups/spooldr.exe Infected: Packed.Win32.Tibs.ap skipped
C:\SDFix\backups\backups.zip/backups/spooldr.sys Infected: Packed.Win32.Tibs.ap skipped
C:\SDFix\backups\backups.zip/backups/startdrv.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\SDFix\backups\backups.zip ZIP: infected - 5 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP21\A0018538.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP23\A0019539.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP23\A0020538.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP23\A0021538.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP33\A0022554.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP35\A0023538.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP38\A0024623.exe:ext.exe:$DATA Infected: Trojan.Win32.Obfuscated.gp skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP38\A0024907.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP40\A0025541.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP41\A0026610.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029576.sys Infected: Rootkit.Win32.Agent.ey skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029579.exe Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029580.exe Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029581.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029582.sys Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029587.sys Infected: Trojan-Proxy.Win32.Agent.mx skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029588.exe Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029589.exe Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029590.sys Infected: Packed.Win32.Tibs.ap skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029591.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\change.log Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\secdrv.sys Infected: Rootkit.Win32.Agent.dp skipped
C:\WINDOWS\$NtServicePackUninstall$\svchost.exe:ext.exe:$DATA Infected: Trojan.Win32.Obfuscated.gp skipped
C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys Infected: Trojan.Win32.Patched.ad skipped
C:\WINDOWS\47681728.exe Infected: Packed.Win32.PolyCrypt.b skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3813BBB6-F121-4367-91E3-01EF6BB69B8E}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\drivers\ip6fw.sys Infected: Rootkit.Win32.Agent.dp skipped
C:\WINDOWS\system32\drivers\_003714_.tmp.dll Infected: Trojan.Win32.Patched.ad skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\zoox1.dll Infected: Trojan-Spy.Win32.Banker.cji skipped
C:\WINDOWS\UpdReg.EXE Infected: Virus.Win32.Agent.ab skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Hi Jack This
Logfile of HijackThis v1.99.1
Scan saved at 3:08:09 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Uninstall List:
Acoustica MP3 Audio Mixer
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Adobe Photoshop 7.0
AirPlus XtremeG
ANIO Service
ANIWZCS2 Service
Ares 2.0.9
ASIO4ALL
Azureus Vuze
Collab
Digital Audio System
FL Studio 7
HijackThis 1.99.1
IL Download Manager
Kaspersky Online Scanner
Nero 7 Ultra Edition
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Spybot - Search & Destroy 1.4
Steinberg Hypersonic v1.0
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip
Looks like SDFix removed them before MoveIt could. That's why the message.I was unable to locate The OT move it log…. when i moved the files over it said that it "cannot create file C:\_OTMoveit\movedfiles7292007_152017.log.
OK we are not out of the woods yet. I don't see that you installed an AntiVirus.
The files below are legit but are being reported as infected. We first need to see if an AntiVirus will fix them.
C:\WINDOWS\$NtServicePackUninstall$\secdrv.sys
C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
Download one of those I mentioned and scan your system. Please.
Saty off the internet as much as possible until we get you cleaned up. This also means no Ares.
*=========================*
Please run a GMER Rootkit scan:
Download GMER's application from here:
http://www.gmer.net/gmer.zip
Unzip it and start the GMER.exe
Click the Rootkit tab and click the Scan button.
Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results in your next reply.
Warning ! Please, do not select the "Show all" checkbox during the scan.
If you're having problems with running GMER.exe, try it in safe mode.
This tools works in safe mode. Other rootkitrevealers don't.
*=========================*
Download and install AVG Anti-Spyware v7.5
- After download, double click on the file to launch the install process.
- Choose a language, click "OK" and then click "Next".
- Read the "License Agreement" and click "I Agree".
- Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
- After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
- The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. As AVG Anti-Spyware may interfere with some of our other fixes, we are temporarily disabling it's active protection features until your system is clean, then you can reenable them.
- Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
- Go to Start > Run and type: services.msc
- Press "OK".
- Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
- When you find the guard service, double-click on it.
- In the Properties Window > General Tab that opens, click the "Stop" button.
- From the drop-down menu next to "Startup Type", click on "Manual".
- Now click "Apply", then "OK" and close the Services window.
- Connect to the Internet, go back to AVG Anti-Spyware, select the "Update" button and click "Start update". Wait until you see the "Update successful" message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
- Exit AVG Anti-Spyware when done - DO NOT perform a scan yet.
Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*
Please double-click OTMoveIt.exe to run it.
Copy the file paths in the quotebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.C:\66.tmp
C:\6D.tmp
C:\WINDOWS\47681728.exe
C:\WINDOWS\system32\drivers\_003714_.tmp.dll
C:\WINDOWS\UpdReg.EXE
C:\WINDOWS\system32\zoox1.dll
C:\WINDOWS\Temp\startdrv.exe
C:\WINDOWS\system32\drivers\ip6fw.sys
Click the red Moveit! button.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
When done, it will create a log (********_******.log – * stands for date and time) in folder: C:\_OTMoveIt\MovedFiles.
*=========================*
Scan with AVG Anti-Spyware as follows:
- Click on the "Scanner" button and choose the "Settings" tab.
- Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
- Under "How to Scan?", "Possibly unwanted software", and What to Scan?" leave all the default settings.
- Under "Reports" select "Do not automatically generate report after every scan" and UNcheck "Only if threats were found".
- Click the "Scan" tab to return to scanning options.
- Click "Complete System Scan" to start.
- When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
- Click on "Report" button to view all completed scans.
- Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt.
- Save to your desktop. A copy of each report will also be saved in C:\Documents and Settings\Your User Name\Application Data\Grisoft\AVG Antispyware 7.5\Reports
- Exit AVG Anti-Spyware when done, reboot normally and submit the log report in your next response.
Please post the following;
GMER Log
AVG AntiSpyware log
New hijackthis log
How is the PC running?
Thanks,
Rogue
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-29 23:22:59
Windows 5.1.2600 Service Pack 2
—- User code sections - GMER 1.0.13 —-
.text C:\Program Files\MSN Messenger\msnmsgr.exe[2912] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\msnmsgr.exe
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE F5740C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE F573D7C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ F573960A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE F5739AED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION F5744958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION F5747821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA F575038A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA F574FD49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS F5749BBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION F574A331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION F57584F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL F5740B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL F573C948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL F574646B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN F575779D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL F5756C4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP F573D2FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP F57571DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible F57521F9
—- Registry - GMER 1.0.13 —-
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\FCI@bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 0x44 0x72 0x55 0x7E …
—- Files - GMER 1.0.13 —-
ADS C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP38\A0024623.exe:ext.exe
ADS C:\WINDOWS\$NtServicePackUninstall$\svchost.exe:ext.exe
—- EOF - GMER 1.0.13 —-
HIJACK THIS
Logfile of HijackThis v1.99.1
Scan saved at 11:29:40 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Are you using a 64 bit version of XP? You're not according to hijackthis.
Please double-click OTMoveIt.exe to run it.
Copy the file paths in the quotebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.C:\WINDOWS\$NtServicePackUninstall$\secdrv.sys
C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
Click the red Moveit! button.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
When done, it will create a log (********_******.log – * stands for date and time) in folder: C:\_OTMoveIt\MovedFiles.
*=========================*
Download Combofix by sUBs! from
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
or
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Save it to your Desktop
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log C:\ComboFix.txt
Post that log in your next reply
Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
*=========================*
Please post the following;
C:\ComboFix.txt
New hijackthis log
Thanks,
Rogue
2001-08-18 05:00 1982208 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\_003686_.tmp.dll.vir 2004-08-03 23:00 29056 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ip6fw.sys.vir 2007-07-22 14:53 9340 –a—— C:\Qoobox\Quarantine\C\WINDOWS\47681728.exe.vir 2007-07-30 23:35 1148 –a—— C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME.reg.cf Folder PATH listing Volume serial number is F4A4-23A9 C:\QOOBOX \—Quarantine +—C | \—WINDOWS | | 47681728.exe.vir | | | \—system32 | | _003686_.tmp.dll.vir | | | \—drivers | ip6fw.sys.vir | \—Registry_backups LEGACY_RUNTIME.reg.cf
Logfile of HijackThis v1.99.1
Scan saved at 23:40, on 2007-07-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\WebAssist.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
OK thanks for the information on the machine being 64 bit.
The ComboFix log is to short. Can you post the entire contents of C:\ComboFix.txt or rescan and post the new combofix log.
Backup the Registry
- Download ERUNT to your desktop
- Double-click on the file to install the program
- Untick the NTREGOPT desktop shortcut option
- Click No when you get the option to run Erunt at Windows startup.
- During the installation, tick Launch Erunt
- Accept the defaults for running a backup
- Erunt will then backup your registry
Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\WebAssist.dll
CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*
Registry Fix
Open Notepad!
Copy and Paste everything from the Quote box into Notepad:
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\FCI]
Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.
Go to File > Save As
Save File name as Fix.reg
Change Save as Type to All Files and save the file to your desktop.
Close Notepad, and double-click Fix.reg on your Desktop. When it asks if you want to merge the info to the registry, hit YES/OK.
*=========================*
Please post the following:
Combofix log
New hijackthis log
How the system is performing
Thanks,
Rogue
Combo Fix:
ComboFix 07-07-30.2 - "Monta Bellrose" 2007-07-30 23:33:47.1 [GMT -7:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\47681728.exe
C:\WINDOWS\system32\_003686_.tmp.dll
C:\WINDOWS\system32\drivers\ip6fw.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_RUNTIME
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 )))))))))))))))))))))))))))))))
2007-07-30 23:33 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-30 18:02 84,992 –a—— C:\WINDOWS\WebAssist.dll
2007-07-29 23:51 d——– C:\VundoFix Backups
2007-07-29 13:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-29 13:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-29 13:19 d——– C:\WINDOWS\ERUNT
2007-07-27 15:17 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Ahead
2007-07-27 15:14 d——– C:\Program Files\Nero
2007-07-27 15:14 d——– C:\Program Files\Common Files\Ahead
2007-07-27 03:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-26 23:27 510,976 –a—— C:\WINDOWS\system32\synsoacc.dll
2007-07-26 20:25 d–h—– C:\WINDOWS\PIF
2007-07-26 20:13 d–h—– C:\WINDOWS\$hf_mig$
2007-07-26 20:13 d——– C:\WINDOWS\system32\PreInstall
2007-07-26 18:42 23,617 –a—— C:\WINDOWS\system32\Qi75533j.exe
2007-07-26 18:18 d——– C:\WINDOWS\system32\LogFiles
2007-07-26 00:13 d——– C:\WINDOWS\Prefetch
2007-07-25 22:56 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Azureus
2007-07-25 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-07-25 22:54 d——– C:\Program Files\Azureus
2007-07-25 22:15 d——– C:\WINDOWS\provisioning
2007-07-25 22:15 d——– C:\WINDOWS\peernet
2007-07-25 22:14 d——– C:\WINDOWS\ServicePackFiles
2007-07-25 22:12 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-07-25 22:12 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-25 22:10 d——– C:\WINDOWS\EHome
2007-07-23 16:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 16:15 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-22 16:15 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-22 13:19 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-07-22 13:19 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-07-22 13:19 77,312 –a—— C:\WINDOWS\system32\browser.dll
2007-07-22 13:19 66,560 –a—— C:\WINDOWS\system32\mtxclu.dll
2007-07-22 13:19 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-07-22 13:19 614,912 –a—— C:\WINDOWS\system32\h323msp.dll
2007-07-22 13:19 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-07-22 13:19 581,120 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-07-22 13:19 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-07-22 13:19 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-07-22 13:19 40,960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-07-22 13:19 397,824 –a—— C:\WINDOWS\system32\rpcss.dll
2007-07-22 13:19 331,264 –a—— C:\WINDOWS\system32\ipnathlp.dll
2007-07-22 13:19 243,200 –a—— C:\WINDOWS\system32\es.dll
2007-07-22 13:19 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-07-22 13:19 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-07-22 13:19 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-07-22 13:19 101,376 –a—— C:\WINDOWS\system32\txflog.dll
2007-07-22 13:19 1,285,120 –a—— C:\WINDOWS\system32\ole32.dll
2007-07-22 13:19 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-07-22 13:10 26,112 –a—— C:\WINDOWS\system32\xpsp1hfm.exe
2007-07-22 13:10 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-07-22 13:10 d–h-c— C:\WINDOWS\$xpsp1hfm$
2007-07-21 13:12 d——– C:\WINDOWS\system32\bits
2007-07-20 23:57 50,688 –a—— C:\WINDOWS\system32\zoox1.dll
2007-07-18 12:26 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-07-18 12:26 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-07-18 01:45 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-18 01:45 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-18 01:45 146,944 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-17 19:37 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-17 19:32 225,280 –a—— C:\WINDOWS\system32\rewire.dll
2007-07-17 19:32 d——– C:\Program Files\VstPlugins
2007-07-17 19:32 d——– C:\Program Files\ASIO4ALL v2
2007-07-17 19:31 d——– C:\Program Files\Image-Line
2007-07-17 18:16 d—s—- C:\DOCUME~1\MONTAB~1\UserData
2007-07-17 17:57 348,160 –a—— C:\WINDOWS\system32\eSellerateEngine.dll
2007-07-17 17:57 d——– C:\Program Files\Acoustica MP3 Audio Mixer
2007-07-16 15:04 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-07-16 15:04 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-07-16 15:04 438,784 ——— C:\WINDOWS\system32\xpob2res.dll
2007-07-16 15:04 351,232 –a—— C:\WINDOWS\system32\winhttp.dll
2007-07-16 15:04 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-07-16 15:01 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-07-16 15:00 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-16 15:00 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-16 15:00 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-16 15:00 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-16 15:00 186,136 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-07-16 15:00 167,704 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-07-16 15:00 d——– C:\WINDOWS\SoftwareDistribution
2007-07-15 12:27 d——– C:\Program Files\Ares
2007-07-15 02:34 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-15 02:34 d——– C:\Program Files\MSN Messenger
2007-07-15 02:34 d——– C:\DOCUME~1\MONTAB~1\Contacts
2007-07-15 02:22 57,407 –a—— C:\WINDOWS\system32\ANICtl.dll
2007-07-15 02:22 49,152 –a—— C:\WINDOWS\system32\AQCKGen.dll
2007-07-15 02:22 368,640 –a—— C:\WINDOWS\system32\ANIWZCS2.dll
2007-07-15 02:22 36,864 –a—— C:\WINDOWS\system32\ANIOApi.dll
2007-07-15 02:22 28,205 –a—— C:\WINDOWS\system32\ANIO.sys
2007-07-15 02:22 221,184 –a—— C:\WINDOWS\system32\wlanapi.dll
2007-07-15 02:22 212,992 –a—— C:\WINDOWS\system32\aIPH.dll
2007-07-15 02:22 143,360 –a—— C:\WINDOWS\system32\WlanApp.dll
2007-07-15 02:22 11,904 –a—— C:\WINDOWS\system32\anio4.sys
2007-07-15 02:22 1,323,095 –a—— C:\WINDOWS\system32\odSupp_M.dll
2007-07-15 02:22 d——– C:\Program Files\D-Link
2007-07-15 02:22 d——– C:\Program Files\ANI
2007-07-15 02:20 d–hs—- C:\RECYCLER
2007-07-15 02:02 306,688 –a—— C:\WINDOWS\IsUninst.exe
2007-07-15 02:02 d——– C:\WINDOWS\Profiles
2007-07-15 02:02 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\InterTrust
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-24 18:34 342016 ——— C:\WINDOWS\system32\drivers\_003714_.tmp.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
2007-07-30 18:02 84992 –a—— C:\WINDOWS\WebAssist.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2005-05-24 01:28 C:\WINDOWS\CTHELPER.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 01:17 C:\WINDOWS\MIDIDEF.EXE]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-07-15 13:23]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-14 15:37]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"tlz"=C:\WINDOWS\47681728.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-26 23:42:38]
R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
R2 ANIO;ANIO Service;\??\C:\WINDOWS\System32\ANIO.SYS
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
R3 QCDonner;Logitech QuickCam Express;C:\WINDOWS\system32\DRIVERS\OVCD.sys
S3 Bridge;MAC Bridge;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys
Contents of the 'Scheduled Tasks' folder
2007-07-30 07:00:30 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 16:00:30 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 17:00:30 C:\WINDOWS\Tasks\At11.job
2007-07-30 18:00:30 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 19:00:30 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 20:00:30 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 21:00:30 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 22:00:30 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 23:00:30 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-31 00:00:30 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-31 01:00:30 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 08:00:30 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-31 02:00:30 C:\WINDOWS\Tasks\At20.job
2007-07-31 03:00:30 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-31 04:00:30 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-31 05:00:30 C:\WINDOWS\Tasks\At23.job
2007-07-31 06:00:30 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 09:00:30 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 10:00:30 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 11:00:30 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 12:00:30 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 13:00:30 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 14:00:30 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\system32\Qi75533j.exe
2007-07-30 15:00:30 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\system32\Qi75533j.exe
Hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 16:19, on 2007-08-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
A few posts back I asked you to install one of the AntiVirus programs that I provided a link to. You mentioned you installed Avast.
There are no signs that it was/has been installed. Before you go any further you must install and antivirus…there free… and keep it installed.
By not doing this we will continue to go in circles trying to get this cleaned.
Install one before you proceed any further.
Secondly if you are getting help elsewhere I need to know. I ask becuase you have recently ran VundoFix
Thridly I asked you to keep internet access to a minumum. Meaning this site only.
Now let's get to work
Open Notepad and copy/paste the text in the quotebox below into it:
Save this as CFScript.txthttp://forums.tomcoyote.org/Help_Me_t81729.html
File::
c:\WINDOWS\WebAssist.dll
C:\WINDOWS\system32\zoox1.dll
C:\WINDOWS\47681728.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
Folder::
C:\VundoFix Backups
Collect::
C:\WINDOWS\system32\Qi75533j.exe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"tlz"=-
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
[external image: Posted Image]
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
You will be prompted to submit Files for further analysis. When the first one prompts you press OK
At the seconf prompt: Copy this file path: C:\WINDOWS\system32\Qi75533j.exe into the box and press Send
*=========================*
Please post the following.
Combofix.txt
New hijackthis log
Thanks,
Rogue
but here's the latest logs.. i now have the clamwin antivirus
ComboFix 07-07-30.2 - "Monta Bellrose" 2007-08-07 21:17:46.2 [GMT -7:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\Monta Bellrose\Desktop\CFScript.txt
* Created a new restore point
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
Logfile of HijackThis v1.99.1
Scan saved at 9:45:21 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\tmp2E.tmp.dll (file missing)
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\vtsqnli.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\CTGmon.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp13.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp15.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2C.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2D.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2E.tmp.exe
C:\VundoFix Backups
C:\WINDOWS\system32\dnf4a423a9.dat
C:\WINDOWS\system32\Qi75533j.exe
C:\WINDOWS\system32\qwerty12.exe
C:\WINDOWS\system32\tmp2E.tmp.dll
C:\WINDOWS\system32\zoox1.dll
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_DOMAINSERVICE
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 )))))))))))))))))))))))))))))))
2007-08-07 17:25 d——– C:\Program Files\ClamWin
2007-08-07 17:25 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-08-07 17:25 d——– C:\DOCUME~1\ALLUSE~1\.clamwin
2007-08-07 15:29 131,385 –a—— C:\WINDOWS\khggee.dll
2007-08-04 14:43 13,380 –a—— C:\WINDOWS\system32\vtsqnli.dll
2007-08-02 19:20 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-08-02 19:19 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-08-02 19:18 d——– C:\Program Files\Google
2007-08-02 19:18 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Google
2007-08-02 18:28 d——– C:\Program Files\Windows Media Connect 2
2007-08-02 18:27 d——– C:\WINDOWS\system32\drivers\UMDF
2007-07-30 23:33 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-29 13:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-29 13:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-29 13:19 d——– C:\WINDOWS\ERUNT
2007-07-27 15:17 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Ahead
2007-07-27 15:14 d——– C:\Program Files\Nero
2007-07-27 15:14 d——– C:\Program Files\Common Files\Ahead
2007-07-27 03:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-26 23:27 510,976 –a—— C:\WINDOWS\system32\synsoacc.dll
2007-07-26 20:25 d–h—– C:\WINDOWS\PIF
2007-07-26 20:13 d–h—– C:\WINDOWS\$hf_mig$
2007-07-26 20:13 d——– C:\WINDOWS\system32\PreInstall
2007-07-26 18:18 d——– C:\WINDOWS\system32\LogFiles
2007-07-26 00:13 d——– C:\WINDOWS\Prefetch
2007-07-25 22:56 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Azureus
2007-07-25 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-07-25 22:54 d——– C:\Program Files\Azureus
2007-07-25 22:15 d——– C:\WINDOWS\provisioning
2007-07-25 22:15 d——– C:\WINDOWS\peernet
2007-07-25 22:14 d——– C:\WINDOWS\ServicePackFiles
2007-07-25 22:12 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-07-25 22:12 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-25 22:10 d——– C:\WINDOWS\EHome
2007-07-23 16:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 16:15 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-22 16:15 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-22 13:19 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-07-22 13:19 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-07-22 13:19 77,312 –a—— C:\WINDOWS\system32\browser.dll
2007-07-22 13:19 66,560 –a—— C:\WINDOWS\system32\mtxclu.dll
2007-07-22 13:19 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-07-22 13:19 614,912 –a—— C:\WINDOWS\system32\h323msp.dll
2007-07-22 13:19 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-07-22 13:19 581,120 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-07-22 13:19 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-07-22 13:19 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-07-22 13:19 40,960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-07-22 13:19 397,824 –a—— C:\WINDOWS\system32\rpcss.dll
2007-07-22 13:19 331,264 –a—— C:\WINDOWS\system32\ipnathlp.dll
2007-07-22 13:19 243,200 –a—— C:\WINDOWS\system32\es.dll
2007-07-22 13:19 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-07-22 13:19 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-07-22 13:19 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-07-22 13:19 101,376 –a—— C:\WINDOWS\system32\txflog.dll
2007-07-22 13:19 1,285,120 –a—— C:\WINDOWS\system32\ole32.dll
2007-07-22 13:19 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-07-22 13:10 26,112 –a—— C:\WINDOWS\system32\xpsp1hfm.exe
2007-07-22 13:10 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-07-22 13:10 d–h-c— C:\WINDOWS\$xpsp1hfm$
2007-07-21 13:12 d——– C:\WINDOWS\system32\bits
2007-07-18 12:26 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-07-18 12:26 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-07-18 01:45 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-18 01:45 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-18 01:45 146,944 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-17 19:37 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-17 19:32 225,280 –a—— C:\WINDOWS\system32\rewire.dll
2007-07-17 19:32 d——– C:\Program Files\VstPlugins
2007-07-17 19:32 d——– C:\Program Files\ASIO4ALL v2
2007-07-17 19:31 d——– C:\Program Files\Image-Line
2007-07-17 18:16 d—s—- C:\DOCUME~1\MONTAB~1\UserData
2007-07-17 17:57 348,160 –a—— C:\WINDOWS\system32\eSellerateEngine.dll
2007-07-17 17:57 d——– C:\Program Files\Acoustica MP3 Audio Mixer
2007-07-16 15:04 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-07-16 15:04 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-07-16 15:04 438,784 ——— C:\WINDOWS\system32\xpob2res.dll
2007-07-16 15:04 351,232 –a—— C:\WINDOWS\system32\winhttp.dll
2007-07-16 15:04 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-07-16 15:01 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-07-16 15:00 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-16 15:00 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-16 15:00 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-16 15:00 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-16 15:00 186,136 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-07-16 15:00 167,704 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-07-16 15:00 d——– C:\WINDOWS\SoftwareDistribution
2007-07-15 12:27 d——– C:\Program Files\Ares
2007-07-15 02:34 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-15 02:34 d——– C:\Program Files\MSN Messenger
2007-07-15 02:34 d——– C:\DOCUME~1\MONTAB~1\Contacts
2007-07-15 02:22 57,407 –a—— C:\WINDOWS\system32\ANICtl.dll
2007-07-15 02:22 49,152 –a—— C:\WINDOWS\system32\AQCKGen.dll
2007-07-15 02:22 368,640 –a—— C:\WINDOWS\system32\ANIWZCS2.dll
2007-07-15 02:22 36,864 –a—— C:\WINDOWS\system32\ANIOApi.dll
2007-07-15 02:22 28,205 –a—— C:\WINDOWS\system32\ANIO.sys
2007-07-15 02:22 221,184 –a—— C:\WINDOWS\system32\wlanapi.dll
2007-07-15 02:22 212,992 –a—— C:\WINDOWS\system32\aIPH.dll
2007-07-15 02:22 143,360 –a—— C:\WINDOWS\system32\WlanApp.dll
2007-07-15 02:22 11,904 –a—— C:\WINDOWS\system32\anio4.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 17:25 ——— d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-07-24 18:34 342016 ——— C:\WINDOWS\system32\drivers\_003714_.tmp.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
C:\WINDOWS\system32\tmp2E.tmp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2005-05-24 01:28 C:\WINDOWS\CTHELPER.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-07-23 02:17]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 01:17 C:\WINDOWS\MIDIDEF.EXE]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-07-15 13:23]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-14 15:37]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-26 23:42:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\vtsqnli.dll
R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
R2 ANIO;ANIO Service;\??\C:\WINDOWS\System32\ANIO.SYS
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
R3 QCDonner;Logitech QuickCam Express;C:\WINDOWS\system32\DRIVERS\OVCD.sys
S3 Bridge;MAC Bridge;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 21:20:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-07 21:21:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-07 21:21
— E O F —
Sorry for the delay. I didn't get an email notification on the post
OK thanks. It does make it a bit more difficult if both are try to solve it as some tools logs that you may use may have clues that I don't get to see.no.. im not getting help from anywhere else.. i just thought id give that a shot…didnt think it would matter…
Excellent. Make sure it stays on the system and running.i now have the clamwin antivirus
*=========================*
Open Notepad and copy/paste the text in the quotebox below into it:
Save this as CFScript.txtFile::
C:\WINDOWS\khggee.dll
C:\WINDOWS\system32\vtsqnli.dll
C:\WINDOWS\system32\tmp2E.tmp.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=-
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
[external image: Posted Image]
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*
Please run another GMER Rootkit scan:
Start the GMER.exe
Click the Rootkit tab and click the Scan button.
Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results in your next reply.
Warning ! Please, do not select the "Show all" checkbox during the scan.
If you're having problems with running GMER.exe, try it in safe mode.
This tools works in safe mode. Other rootkitrevealers don't.
*=========================*
Download SUPERAntiSpyware
http://www.superantispyware.com/ Free for Home Users
- Double-click SUPERAntiSpyware.exe and use the default settings for installation.
- An icon will be created on your desktop. Double-click that icon to launch the program.
- If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here .)
- Under "Configuration and Preferences", click the Preferences button.
- Click the Scanning Control tab.
- Under Scanner Options make sure the following are checked (leave all others unchecked):
- Close browsers before scanning.
- Scan for tracking cookies.
- Terminate memory threats before quarantining.
- Click the "Close" button to leave the control center screen.
- Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
- On the left, make sure you check C:\Fixed Drive.
- On the right, under "Complete Scan", choose Perform Complete Scan.
- Click "Next" to start the scan. Please be patient while it scans your computer.
- After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
- Make sure everything has a checkmark next to it and click "Next".
- A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
- If asked if you want to reboot, click "Yes".
- To retrieve the removal information after reboot, launch SUPERAntispyware again.
- Click Preferences, then click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
- Please copy and paste the Scan Log results in your next reply with a new hijackthis log.
- Click Close to exit the program.
Please post the following:
ComboFix.txt
GMER Log
SUPERAntiSpyware log
New hijackthis log
How is the system performing?
Thanks
Rogue
ComboFix:
ComboFix 07-07-30.2 - "Monta Bellrose" 2007-08-07 21:17:46.2 [GMT -7:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\Monta Bellrose\Desktop\CFScript.txt
* Created a new restore point
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\CTGmon.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp13.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp15.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2C.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2D.tmp.exe
C:\DOCUME~1\MONTAB~1\APPLIC~1\tmp2E.tmp.exe
C:\VundoFix Backups
C:\WINDOWS\system32\dnf4a423a9.dat
C:\WINDOWS\system32\Qi75533j.exe
C:\WINDOWS\system32\qwerty12.exe
C:\WINDOWS\system32\tmp2E.tmp.dll
C:\WINDOWS\system32\zoox1.dll
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_DOMAINSERVICE
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 )))))))))))))))))))))))))))))))
2007-08-07 17:25 d——– C:\Program Files\ClamWin
2007-08-07 17:25 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-08-07 17:25 d——– C:\DOCUME~1\ALLUSE~1\.clamwin
2007-08-07 15:29 131,385 –a—— C:\WINDOWS\khggee.dll
2007-08-04 14:43 13,380 –a—— C:\WINDOWS\system32\vtsqnli.dll
2007-08-02 19:20 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-08-02 19:19 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-08-02 19:18 d——– C:\Program Files\Google
2007-08-02 19:18 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Google
2007-08-02 18:28 d——– C:\Program Files\Windows Media Connect 2
2007-08-02 18:27 d——– C:\WINDOWS\system32\drivers\UMDF
2007-07-30 23:33 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-29 13:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-29 13:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-29 13:19 d——– C:\WINDOWS\ERUNT
2007-07-27 15:17 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Ahead
2007-07-27 15:14 d——– C:\Program Files\Nero
2007-07-27 15:14 d——– C:\Program Files\Common Files\Ahead
2007-07-27 03:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-26 23:27 510,976 –a—— C:\WINDOWS\system32\synsoacc.dll
2007-07-26 20:25 d–h—– C:\WINDOWS\PIF
2007-07-26 20:13 d–h—– C:\WINDOWS\$hf_mig$
2007-07-26 20:13 d——– C:\WINDOWS\system32\PreInstall
2007-07-26 18:18 d——– C:\WINDOWS\system32\LogFiles
2007-07-26 00:13 d——– C:\WINDOWS\Prefetch
2007-07-25 22:56 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Azureus
2007-07-25 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-07-25 22:54 d——– C:\Program Files\Azureus
2007-07-25 22:15 d——– C:\WINDOWS\provisioning
2007-07-25 22:15 d——– C:\WINDOWS\peernet
2007-07-25 22:14 d——– C:\WINDOWS\ServicePackFiles
2007-07-25 22:12 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-07-25 22:12 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-25 22:10 d——– C:\WINDOWS\EHome
2007-07-23 16:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 16:15 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-22 16:15 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-22 13:19 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-07-22 13:19 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-07-22 13:19 77,312 –a—— C:\WINDOWS\system32\browser.dll
2007-07-22 13:19 66,560 –a—— C:\WINDOWS\system32\mtxclu.dll
2007-07-22 13:19 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-07-22 13:19 614,912 –a—— C:\WINDOWS\system32\h323msp.dll
2007-07-22 13:19 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-07-22 13:19 581,120 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-07-22 13:19 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-07-22 13:19 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-07-22 13:19 40,960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-07-22 13:19 397,824 –a—— C:\WINDOWS\system32\rpcss.dll
2007-07-22 13:19 331,264 –a—— C:\WINDOWS\system32\ipnathlp.dll
2007-07-22 13:19 243,200 –a—— C:\WINDOWS\system32\es.dll
2007-07-22 13:19 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-07-22 13:19 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-07-22 13:19 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-07-22 13:19 101,376 –a—— C:\WINDOWS\system32\txflog.dll
2007-07-22 13:19 1,285,120 –a—— C:\WINDOWS\system32\ole32.dll
2007-07-22 13:19 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-07-22 13:10 26,112 –a—— C:\WINDOWS\system32\xpsp1hfm.exe
2007-07-22 13:10 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-07-22 13:10 d–h-c— C:\WINDOWS\$xpsp1hfm$
2007-07-21 13:12 d——– C:\WINDOWS\system32\bits
2007-07-18 12:26 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-07-18 12:26 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-07-18 01:45 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-18 01:45 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-18 01:45 146,944 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-17 19:37 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-17 19:32 225,280 –a—— C:\WINDOWS\system32\rewire.dll
2007-07-17 19:32 d——– C:\Program Files\VstPlugins
2007-07-17 19:32 d——– C:\Program Files\ASIO4ALL v2
2007-07-17 19:31 d——– C:\Program Files\Image-Line
2007-07-17 18:16 d—s—- C:\DOCUME~1\MONTAB~1\UserData
2007-07-17 17:57 348,160 –a—— C:\WINDOWS\system32\eSellerateEngine.dll
2007-07-17 17:57 d——– C:\Program Files\Acoustica MP3 Audio Mixer
2007-07-16 15:04 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-07-16 15:04 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-07-16 15:04 438,784 ——— C:\WINDOWS\system32\xpob2res.dll
2007-07-16 15:04 351,232 –a—— C:\WINDOWS\system32\winhttp.dll
2007-07-16 15:04 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-07-16 15:01 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-07-16 15:00 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-16 15:00 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-16 15:00 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-16 15:00 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-16 15:00 186,136 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-07-16 15:00 167,704 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-07-16 15:00 d——– C:\WINDOWS\SoftwareDistribution
2007-07-15 12:27 d——– C:\Program Files\Ares
2007-07-15 02:34 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-15 02:34 d——– C:\Program Files\MSN Messenger
2007-07-15 02:34 d——– C:\DOCUME~1\MONTAB~1\Contacts
2007-07-15 02:22 57,407 –a—— C:\WINDOWS\system32\ANICtl.dll
2007-07-15 02:22 49,152 –a—— C:\WINDOWS\system32\AQCKGen.dll
2007-07-15 02:22 368,640 –a—— C:\WINDOWS\system32\ANIWZCS2.dll
2007-07-15 02:22 36,864 –a—— C:\WINDOWS\system32\ANIOApi.dll
2007-07-15 02:22 28,205 –a—— C:\WINDOWS\system32\ANIO.sys
2007-07-15 02:22 221,184 –a—— C:\WINDOWS\system32\wlanapi.dll
2007-07-15 02:22 212,992 –a—— C:\WINDOWS\system32\aIPH.dll
2007-07-15 02:22 143,360 –a—— C:\WINDOWS\system32\WlanApp.dll
2007-07-15 02:22 11,904 –a—— C:\WINDOWS\system32\anio4.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 17:25 ——— d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-07-24 18:34 342016 ——— C:\WINDOWS\system32\drivers\_003714_.tmp.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
C:\WINDOWS\system32\tmp2E.tmp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2005-05-24 01:28 C:\WINDOWS\CTHELPER.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-07-23 02:17]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 01:17 C:\WINDOWS\MIDIDEF.EXE]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-07-15 13:23]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-14 15:37]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-26 23:42:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\vtsqnli.dll
R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
R2 ANIO;ANIO Service;\??\C:\WINDOWS\System32\ANIO.SYS
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
R3 QCDonner;Logitech QuickCam Express;C:\WINDOWS\system32\DRIVERS\OVCD.sys
S3 Bridge;MAC Bridge;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-07 21:20:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-07 21:21:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-07 21:21
— E O F —
SuperAntispyware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 08/10/2007 at 01:23 PM
Application Version : 3.9.1008
Core Rules Database Version : 3283
Trace Rules Database Version: 1294
Scan type : Complete Scan
Total Scan Time : 00:20:00
Memory items scanned : 357
Memory threats detected : 0
Registry items scanned : 4252
Registry threats detected : 0
File items scanned : 29502
File threats detected : 74
Adware.Tracking Cookie
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@winantivirus[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@serving-sys[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@adbrite[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@msnportal.112.2o7[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@hitbox[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@pro-market[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@adrevolver[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@revsci[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@adcentriconline[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@network-ca.247realmedia[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@247realmedia[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@casalemedia[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@mediaplex[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@2o7[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@doubleclick[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@advertising[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@atdmt[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@clicktorrent[2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][2].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@adrevolver[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@tribalfusion[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed][1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta [removed]-sys[1].txt
C:\Documents and Settings\Monta Bellrose\Cookies\monta bellrose@realmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@67.15.239[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@67.15.239[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@67.15.239[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@67.15.239[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@67.15.239[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\[removed][2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@spylog[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\system@yadro[1].txt
Trojan.Duncan
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\CTGMON.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\C_1FIG.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP59\A0031883.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP62\A0032036.DLL
Unclassified.Unknown Origin/System
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\VTSQNLI.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP62\A0032024.DLL
Rootkit.SpoolDR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029582.SYS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP45\A0029590.SYS
Trace.Known Threat Sources
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\default[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\img_01[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\img_14[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\INCJMTAV\checksoft[1].js
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\win1[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\img_03[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\tb_01[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\KDAH07QL\check[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\INCJMTAV\img_13[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\KDAH07QL\bt_bgT[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\2007[1].htm
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\INCJMTAV\no[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\KDAH07QL\box2[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\KDAH07QL\CAOXQR0H.js
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\INCJMTAV\img_11[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\img_37[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\KDAH07QL\img_02[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\test[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\WLMPYD8D\img_12[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\YDJC94B6\banner1026n[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\INCJMTAV\tb_03[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\win2[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\bg[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\SR2XKXQX\boton1[1].gif
C:\Documents and Settings\Monta Bellrose\Local Settings\Temporary Internet Files\Content.IE5\GN8RT6UA\banner1026n[1].gif
Gmer Log:
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-08-10 13:56:27
Windows 5.1.2600 Service Pack 2
—- User code sections - GMER 1.0.13 —-
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[1524] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\MsnMsgr.Exe
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE F551BC8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE F55187C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ F551460A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE F5514AED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION F551F958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION F5522821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA F552B38A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA F552AD49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS F5524BBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION F5525331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION F55334F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL F551BB37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL F5517948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL F552146B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN F553279D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL F5531C4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP F55182FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP F55321DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible F552D1F9
—- Files - GMER 1.0.13 —-
ADS C:\System Volume Information\_restore{CFF0AB9A-E74E-438C-8275-E0BDC7DB5346}\RP38\A0024623.exe:ext.exe
ADS C:\_OTMoveIt\MovedFiles\WINDOWS\$NtServicePackUninstall$\svchost.exe:ext.exe
—- EOF - GMER 1.0.13 —-
HIJackthis:
Logfile of HijackThis v1.99.1
Scan saved at 13:56, on 2007-08-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Monta Bellrose\Desktop\gmer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Looking a lot better.
I strongly encourage you to install one of the firewalls I have listed below.
I would also like you to install a new version of Combofix at the end. But before that do the following.
- Double click OTMoveIt.exe to launch the program.
- Click on the CleanUp! button.
- OTMoveIt will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
- You will be prompted to allow the clean up procedure, click Yes
- When finished exit out of OTMoveIt
Flush System Restore
Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a Restore Point, and then click Ok
Next, go to Start > Run and type in cleanmgr
Select the More Options tab
Choose the option to Clean Up System Restore and select OK.
This will remove all restore points except the new one you just created
*========================*
Use a Firewall - this keeps your computer safe from hackers AS WELL AS from several computer viruses (mostly worms) which spread through the internet by using security holes of Windows. Have in mind that these are FREE FULL versions of the software and they lack of some features available in their shareware versions. Nevertheless, the FREE versions are capable of providing a basic firewall protection to your computer.
- Kerio Personal Firewall
- ZoneAlarm©
- Outpost Free
- Comodo
- Sygate (not supported anymore but you can download from here
*========================*
Download Combofix by sUBs! from
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
or
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Save it to your Desktop
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log C:\ComboFix.txt
Post that log in your next reply
Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
*=========================*
C:\ComboFix.txt
New hijackthis log
Thanks,
Rogue
ComboFix 07-08-09.3 - "Monta Bellrose" 2007-08-13 13:11:13.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.563 [GMT -7:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\MONTAB~1\spooldr.ini
((((((((((((((((((((((((( Files Created from 2007-07-13 to 2007-08-13 )))))))))))))))))))))))))))))))
2007-08-13 13:10 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-12 21:56 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Yahoo!
2007-08-12 21:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-08-12 21:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-08-12 21:50 d——– C:\Program Files\Yahoo!
2007-08-11 19:12 d——– C:\Program Files\Common Files\Agnitum Shared
2007-08-11 19:11 d——– C:\Program Files\Agnitum
2007-08-10 13:00 d——– C:\Program Files\SUPERAntiSpyware
2007-08-10 13:00 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-10 13:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-10 12:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-08-07 17:25 d——– C:\Program Files\ClamWin
2007-08-07 17:25 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-08-07 17:25 d——– C:\DOCUME~1\ALLUSE~1\.clamwin
2007-08-02 19:20 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-08-02 19:19 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-08-02 19:18 d——– C:\Program Files\Google
2007-08-02 19:18 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Google
2007-08-02 18:28 d——– C:\Program Files\Windows Media Connect 2
2007-08-02 18:27 d——– C:\WINDOWS\system32\drivers\UMDF
2007-07-29 13:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-29 13:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-29 13:19 d——– C:\WINDOWS\ERUNT
2007-07-27 15:17 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Ahead
2007-07-27 15:14 d——– C:\Program Files\Nero
2007-07-27 15:14 d——– C:\Program Files\Common Files\Ahead
2007-07-27 03:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-27 03:01 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-07-27 03:01 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-07-27 03:01 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-07-26 23:27 510,976 –a—— C:\WINDOWS\system32\synsoacc.dll
2007-07-26 20:25 d–h—– C:\WINDOWS\PIF
2007-07-26 20:13 d–h—– C:\WINDOWS\$hf_mig$
2007-07-26 20:13 d——– C:\WINDOWS\system32\PreInstall
2007-07-26 18:18 d——– C:\WINDOWS\system32\LogFiles
2007-07-26 00:13 d——– C:\WINDOWS\Prefetch
2007-07-25 22:56 d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\Azureus
2007-07-25 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-07-25 22:54 d——– C:\Program Files\Azureus
2007-07-25 22:15 d——– C:\WINDOWS\provisioning
2007-07-25 22:15 d——– C:\WINDOWS\peernet
2007-07-25 22:14 d——– C:\WINDOWS\ServicePackFiles
2007-07-25 22:12 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-07-25 22:12 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-25 22:10 d——– C:\WINDOWS\EHome
2007-07-23 16:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 16:15 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-22 16:15 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-22 13:19 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-07-22 13:19 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-07-22 13:19 77,312 –a—— C:\WINDOWS\system32\browser.dll
2007-07-22 13:19 66,560 –a—— C:\WINDOWS\system32\mtxclu.dll
2007-07-22 13:19 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-07-22 13:19 614,912 –a—— C:\WINDOWS\system32\h323msp.dll
2007-07-22 13:19 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-07-22 13:19 581,120 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-07-22 13:19 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-07-22 13:19 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-07-22 13:19 40,960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-07-22 13:19 40,960 —–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-07-22 13:19 397,824 –a—— C:\WINDOWS\system32\rpcss.dll
2007-07-22 13:19 331,264 –a—— C:\WINDOWS\system32\ipnathlp.dll
2007-07-22 13:19 243,200 –a—— C:\WINDOWS\system32\es.dll
2007-07-22 13:19 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-07-22 13:19 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-07-22 13:19 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-07-22 13:19 101,376 –a—— C:\WINDOWS\system32\txflog.dll
2007-07-22 13:19 1,285,120 –a—— C:\WINDOWS\system32\ole32.dll
2007-07-22 13:19 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-07-22 13:10 26,112 –a—— C:\WINDOWS\system32\xpsp1hfm.exe
2007-07-22 13:10 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-07-22 13:10 d–h-c— C:\WINDOWS\$xpsp1hfm$
2007-07-21 13:12 d——– C:\WINDOWS\system32\bits
2007-07-18 12:26 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-07-18 12:26 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-07-18 01:45 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-18 01:45 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-18 01:45 146,944 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-17 19:37 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-17 19:32 225,280 –a—— C:\WINDOWS\system32\rewire.dll
2007-07-17 19:32 d——– C:\Program Files\VstPlugins
2007-07-17 19:32 d——– C:\Program Files\ASIO4ALL v2
2007-07-17 19:31 d——– C:\Program Files\Image-Line
2007-07-17 18:16 d—s—- C:\DOCUME~1\MONTAB~1\UserData
2007-07-17 17:57 d——– C:\Program Files\Acoustica MP3 Audio Mixer
2007-07-16 15:04 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-07-16 15:04 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-07-16 15:04 438,784 ——— C:\WINDOWS\system32\xpob2res.dll
2007-07-16 15:04 351,232 –a—— C:\WINDOWS\system32\winhttp.dll
2007-07-16 15:04 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-07-16 15:01 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-07-16 15:00 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-16 15:00 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-16 15:00 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-16 15:00 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-16 15:00 186,136 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-07-16 15:00 167,704 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-07-16 15:00 d——– C:\WINDOWS\SoftwareDistribution
2007-07-15 12:27 d——– C:\Program Files\Ares
2007-07-15 02:34 d—-c— C:\WINDOWS\system32\DRVSTORE
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 17:25 ——— d——– C:\DOCUME~1\MONTAB~1\APPLIC~1\.clamwin
2007-07-24 18:34 342016 ——— C:\WINDOWS\system32\drivers\_003714_.tmp.dll
2007-05-16 08:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 08:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 08:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 08:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 08:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2005-05-24 01:28 C:\WINDOWS\CTHELPER.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-07-23 02:17]
"Outpost Firewall"="C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 16:56]
"OutpostFeedBack"="C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 13:18]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 01:17 C:\WINDOWS\MIDIDEF.EXE]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-07-15 13:23]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-14 15:37]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-07-16 15:17]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-26 23:42:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
R1 SandBox;Outpost Firewall Sandbox Driver;\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R1 VFILT;Outpost Firewall Kernel Driver;\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL
R3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);\??\C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL
S3 Bridge;MAC Bridge;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system32\DRIVERS\bridge.sys
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-13 13:18:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-13 13:22:46
C:\ComboFix-quarantined-files.txt … 2007-08-13 13:22
— E O F —
Hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 1:47:48 PM, on 8/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{B445C4EE-C935-4461-933F-171F7EB9303D}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8DA83D-DAFA-4BE6-86D5-457F645A61DF}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{E30D886A-BD3F-420A-AFCF-A962041098BB}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F14B1FE8-D826-4C3D-B882-CB9F73854931}: NameServer = 62.217.54.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB0CEB6-A555-4560-9BD6-F66C83D7750E}: NameServer = 62.217.54.69
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI