This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Hijackthis Log

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here's my Log:
_____________________________________________________________
StartupList report, 8/1/2007, 12:04:11 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\TEMP\win1A6.tmp.exe
C:\WINDOWS\mgrs.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

avp = C:\WINDOWS\TEMP\win1A6.tmp.exe
CTDrive = rundll32.exe C:\WINDOWS\system32\drvheg.dll,startup
smgr = mgrs.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
SystemOptimizer = rundll32.exe "C:\WINDOWS\system32\fcopidtl.dll",forkonce

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

DW4 =
Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
Uaol = "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazb

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
McAfee.com Scan for Viruses - My Computer (D9KM7Z81-Chase).job
SpywareBot Scheduled Scan.job
Uniblue SpeedUpMyPC Nag.job
Uniblue SpeedUpMyPC.job
Uniblue SpyEraser.job

————————————————–

Enumerating Download Program Files:

[iPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ipixx.ocx
CODEBASE = http://www.ipix.com/viewers/ipixx.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\yinsthelper.dll

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

Protocol #1: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #2: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #3: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #4: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #5: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #6: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #7: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #8: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #9: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #10: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #11: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #12: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #13: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #14: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #15: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #16: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #17: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #18: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #19: C:\Program Files\Hide My IP 2007\ProxyFilter.dll
Protocol #39: C:\Program Files\Hide My IP 2007\ProxyFilter.dll

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: c:\windows\system32\swafrvvw.exe||C:\WINDOWS\system32\jalopidh.dll


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

————————————————–
End of report, 6,780 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
______________________________________________________________


Computer Symptoms:

IE & Firefox Popups
Multiple Error Messages
Unknown Toolbar Icons telling me that I have Spyware.
Same Three Icons on my Desktop (Keep Re-Appearing, even after deletion)
-Free Online Dating
-Go to Casino
-Find Spyware Now
Applications not opening
Computer going slow
Firefox Freeze ups, attempts to repair fail, causing manual shut down of computer

Please help! :(
Hello Chase and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


Please run HijackThis.exe, scan, produce al og and post it in your reply.

Regards,

Trevuren
Thank you so much for responding! :)

Here's my log. My apologies, I thought the last one was the actual log. :P

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:54 AM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\TEMP\win9A.tmp.exe
C:\WINDOWS\mgrs.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
O3 - Toolbar: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win9A.tmp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvheg.dll,startup
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\idstmeaa.dll",forkonce
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Uaol] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazb
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\yo\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O22 - SharedTaskScheduler: za - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINDOWS\wjejmlav.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8671 bytes
A. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


B. I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

1. Click Start, then Settings, then click Control Panel.
2. In Control Panel, double-click Add or Remove Programs.
3. In Add or Remove Programs, Remove the Viewpoint component
4. Do the same for each Viewpoint component.


C.
Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
ComboFix Log

ComboFix 07-08-02.3 - "Chase" 2007-08-02 13:22:14.2 [GMT -5:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\d.exe
C:\DOCUME~1\Chase\APPLIC~1\install.dat
C:\DOCUME~1\Chase\Desktop.\internet explorer.lnk
C:\DOCUME~1\yo\APPLIC~1\install.dat
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\WINDOWS\inetloader.dll
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\byxurst.dll
C:\WINDOWS\system32\cbxvutu.dll
C:\WINDOWS\system32\ducmbbhi.exe
C:\WINDOWS\system32\duvvxdgy.exe
C:\WINDOWS\system32\efcdaxv.dll
C:\WINDOWS\system32\egoiraqu.exe
C:\WINDOWS\system32\ekxvoeio.exe
C:\WINDOWS\system32\fccbawx.dll
C:\WINDOWS\system32\fccdbxy.dll
C:\WINDOWS\system32\giguaelj.exe
C:\WINDOWS\system32\hhkmp.bak1
C:\WINDOWS\system32\hhkmp.bak2
C:\WINDOWS\system32\hhkmp.ini
C:\WINDOWS\system32\hhkmp.ini2
C:\WINDOWS\system32\hhkmp.tmp
C:\WINDOWS\system32\hlpsrv.exe
C:\WINDOWS\system32\ixbhqqdk.exe
C:\WINDOWS\system32\knqjximj.exe
C:\WINDOWS\system32\kvbxgvgy.exe
C:\WINDOWS\system32\lgjxxcnr.exe
C:\WINDOWS\system32\mbegbeph.exe
C:\WINDOWS\system32\msasxbpy.exe
C:\WINDOWS\system32\okidggtx.dll
C:\WINDOWS\system32\okqeytlm.exe
C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\rdgdxfcj.dll
C:\WINDOWS\system32\rpjkueee.exe
C:\WINDOWS\system32\sledryqr.exe
C:\WINDOWS\system32\sqhneuoe.exe
C:\WINDOWS\system32\sqrbuwef.exe
C:\WINDOWS\system32\tuvwurq.dll
C:\WINDOWS\system32\uwcctjrn.exe
C:\WINDOWS\system32\vnsvifbu.exe
C:\WINDOWS\system32\winnwn32.dll
C:\WINDOWS\system32\xgiosmvd.exe
C:\WINDOWS\system32\xxywwts.dll
C:\WINDOWS\wr.txt
C:\windows\xpupdate.exe


((((((((((((((((((((((((( Files Created from 2007-07-02 to 2007-08-02 )))))))))))))))))))))))))))))))


2007-08-02 13:10 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 03:31 125,504 –a—— C:\WINDOWS\system32\natnugfu.dll
2007-08-02 03:25 d——– C:\DOCUME~1\Chase\APPLIC~1\Comodo
2007-08-02 03:21 d——– C:\Program Files\Comodo
2007-08-01 16:09 21,504 –a—— C:\WINDOWS\system32\atmfda.dll
2007-08-01 15:42 d——– C:\Program Files\Magicantispy
2007-08-01 01:52 dr-h—– C:\DOCUME~1\Chase\APPLIC~1\yahoo!
2007-07-31 23:45 d——– C:\Program Files\Trend Micro
2007-07-31 18:29 125,504 –a—— C:\WINDOWS\system32\meamkhvj.dll
2007-07-31 17:53 125,504 –a—— C:\WINDOWS\system32\tpqkmrjs.dll
2007-07-31 17:09 d——– C:\Program Files\Image ActiveX Access
2007-07-31 17:06 70,312 –a—— C:\Program Files\codec_setup.exe
2007-07-31 17:04 93,696 –a—— C:\WINDOWS\system32\drvheg.dll
2007-07-31 17:04 d——– C:\WINDOWS\W?nSxS
2007-07-31 17:02 d——– C:\DOCUME~1\Chase\APPLIC~1\WinRAR
2007-07-31 16:10 125,504 –a—— C:\WINDOWS\system32\vwkmepcp.dll
2007-07-31 16:09 21,504 –a—— C:\WINDOWS\system32\avicap32b.dll
2007-07-31 04:15 114 –ah—– C:\aaw7boot.cmd
2007-07-31 04:06 d——– C:\Program Files\Lavasoft
2007-07-30 19:29 d——– C:\DOCUME~1\Chase\The Sims Online Setup Files
2007-07-30 16:37 125,504 –a—— C:\WINDOWS\system32\tyvvnvct.dll
2007-07-30 15:40 21,504 –a—— C:\WINDOWS\system32\advpackb.dll
2007-07-30 13:31 d——– C:\DOCUME~1\Chase\APPLIC~1\Uniblue
2007-07-30 01:00 d——– C:\DOCUME~1\Chase\APPLIC~1\Talkback
2007-07-30 00:38 d——– C:\DOCUME~1\Internet\APPLIC~1\Talkback
2007-07-30 00:27 d——– C:\DOCUME~1\Internet\APPLIC~1\SiteAdvisor
2007-07-30 00:20 d–h—– C:\DOCUME~1\Internet\APPLIC~1\GTek
2007-07-30 00:18 1,048,576 –ah—– C:\DOCUME~1\Internet\NTUSER.DAT
2007-07-30 00:18 d——– C:\DOCUME~1\Internet\APPLIC~1\Intel
2007-07-29 23:50 d——– C:\DOCUME~1\Chase\APPLIC~1\McAfee
2007-07-29 19:17 d–h—– C:\WINDOWS\system32\WLANProfiles
2007-07-29 19:17 d–h—– C:\Settings
2007-07-26 05:04 d——– C:\Program Files\DAEMON Tools
2007-07-26 05:00 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-07-26 03:32 d——– C:\Program Files\7-Zip
2007-07-24 21:42 d——– C:\WINDOWS\.jagex_cache_32
2007-07-24 16:51 126,016 –a—— C:\WINDOWS\system32\phodxgjy.dll
2007-07-23 16:45 126,016 –a—— C:\WINDOWS\system32\thtykggq.dll
2007-07-23 01:27 21,504 –a—— C:\WINDOWS\system32\bidisplv.dll
2007-07-21 21:28 21,504 –a—— C:\WINDOWS\system32\avifil32s.dll
2007-07-21 07:41 68,608 –a—— C:\WINDOWS\wjejmlav.dll
2007-07-21 07:41 d——– C:\WINDOWS\system32\beglrhsg
2007-07-21 07:41 d——– C:\Program Files\xkvqzghe
2007-07-21 07:41 d——– C:\Program Files\USoft
2007-07-21 07:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
2007-07-20 15:17 21,504 –a—— C:\WINDOWS\system32\audiodevs.dll
2007-07-20 15:17 d——– C:\Program Files\TrustIn Contextual
2007-07-20 02:50 d——– C:\DOCUME~1\yo\APPLIC~1\FreeCap
2007-07-20 02:42 d——– C:\Program Files\SecondLife
2007-07-17 19:05 d——– C:\Program Files\Uniblue
2007-07-17 19:05 d——– C:\DOCUME~1\yo\APPLIC~1\Uniblue
2007-07-15 19:20 d——– C:\Program Files\Hide The IP
2007-07-15 18:35 d——– C:\DOCUME~1\yo\APPLIC~1\Comodo
2007-07-15 18:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-07-14 23:53 d–hs—- C:\WINDOWS\system32\Sys
2007-07-14 23:08 75 –a—— C:\8.vbs
2007-07-14 23:08 74 –a—— C:\10.vbs
2007-07-14 23:08 60 –a—— C:\2.vbs
2007-07-14 23:08 55 –a—— C:\5.vbs
2007-07-14 23:08 55 –a—— C:\1.vbs
2007-07-14 23:08 51 –a—— C:\7.vbs
2007-07-14 23:08 48 –a—— C:\9.vbs
2007-07-14 23:08 48 –a—— C:\4.vbs
2007-07-14 23:08 47 –a—— C:\3.vbs
2007-07-13 03:35 d——– C:\Program Files\ACSPMonitor
2007-07-09 09:48 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2007-07-08 20:37 d——– C:\Program Files\Common Files\aolshare
2007-07-08 20:34 d——– C:\Program Files\Common Files\Stardock
2007-07-08 13:12 d——– C:\Program Files\Common Files\aolback
2007-07-08 12:53 d——– C:\aolextras(2)
2007-07-08 12:32 d——– C:\Program Files\Pure Networks
2007-07-08 03:49 d——– C:\Program Files\Common Files\aolshare(2)
2007-07-08 03:44 4,718,592 –a—— C:\DOCUME~1\yo\ntuser.dat
2007-07-08 01:58 d——– C:\WINDOWS\BricoPacks
2007-07-07 21:47 42,544 –a—— C:\WINDOWS\system32\gotomon.dll
2007-07-07 21:47 d——– C:\Program Files\Citrix
2007-07-07 21:46 3,820,104 –a—— C:\DOCUME~1\yo\gosetup.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-31 12:41 ——— d——– C:\Program Files\Intel
2007-07-31 12:39 ——— d——– C:\DOCUME~1\Chase\APPLIC~1\Intel
2007-07-31 04:04 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-30 21:54 ——— d——– C:\Program Files\Maxis
2007-07-30 16:11 ——— d–h—– C:\DOCUME~1\Chase\APPLIC~1\Gtek
2007-07-30 14:43 ——— d——– C:\Program Files\Corel
2007-07-30 14:43 ——— d——– C:\Program Files\Common Files\Corel
2007-07-30 00:34 ——— d——– C:\Program Files\McAfee
2007-07-29 23:44 7518 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-29 23:44 104 -r-hs—- C:\WINDOWS\system32\EF7BF7DB65.sys
2007-07-17 22:18 ——— d——– C:\Program Files\PCFriendly
2007-07-15 18:57 ——— d——– C:\Program Files\Hide My IP 2007
2007-07-08 20:37 ——— d——– C:\Program Files\Common Files\AOL
2007-07-08 20:36 ——— d——– C:\Program Files\Movie Maker
2007-07-08 20:33 ——— d——– C:\Program Files\2Wire
2007-07-07 21:47 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 23:15 ——— d——– C:\DOCUME~1\Chase\APPLIC~1\AOL
2007-06-23 12:51 ——— d——– C:\Program Files\LimeWire
2007-06-23 12:48 ——— d——– C:\Program Files\pspvideo9
2007-06-23 12:30 ——— d——– C:\Program Files\NoAdware4
2007-06-20 23:03 1156 –a—— C:\WINDOWS\mozver.dat
2007-06-11 11:14 ——— d——– C:\Program Files\Party_Central_Radio
2007-06-04 15:18 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6272 –a—— C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-02 06:26 ——— d——– C:\Program Files\MorpheusBar
2007-05-16 10:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 10:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 10:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 10:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 10:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 10:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-04 07:59 3064320 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-04-15 11:49:08 88 –sh–r C:\WINDOWS\system32\65DBF77BEF.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53B5F2B1-94DD-43E5-8187-EB4E31F00701}]
2007-07-21 07:41 68608 –a—— C:\WINDOWS\wjejmlav.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c0b75d0a-be9e-4637-921f-435d6b079fbc}]
2007-06-03 11:42 1354776 –a—— C:\Program Files\Party_Central_Radio\tbPart.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C0B75D0A-BE9E-4637-921F-435D6B079FBC}"= C:\Program Files\Party_Central_Radio\tbPart.dll [2007-06-03 11:42 1354776]

[HKEY_CLASSES_ROOT\CLSID\{C0B75D0A-BE9E-4637-921F-435D6B079FBC}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-08-02 03:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="" []
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 10:29]
"Uaol"="C:\WINDOWS\WNSXS~1\chkntfs.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{53B5F2B1-94DD-43E5-8187-EB4E31F00701}"= C:\WINDOWS\wjejmlav.dll [2007-07-21 07:41 68608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll 2007-01-12 17:45 10800 C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

R0 Inspect;Comodo Network Engine;C:\WINDOWS\system32\DRIVERS\inspect.sys
R1 APPDRV;APPDRV;C:\WINDOWS\system32\DRIVERS\APPDRV.SYS
R1 CmdMon;Comodo Application Engine;C:\WINDOWS\system32\DRIVERS\cmdmon.sys
R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys
R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
R2 ehRecvr;Media Center Receiver Service;C:\WINDOWS\eHome\ehRecvr.exe
R2 ehSched;Media Center Scheduler Service;C:\WINDOWS\eHome\ehSched.exe
R2 McrdSvc;Media Center Extender Service;C:\WINDOWS\ehome\mcrdsvc.exe
R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys
R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys
R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys
R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys
R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys
R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys
R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys
R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
R3 HSFHWAZL;HSFHWAZL;C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
R3 rimmptsk;rimmptsk;C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
R3 rimsptsk;rimsptsk;C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
R3 rismxdp;Ricoh xD-Picture Card Driver;C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 STHDA;SigmaTel High Definition Audio CODEC;C:\WINDOWS\system32\drivers\sthda.sys
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys
R3 w29n51;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
S3 MHN;MHN;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 MHNDRV;MHN driver;C:\WINDOWS\system32\DRIVERS\mhndrv.sys
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
S4 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-07-20 19:22:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-07-20 23:30:02 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D9KM7Z81-Chase).job - c:\program files\mcafee.com\vso\mcmnhdlr.exe
2007-08-02 08:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe
2007-07-18 03:04:54 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-07-18 02:40:46 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-07-31 22:39:19 C:\WINDOWS\Tasks\Uniblue SpyEraser.job - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 13:36:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-02 13:38:17 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-02 13:37

— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 1:46:28 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINDOWS\wjejmlav.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
O3 - Toolbar: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Uaol] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazb
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\yo\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: GoToMyPC - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToMyPC - Unknown owner - C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
We have a lot of work to do to get this machine clean:

A. Using the Add/Remove Program module in your Control Panel, please UNINSTALL the following "non-recommended" programs:

NoAdware4
Part_Central_Radio
PartyGaming
Morpheus 9Anything with that as part of the name)
Magicantispy
TrustIn Contextual



B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
    O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
    O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINDOWS\wjejmlav.dll
    O2 - BHO: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll
    O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
    O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
    O3 - Toolbar: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKCU\..\Run: [Uaol] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazb
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)



  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Hijackthis_Log_t81837.html&pid=391407#entry391407

Collect::
C:\WINDOWS\system32\natnugfu.dll
C:\8.vbs
C:\10.vbs
C:\2.vbs
C:\5.vbs
C:\1.vbs
C:\7.vbs
C:\9.vbs
C:\4.vbs
C:\3.vbs
C:\WINDOWS\system32\atmfda.dll
C:\WINDOWS\system32\meamkhvj.dll
C:\WINDOWS\system32\avicap32b.dll
C:\WINDOWS\system32\bidisplv.dll
C:\WINDOWS\system32\avifil32s.dll

File::
C:\WINDOWS\wjejmlav.dll
C:\WINDOWS\system32\tpqkmrjs.dll
C:\WINDOWS\system32\meamkhvj.dll
C:\WINDOWS\system32\Sys
C:\WINDOWS\system32\EF7BF7DB65.sys
C:\Program Files\codec_setup.exe
C:\WINDOWS\system32\65DBF77BEF.sys
C:\WINDOWS\system32\drvheg.dll
C:\WINDOWS\system32\vwkmepcp.dll
C:\WINDOWS\system32\tyvvnvct.dll
C:\WINDOWS\system32\advpackb.dll
C:\WINDOWS\system32\phodxgjy.dll
C:\WINDOWS\system32\audiodevs.dll
C:\WINDOWS\system32\thtykggq.dll

Folder::
C:\Program Files\NoAdware4
C:\Program Files\Party_Central_Radio
C:\Program Files\MorpheusBar
C:\Program Files\PartyGaming
C:\Program Files\Magicantispy
C:\Program Files\TrustIn Contextual
C:\WINDOWS\system32\beglrhsg
C:\Program Files\xkvqzghe
C:\WINDOWS\WNSXS~1

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

9. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, you may DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

We have a lot of work to do to get this machine clean:

A. Using the Add/Remove Program module in your Control Panel, please UNINSTALL the following "non-recommended" programs:

NoAdware4
**Part_Central_Radio**
PartyGaming
**Morpheus 9Anything with that as part of the name)**
Magicantispy
TrustIn Contextual


Only the things with ** before and after them were on the Add/Remove Program List.

[*]Place a check mark beside each one of the following items:


R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL (Couldn't Find Exact Match)
O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL(Couldn't Find Match)
O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINDOWS\wjejmlav.dll (Found, Checked)
O2 - BHO: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll (Couldn't Find Match)
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL(Couldn't Find Match)
O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL (Couldn't Find Match)
O3 - Toolbar: Party_Central_Radio toolbar - {c0b75d0a-be9e-4637-921f-435d6b079fbc} - C:\Program Files\Party_Central_Radio\tbPart.dll (Couldn't Find Match)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) (Found, Checked)
O4 - HKCU\..\Run: [Uaol] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazb (Found, Checked)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) (Found, Checked)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
(Couldn't Find Exact Match)

ComboFix Log

ComboFix 07-08-02.3 - "Chase" 2007-08-02 15:26:12.3 [GMT -5:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\Chase\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((( Files Created from 2007-07-02 to 2007-08-02 )))))))))))))))))))))))))))))))


2007-08-02 15:06 237,568 –a—— C:\Program Files\Uninstall Morpheus Toolbar.dll
2007-08-02 13:10 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 03:31 125,504 –a—— C:\WINDOWS\system32\natnugfu.dll
2007-08-02 03:25 d——– C:\DOCUME~1\Chase\APPLIC~1\Comodo
2007-08-02 03:21 d——– C:\Program Files\Comodo
2007-08-01 16:09 21,504 –a—— C:\WINDOWS\system32\atmfda.dll
2007-08-01 15:42 d——– C:\Program Files\Magicantispy
2007-08-01 01:52 dr-h—– C:\DOCUME~1\Chase\APPLIC~1\yahoo!
2007-07-31 23:45 d——– C:\Program Files\Trend Micro
2007-07-31 18:29 125,504 –a—— C:\WINDOWS\system32\meamkhvj.dll
2007-07-31 17:53 125,504 –a—— C:\WINDOWS\system32\tpqkmrjs.dll
2007-07-31 17:09 d——– C:\Program Files\Image ActiveX Access
2007-07-31 17:06 70,312 –a—— C:\Program Files\codec_setup.exe
2007-07-31 17:04 93,696 –a—— C:\WINDOWS\system32\drvheg.dll
2007-07-31 17:04 d——– C:\WINDOWS\W?nSxS
2007-07-31 17:02 d——– C:\DOCUME~1\Chase\APPLIC~1\WinRAR
2007-07-31 16:10 125,504 –a—— C:\WINDOWS\system32\vwkmepcp.dll
2007-07-31 16:09 21,504 –a—— C:\WINDOWS\system32\avicap32b.dll
2007-07-31 04:15 114 –ah—– C:\aaw7boot.cmd
2007-07-31 04:06 d——– C:\Program Files\Lavasoft
2007-07-30 19:29 d——– C:\DOCUME~1\Chase\The Sims Online Setup Files
2007-07-30 16:37 125,504 –a—— C:\WINDOWS\system32\tyvvnvct.dll
2007-07-30 15:40 21,504 –a—— C:\WINDOWS\system32\advpackb.dll
2007-07-30 13:31 d——– C:\DOCUME~1\Chase\APPLIC~1\Uniblue
2007-07-30 01:00 d——– C:\DOCUME~1\Chase\APPLIC~1\Talkback
2007-07-30 00:38 d——– C:\DOCUME~1\Internet\APPLIC~1\Talkback
2007-07-30 00:27 d——– C:\DOCUME~1\Internet\APPLIC~1\SiteAdvisor
2007-07-30 00:20 d–h—– C:\DOCUME~1\Internet\APPLIC~1\GTek
2007-07-30 00:18 1,048,576 –ah—– C:\DOCUME~1\Internet\NTUSER.DAT
2007-07-30 00:18 d——– C:\DOCUME~1\Internet\APPLIC~1\Intel
2007-07-29 23:50 d——– C:\DOCUME~1\Chase\APPLIC~1\McAfee
2007-07-29 19:17 d–h—– C:\WINDOWS\system32\WLANProfiles
2007-07-29 19:17 d–h—– C:\Settings
2007-07-26 05:04 d——– C:\Program Files\DAEMON Tools
2007-07-26 05:00 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-07-26 03:32 d——– C:\Program Files\7-Zip
2007-07-24 21:42 d——– C:\WINDOWS\.jagex_cache_32
2007-07-24 16:51 126,016 –a—— C:\WINDOWS\system32\phodxgjy.dll
2007-07-23 16:45 126,016 –a—— C:\WINDOWS\system32\thtykggq.dll
2007-07-23 01:27 21,504 –a—— C:\WINDOWS\system32\bidisplv.dll
2007-07-21 21:28 21,504 –a—— C:\WINDOWS\system32\avifil32s.dll
2007-07-21 07:41 68,608 –a—— C:\WINDOWS\wjejmlav.dll
2007-07-21 07:41 d——– C:\WINDOWS\system32\beglrhsg
2007-07-21 07:41 d——– C:\Program Files\xkvqzghe
2007-07-21 07:41 d——– C:\Program Files\USoft
2007-07-21 07:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
2007-07-20 15:17 21,504 –a—— C:\WINDOWS\system32\audiodevs.dll
2007-07-20 15:17 d——– C:\Program Files\TrustIn Contextual
2007-07-20 02:50 d——– C:\DOCUME~1\yo\APPLIC~1\FreeCap
2007-07-20 02:42 d——– C:\Program Files\SecondLife
2007-07-17 19:05 d——– C:\Program Files\Uniblue
2007-07-17 19:05 d——– C:\DOCUME~1\yo\APPLIC~1\Uniblue
2007-07-15 19:20 d——– C:\Program Files\Hide The IP
2007-07-15 18:35 d——– C:\DOCUME~1\yo\APPLIC~1\Comodo
2007-07-15 18:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-07-14 23:53 d–hs—- C:\WINDOWS\system32\Sys
2007-07-14 23:08 75 –a—— C:\8.vbs
2007-07-14 23:08 74 –a—— C:\10.vbs
2007-07-14 23:08 60 –a—— C:\2.vbs
2007-07-14 23:08 55 –a—— C:\5.vbs
2007-07-14 23:08 55 –a—— C:\1.vbs
2007-07-14 23:08 51 –a—— C:\7.vbs
2007-07-14 23:08 48 –a—— C:\9.vbs
2007-07-14 23:08 48 –a—— C:\4.vbs
2007-07-14 23:08 47 –a—— C:\3.vbs
2007-07-13 03:35 d——– C:\Program Files\ACSPMonitor
2007-07-09 09:48 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2007-07-08 20:37 d——– C:\Program Files\Common Files\aolshare
2007-07-08 20:34 d——– C:\Program Files\Common Files\Stardock
2007-07-08 13:12 d——– C:\Program Files\Common Files\aolback
2007-07-08 12:53 d——– C:\aolextras(2)
2007-07-08 12:32 d——– C:\Program Files\Pure Networks
2007-07-08 03:49 d——– C:\Program Files\Common Files\aolshare(2)
2007-07-08 03:44 4,718,592 –a—— C:\DOCUME~1\yo\ntuser.dat
2007-07-08 01:58 d——– C:\WINDOWS\BricoPacks
2007-07-07 21:47 42,544 –a—— C:\WINDOWS\system32\gotomon.dll
2007-07-07 21:47 d——– C:\Program Files\Citrix
2007-07-07 21:46 3,820,104 –a—— C:\DOCUME~1\yo\gosetup.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-31 12:41 ——— d——– C:\Program Files\Intel
2007-07-31 12:39 ——— d——– C:\DOCUME~1\Chase\APPLIC~1\Intel
2007-07-31 04:04 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-30 21:54 ——— d——– C:\Program Files\Maxis
2007-07-30 16:11 ——— d–h—– C:\DOCUME~1\Chase\APPLIC~1\Gtek
2007-07-30 14:43 ——— d——– C:\Program Files\Corel
2007-07-30 14:43 ——— d——– C:\Program Files\Common Files\Corel
2007-07-30 00:34 ——— d——– C:\Program Files\McAfee
2007-07-29 23:44 7518 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-29 23:44 104 -r-hs—- C:\WINDOWS\system32\EF7BF7DB65.sys
2007-07-17 22:18 ——— d——– C:\Program Files\PCFriendly
2007-07-15 18:57 ——— d——– C:\Program Files\Hide My IP 2007
2007-07-08 20:37 ——— d——– C:\Program Files\Common Files\AOL
2007-07-08 20:36 ——— d——– C:\Program Files\Movie Maker
2007-07-08 20:33 ——— d——– C:\Program Files\2Wire
2007-07-07 21:47 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 23:15 ——— d——– C:\DOCUME~1\Chase\APPLIC~1\AOL
2007-06-23 12:51 ——— d——– C:\Program Files\LimeWire
2007-06-23 12:48 ——— d——– C:\Program Files\pspvideo9
2007-06-23 12:30 ——— d——– C:\Program Files\NoAdware4
2007-06-20 23:03 1156 –a—— C:\WINDOWS\mozver.dat
2007-06-04 15:18 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6272 –a—— C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-02 06:26 ——— d——– C:\Program Files\MorpheusBar
2007-05-16 10:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 10:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 10:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 10:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 10:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 10:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-04 07:59 3064320 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-04-15 11:49:08 88 –sh–r C:\WINDOWS\system32\65DBF77BEF.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-08-02 03:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="" []
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 10:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"MorpheusToolbar Uninstall"=rundll32 C:\PROGRA~1\UNINST~1.DLL,O -2

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll 2007-01-12 17:45 10800 C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

R0 Inspect;Comodo Network Engine;C:\WINDOWS\system32\DRIVERS\inspect.sys
R1 APPDRV;APPDRV;C:\WINDOWS\system32\DRIVERS\APPDRV.SYS
R1 CmdMon;Comodo Application Engine;C:\WINDOWS\system32\DRIVERS\cmdmon.sys
R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys
R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys
R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys
R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
R2 ehRecvr;Media Center Receiver Service;C:\WINDOWS\eHome\ehRecvr.exe
R2 ehSched;Media Center Scheduler Service;C:\WINDOWS\eHome\ehSched.exe
R2 McrdSvc;Media Center Extender Service;C:\WINDOWS\ehome\mcrdsvc.exe
R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys
R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys
R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys
R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys
R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys
R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys
R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys
R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys
R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
R3 HSFHWAZL;HSFHWAZL;C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
R3 rimmptsk;rimmptsk;C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
R3 rimsptsk;rimsptsk;C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
R3 rismxdp;Ricoh xD-Picture Card Driver;C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 STHDA;SigmaTel High Definition Audio CODEC;C:\WINDOWS\system32\drivers\sthda.sys
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys
R3 w29n51;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
S3 MHN;MHN;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 MHNDRV;MHN driver;C:\WINDOWS\system32\DRIVERS\mhndrv.sys
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
S4 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-07-20 19:22:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-07-20 23:30:02 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D9KM7Z81-Chase).job - c:\program files\mcafee.com\vso\mcmnhdlr.exe
2007-08-02 08:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe
2007-07-18 03:04:54 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-07-18 02:40:46 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-07-31 22:39:19 C:\WINDOWS\Tasks\Uniblue SpyEraser.job - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 15:29:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000006f9

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-02 15:30:10
C:\ComboFix-quarantined-files.txt … 2007-08-02 15:29
C:\ComboFix2.txt … 2007-08-02 13:38

— E O F —
HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 3:34:44 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\RunOnce: [MorpheusToolbar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -2
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\yo\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\hide my ip 2007\proxyfilter.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: GoToMyPC - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToMyPC - Unknown owner - C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI