This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Msn Messenger And Other Problems

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can you give me a new combofix scan?
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
ComboFix 07-08-09.3 - "Administrator" 2007-08-11 17:48:56.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.251 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-09 19:31 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-07 12:30 d——– C:\Program Files\Norton 360
2007-08-07 12:28 48,776 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-08-07 12:28 115,000 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-08-04 20:07 d——– C:\Program Files\MSN Messenger


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 21:48 288 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-08-10 21:48 288 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-08-10 21:31 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-08-07 12:34 806 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-08-07 12:34 8014 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-08-07 12:34 ——— d——– C:\Program Files\Symantec
2007-08-05 09:44 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Yahoo! Messenger
2007-08-04 20:08 ——— d——– C:\Program Files\MSN Toolbar
2007-07-21 22:58 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Canon
2007-07-17 12:21 186256 –a—— C:\WINDOWS\system32\SymNPPWA.dll
2007-07-10 19:26 ——— d——– C:\Program Files\FLVPlayer
2007-07-03 17:21 ——— d——– C:\Program Files\Roni Music
2007-06-30 20:18 58952 –a—— C:\WINDOWS\system32\MsgPlusLoader.dll
2007-06-30 20:18 ——— d——– C:\Program Files\MessengerPlus! 3
2007-06-26 16:42 ——— d——– C:\Program Files\Winamp
2007-06-23 23:07 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Aim
2007-06-23 16:06 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 16:06 ——— d——– C:\Program Files\PC Inspector File Recovery
2007-06-22 17:23 ——— d——– C:\Program Files\FILE RECOVERY for Windows
2007-06-22 13:47 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\VERITAS
2007-06-22 08:19 ——— d——– C:\Program Files\MSXML 6.0
2007-06-21 18:35 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Tenebril
2007-06-20 20:20 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-06-19 16:52 ——— d——– C:\Program Files\Washer
2007-06-19 16:21 ——— d——– C:\Program Files\Messenger
2007-06-17 17:01 ——— d——– C:\Program Files\Windows NT
2007-06-17 17:01 ——— d——– C:\Program Files\Movie Maker
2007-06-17 11:20 ——— d——– C:\Program Files\Hewlett-Packard
2007-06-17 10:29 4464 -rahs—- C:\WINDOWS\system32\drivers\HP_DB287A-ABA 864N_YC_Pavi_QMX3043_E31NAfsEPC4_4_IMS-6577_SMICRO-STAR INTERNATIONAL CO., LTD_V020_B3.10_T030109_WXP1_L409_M512_J164_7Intel_8Pentium 4_92.67_1103300F2_N10EC8139_P_Z11C1044E_K_A11020004_U808624C2_G10DE0171_O.MRK
2007-06-17 08:45 ——— d——– C:\Program Files\Creative
2007-05-16 11:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll
2004-08-29 13:34 5245352 –a–c— C:\Program Files\SetupDl.exe
1998-08-24 13:09 10000 –a—— C:\WINDOWS\inf\unregpn.exe
2003-12-02 01:06:04 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 11:05]
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" [2002-10-25 19:33]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 01:42]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-06-14 19:39]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2006-08-11 12:15]
"MaxtorOneTouch"="C:\Program Files\Maxtor\ManagerApp\Onetouch.exe" [2006-08-11 09:45]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"ProxyFirewall"="C:\Program Files\ProxyFirewall\ProxyFirewall.exe" []
"AOL Fast Start"="C:\Program Files\America Online 9.0f\AOL.exe" [2005-07-12 01:17]
"iClean"="C:\Program Files\Aladdin Systems\iClean\iclean.exe" [2003-06-19 20:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservicesonce]
"washindex"=C:\Program Files\Washer\washidx.exe "Administrator"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"PlayCenter2"="C:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.EXE" "C:\Program Files\Creative\SBAudigy\PlayCenter2"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=interceptor.dll,msgplusloader.dll

R3 EvcapMaui;Emuzed EvcapMaui Device;C:\WINDOWS\system32\DRIVERS\EvcapMau.sys
R3 ltmodem5;Agere Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
R3 Ps2;PS2;C:\WINDOWS\system32\DRIVERS\PS2.sys
R3 SRTSP;SRTSP;C:\WINDOWS\system32\Drivers\SRTSP.SYS
S3 MXOPSWD;Maxtor OneTouch Security Driver;C:\WINDOWS\system32\DRIVERS\mxopswd.sys
S3 SRTSPL;SRTSPL;C:\WINDOWS\system32\Drivers\SRTSPL.SYS

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-06-09 13:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 18:50:02
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwQuerySystemInformation

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

C:\WINDOWS\bwUnin-6.1.0.170.exe

scan completed successfully
hidden files: 1

**************************************************************************

Completion time: 2007-08-11 18:58:17
C:\ComboFix-quarantined-files.txt … 2007-08-11 18:58
C:\ComboFix2.txt … 2007-08-10 17:20

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 7:00:29 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\Utils\SyncServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\ComboFix\vfind.cfexe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://maxtor.custhelp.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar1.01.2607.0\en-us\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Administrator"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ProxyFirewall] C:\Program Files\ProxyFirewall\ProxyFirewall.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O4 - HKCU\..\Run: [iClean] "C:\Program Files\Aladdin Systems\iClean\iclean.exe" /I
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182209990421
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182209904265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll,msgplusloader.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Program Files\ProxyFirewall\ProxyFirewall.exe

Folder::
C:\Program Files\ProxyFirewall

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProxyFirewall"=-


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
ComboFix 07-08-09.3 - "Administrator" 2007-08-11 19:34:15.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.212 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\Program Files\ProxyFirewall\ProxyFirewall.exe


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-09 19:31 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-07 12:30 d——– C:\Program Files\Norton 360
2007-08-07 12:28 48,776 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-08-07 12:28 115,000 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-08-04 20:07 d——– C:\Program Files\MSN Messenger


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 21:48 288 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-08-10 21:48 288 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-08-10 21:31 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-08-07 12:34 806 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-08-07 12:34 8014 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-08-07 12:34 ——— d——– C:\Program Files\Symantec
2007-08-05 09:44 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Yahoo! Messenger
2007-08-04 20:08 ——— d——– C:\Program Files\MSN Toolbar
2007-07-21 22:58 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Canon
2007-07-17 12:21 186256 –a—— C:\WINDOWS\system32\SymNPPWA.dll
2007-07-10 19:26 ——— d——– C:\Program Files\FLVPlayer
2007-07-03 17:21 ——— d——– C:\Program Files\Roni Music
2007-06-30 20:18 58952 –a—— C:\WINDOWS\system32\MsgPlusLoader.dll
2007-06-30 20:18 ——— d——– C:\Program Files\MessengerPlus! 3
2007-06-26 16:42 ——— d——– C:\Program Files\Winamp
2007-06-23 23:07 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Aim
2007-06-23 16:06 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 16:06 ——— d——– C:\Program Files\PC Inspector File Recovery
2007-06-22 17:23 ——— d——– C:\Program Files\FILE RECOVERY for Windows
2007-06-22 13:47 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\VERITAS
2007-06-22 08:19 ——— d——– C:\Program Files\MSXML 6.0
2007-06-21 18:35 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Tenebril
2007-06-20 20:20 ——— d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-06-19 16:52 ——— d——– C:\Program Files\Washer
2007-06-19 16:21 ——— d——– C:\Program Files\Messenger
2007-06-17 17:01 ——— d——– C:\Program Files\Windows NT
2007-06-17 17:01 ——— d——– C:\Program Files\Movie Maker
2007-06-17 11:20 ——— d——– C:\Program Files\Hewlett-Packard
2007-06-17 10:29 4464 -rahs—- C:\WINDOWS\system32\drivers\HP_DB287A-ABA 864N_YC_Pavi_QMX3043_E31NAfsEPC4_4_IMS-6577_SMICRO-STAR INTERNATIONAL CO., LTD_V020_B3.10_T030109_WXP1_L409_M512_J164_7Intel_8Pentium 4_92.67_1103300F2_N10EC8139_P_Z11C1044E_K_A11020004_U808624C2_G10DE0171_O.MRK
2007-06-17 08:45 ——— d——– C:\Program Files\Creative
2007-05-16 11:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll
2004-08-29 13:34 5245352 –a–c— C:\Program Files\SetupDl.exe
1998-08-24 13:09 10000 –a—— C:\WINDOWS\inf\unregpn.exe
2003-12-02 01:06:04 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 11:05]
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" [2002-10-25 19:33]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 01:42]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-06-14 19:39]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2006-08-11 12:15]
"MaxtorOneTouch"="C:\Program Files\Maxtor\ManagerApp\Onetouch.exe" [2006-08-11 09:45]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"AOL Fast Start"="C:\Program Files\America Online 9.0f\AOL.exe" [2005-07-12 01:17]
"iClean"="C:\Program Files\Aladdin Systems\iClean\iclean.exe" [2003-06-19 20:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservicesonce]
"washindex"=C:\Program Files\Washer\washidx.exe "Administrator"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"PlayCenter2"="C:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.EXE" "C:\Program Files\Creative\SBAudigy\PlayCenter2"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=interceptor.dll,msgplusloader.dll

R3 EvcapMaui;Emuzed EvcapMaui Device;C:\WINDOWS\system32\DRIVERS\EvcapMau.sys
R3 ltmodem5;Agere Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
R3 Ps2;PS2;C:\WINDOWS\system32\DRIVERS\PS2.sys
R3 SRTSP;SRTSP;C:\WINDOWS\system32\Drivers\SRTSP.SYS
S3 MXOPSWD;Maxtor OneTouch Security Driver;C:\WINDOWS\system32\DRIVERS\mxopswd.sys
S3 SRTSPL;SRTSPL;C:\WINDOWS\system32\Drivers\SRTSPL.SYS

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-06-09 13:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 20:41:04
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwQuerySystemInformation

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

C:\WINDOWS\bwUnin-6.1.0.170.exe

scan completed successfully
hidden files: 1

**************************************************************************

Completion time: 2007-08-11 20:50:17
C:\ComboFix-quarantined-files.txt … 2007-08-11 20:49
C:\ComboFix2.txt … 2007-08-11 18:58
C:\ComboFix3.txt … 2007-08-10 17:20

— E O F —
My computer is a little slower rebooting and msn messenger still says my gateway is offline. Other than that it seems OK.

Logfile of HijackThis v1.99.1
Scan saved at 9:27:34 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\Utils\SyncServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0f\waol.exe
C:\Program Files\Aladdin Systems\iClean\iclean.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0f\shellmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://maxtor.custhelp.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar1.01.2607.0\en-us\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Administrator"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O4 - HKCU\..\Run: [iClean] "C:\Program Files\Aladdin Systems\iClean\iclean.exe" /I
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182209990421
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182209904265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll,msgplusloader.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Do you have a router? Have you tried resetting it? Also try this: Click Start> Run> type in CMD tap enter key Copy/Paste: ipconfig /flushdns If you are typing this in, note the space between the g /f It needs to be there. Now lets check some settings on your system. Enter your Control Panel and double-click on Network Connections Then right click on your Default Connection Usually Local Area Connection for Cable and DSL Left click on Properties Double-Click on the Internet Protocol (TCP/IP) item Select the radio dial that says Obtain DNS Servers Automatically Note: Do this for all Network Connections Press OK twice to get out of the properties screen and reboot if it asks
I don't have a router. I did both things you said. I am on dialup. Under TCP/IP properties 2 boxes were and still are checked, Obtain an IP address automatically and Obtain DNS server address automatically. On the GENERAL tab of internet properties, under "connect using" the box is checked next to "Removed WAN miniport(ATW)(IRDA12-0) and there is a red X between the checked box and the word Removed. Also there is a 1394 Connection that is connected. Should I look for something in there? I did reboot and msn messenger still says gateway offline
I don't know what else to try. I suggest you go over to our Other Computer Problems and post a topic there explaining the issues you're having.

Also let them know your HijackThis log has been cleaned.

http://forums.tomcoyote.org/Other_Computer_Problems_f83.html

Do this first:

You can remove any programs / Tools I had you install. Use Add/Remove Programs to remove if listed there otherwise just delete them and empty recycle bin.

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.



Only run one Anti-Virus and Firewall program.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware


Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI