This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Hijack This Log

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Tom and other volunteers,
Thank you for your invaluable website that helped me remove numerous problems from my daughter's computer. Unfortunately, it is still not running right, probably due to me deleting some files before I found your website. I had Smit Fraud, Keylogger, and numerous other issues previously. Unbeknownst to me, my daughter was downloading stuff without updated virus software. I ran all programs recommended before posting this log. Any advice is greatly appreciated.
Thanks,
Lori
:wavey:

Logfile of HijackThis v1.99.1
Scan saved at 4:06:42 PM, on 8/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec

Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec

Shared\ccProxy.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec

Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) -

{1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program

Files\Common Files\Symantec

Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) -

{2C65A069-5204-40A0-BE11-6D18FF5E3B54} - (no file)
O2 - BHO: (no name) -

{3E155C1A-176A-447C-8BDD-4F1F0EB42EBC} -

C:\WINDOWS\system32\ddabb.dll (disabled by BHODemon)
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-206D7942484F} - C:\Program

Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) -

{639BC63C-1F26-43C0-B160-914078103B91} - (no file)
O2 - BHO: (no name) -

{904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4} - (no file)
O2 - BHO: (no name) -

{93EF16B6-4E80-478B-8CC1-8E758B00256D} - (no file)
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll (disabled by BHODemon)
O2 - BHO: (no name) -

{BC08C629-5C96-4EF2-904C-B41F5044F587} - (no file)
O2 - BHO: (no name) -

{BE47878A-1D30-460C-8FC3-4249B9FA935A} - (no file)
O2 - BHO: (no name) -

{E0B17033-4510-4DEE-B49D-4816A387C2D0} - (no file)
O2 - BHO: (no name) -

{EFCB6030-B343-4836-97F0-9319A3178101} - (no file)
O2 - BHO: (no name) -

{F6143B57-425B-432B-9BF6-802D0A81C63A} - (no file)
O3 - Toolbar: (no name) -

{DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Show Norton Toolbar -

{90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program

Files\Common Files\Symantec

Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft

IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program

Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common

Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton

Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program

Files\Common Files\Symantec

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc

.exe" /a /m "C:\Program Files\Common Files\Symantec

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertE

ng.dll"
O4 - HKLM\..\Run: [SoundService] rundll32.exe

"C:\WINDOWS\system32\nlkwmvrm.dll",setvm
O4 - HKLM\..\Run: [UserFaultCheck]

%systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection]

C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [HijackThis startup scan]

C:\DOCUME~1\WebSites\LOCALS~1\Temp\Temporary Directory 2

for hijackthis[1].zip\HijackThis.exe /startupscan
O9 - Extra button: AOL Toolbar -

{3369AF0D-62E9-4bda-8103-B4C75499B578} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ -

{6224f700-cba3-4071-b251-47cb894244cd} - C:\Program

Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ -

{6224f700-cba3-4071-b251-47cb894244cd} - C:\Program

Files\ICQ\ICQ.exe
O9 - Extra button: (no name) -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF:

START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}

(Snapfish Activia) -

http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1}

(FujifilmUploader Class) -

http://www.samsphotoclub.com/upload/FujifilmUploadClient

.cab
O20 - Winlogon Notify: ddabb - C:\WINDOWS\
O20 - Winlogon Notify: gebya - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui -

C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkhhi - C:\WINDOWS\
O20 - Winlogon Notify: jkkjk - C:\WINDOWS\
O20 - Winlogon Notify: mljhghf - mljhghf.dll (file

missing)
O20 - Winlogon Notify: pmkjj -

C:\WINDOWS\system32\pmkjj.dll (file missing)
O20 - Winlogon Notify: urqroml - urqroml.dll (file

missing)
O20 - Winlogon Notify: WgaLogon -

C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj -

{AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) -

Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware

2007\aawservice.exe
O23 - Service: Access Task Manager - Unknown owner -

C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec

Corporation - C:\Program

Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. -

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) -

Unknown owner - C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) -

Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) -

Unknown owner - C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service

(CLTNetCnService) - Unknown owner - C:\Program

Files\Common Files\Symantec Shared\ccSvcHst.exe" /h

cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation

- C:\Program Files\Common Files\Symantec

Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. -

C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation

(ISPwdSvc) - Symantec Corporation - C:\Program

Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark

International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation -

C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate

Notice Ex) - Unknown owner - C:\Program Files\Common

Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file

missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner

- C:\Program Files\Common Files\Symantec

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc

.exe" /m "C:\Program Files\Common Files\Symantec

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng

.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation -

C:\Program Files\Common Files\Sony

Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation -

C:\Program Files\Common Files\Sony

Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony

Corporation - C:\Program Files\Common Files\Sony

Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation -

C:\Program Files\Common Files\Symantec

Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) -

Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Virtual Audio Adapter (VAPSV) - Unknown

owner - C:\WINDOWS\system32\vapsvc.exe (file missing)
LoriGiz,

Welcome to the forum, sorry for the delay. Your HJT log is hard to read the way you posted it, when it opens in Notepad, go to Format and uncheck Wordwrap.


C:\Program Files\Hijackthis\HijackThis.exe <–Go here and right click on the HJT Icon, (looks like a red stick of dynamite with a plunger) and rename it to Scanner.exe. <– Don't forget the .exe

Run both these tools.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall




Download VundoFix to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.


I need to see the Combofix log, the Vundo Report and a New HJT log with it renamed please
Dear Ken,

Thanks for your reply. sorry about wordwrap, I unchecked box. Also- I sent note to forum "I didn't get a reply in 5 days" by mistake (I thought it was August 21st and it was only August 18th- I am so busy I was three days ahead of myself.

Also, I want to let you know that Microsoft picked up this forum as a possible phishing site. Link below for response:

https://phishingfilter.microsoft.com/feedba…Giz_m72203.html

I am concerned that you may not be able to get the whole picture since I worked on this problem myself for over a month running various scanners before I got to this point. After reading this forum I now realize how complicated the actual fix is, and I probably needed to do a lot more than I did.

Just to let you I also had Winfix,and win32(major popups), and can't remember rest, but we had major problems. There was a boy in my daughters school that was caught spying on teachers computers, and I believe that her computer was infected after clicking a link from an AIM message that circulated around the school. She was also downloading from Limewire even though she was instructed not to. She was also downloading from individual sites to learn about web graphics, and HTML code. My biggest concern is that someone has personal info out there.

Anyway thanks again for your volunteer time. You guys are great. :thumbup:

**************************************************************

Ok. I did as you suggested:

Renamed Hijack this to scanner.exe and ran

Ran combofix

Ran Vundo - I had previously run and was infected and fixed, however I ran again anyway.

Had to re-run everything after I noticed that my rename of scanner.exe did not change( I must have forgotten to hit apply). I sent both copies - sorry, Hope it's not too confusing.

Ran Hijackthis

logs in order below:


****************************************************
ComboFix 07-08-14.4 - "WebSites" 2007-08-19 20:34:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.54 [GMT -4:00]
* Created a new restore point

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\WebSites\APPLIC~1.\macromedia\Flash Player\#SharedObjects\58SJE6CN\www.broadcaster.com
C:\DOCUME~1\WebSites\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\WebSites\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Program Files\vsadd-in


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\nm


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-19 20:29 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-15 22:38 d——– C:\Program Files\MSXML 6.0
2007-07-31 08:17 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-30 23:24 d——– C:\Program Files\AIM Spyware Remover
2007-07-30 23:16 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-27 20:34 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-27 20:34 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-27 20:34 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-07-27 20:34 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-19 18:16 81,332 –a—— C:\WINDOWS\system32\Bass.Dll
2007-07-19 18:16 733,184 –a—— C:\WINDOWS\system32\NCTAudioLibrary2.dll
2007-07-19 18:16 315,392 –a—— C:\WINDOWS\system32\NCTAudioPlayer2.dll
2007-07-19 18:16 307,200 –a—— C:\WINDOWS\system32\NCTAudioRecord2.dll
2007-07-19 18:16 237,568 –a—— C:\WINDOWS\system32\lame_enc.dll
2007-07-19 18:16 196,608 –a—— C:\WINDOWS\system32\NCTWMAFile2.dll
2007-07-19 18:16 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-07-19 18:16 1,839,104 –a—— C:\WINDOWS\system32\NCTAudioFile2.dll
2007-07-19 18:16 1,662,976 –a—— C:\WINDOWS\system32\NCTAudioCompress2.dll
2007-07-19 18:16 d——– C:\Program Files\SoftwareClub.ws


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 17:42 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-07-30 23:42 ——— d——– C:\Program Files\Lavasoft
2007-07-30 23:35 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-23 09:32 ——— d——– C:\Program Files\Common Files\AOL
2007-07-22 09:13 ——— d——– C:\Program Files\Image-Line
2007-07-20 15:13 ——— d——– C:\Program Files\Windows Movie Maker 2
2007-07-19 02:59 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-12 19:31 765952 –a–c— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 10:34 823808 –a–c— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 10:34 671232 –a–c— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 10:34 6058496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 10:34 52224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 10:34 477696 –a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 10:34 459264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 10:34 44544 —–c— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 10:34 384512 —–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 10:34 383488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 10:34 27648 –a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 10:34 267776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 10:34 232960 –a–c— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 10:34 230400 —–c— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 10:34 193024 –a–c— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 10:34 153088 —–c— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 10:34 132608 –a–c— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 10:34 124928 —–c— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:34 1152000 –a–c— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 10:34 105984 –a–c— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 10:34 102400 –a–c— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 04:27 63488 —–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 04:27 625152 –a–c— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 04:27 13824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 03:00 161792 —–c— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 02:08 1104896 –a–c— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 17:14 864 –ahs—- C:\zjmjaeh0.sys
2007-06-23 16:41 ——— d——– C:\Program Files\MtStudio
2007-06-19 09:31 282112 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a–c— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 –a–c— C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-07 10:06 3798528 –a—— C:\Program Files\SymADataWeb.msi
2006-12-18 20:58 796332 –a—— C:\Program Files\flashcreate!.exe
2006-12-18 17:48 1771096 –a—— C:\Program Files\MP3-Audio-Mixer.exe
2006-11-29 20:55 474 –a—— C:\Program Files\Shortcut to mstudioZ.lnk
2006-11-29 20:44 646 –a—— C:\Program Files\Video DVD Maker (2).lnk
2006-11-29 20:44 499 –a—— C:\Program Files\DivXInstaller.lnk
2006-11-21 18:55 15926792 –a—— C:\Program Files\DivXInstaller.exe
2006-11-21 16:36 897 –a—— C:\Program Files\Google Video Player.lnk
2006-10-14 16:59 4322816 –a—— C:\Program Files\mstudioZ.exe
2007-03-14 03:26:57 43 –sha-w C:\WINDOWS\temp\removalfile.bat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C65A069-5204-40A0-BE11-6D18FF5E3B54}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E155C1A-176A-447C-8BDD-4F1F0EB42EBC}]
C:\WINDOWS\system32\ddabb.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{639BC63C-1F26-43C0-B160-914078103B91}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{93EF16B6-4E80-478B-8CC1-8E758B00256D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BC08C629-5C96-4EF2-904C-B41F5044F587}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE47878A-1D30-460C-8FC3-4249B9FA935A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0B17033-4510-4DEE-B49D-4816A387C2D0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFCB6030-B343-4836-97F0-9319A3178101}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F6143B57-425B-432B-9BF6-802D0A81C63A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 04:51]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 04:50]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-03-14 23:10]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 03:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddabb]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebya]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhi]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjk]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhghf]
mljhghf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjj]
C:\WINDOWS\system32\pmkjj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqroml]
urqroml.dll

R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S2 Access Task Manager;Access Task Manager;"C:\WINDOWS\system32\spoolcs.exe"
S2 VAPSV;Virtual Audio Adapter;"C:\WINDOWS\system32\vapsvc.exe"
S3 LMImirr;LMImirr;C:\WINDOWS\system32\DRIVERS\LMImirr.sys
S3 STVqx3;Intel Play QX3 Microscope;C:\WINDOWS\system32\drivers\STVqx3.sys

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-04-05 16:04:17 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
2007-08-20 00:45:20 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - WebSites.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net">http://www.gm…://www.gmer.net
Rootkit scan 2007-08-19 20:44:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 20:50:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-19 20:50

— E O F —
******************************************RAN VUNDO TWICE WITH SAME RESULT

VundoFix V6.5.7

Checking Java version…

Java version is 1.5.0.8
Old versions of java are exploitable and should be removed.

Scan started at 9:09:25 PM 8/19/2007

Listing files found while scanning….

No infected files were found.

*****************************************

Logfile of HijackThis v1.99.1
Scan saved at 10:21:16 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spider.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Hijackthis\SCANNER.EXE.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=691…k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=548…k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=548…k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {2C65A069-5204-40A0-BE11-6D18FF5E3B54} - (no file)
O2 - BHO: (no name) - {3E155C1A-176A-447C-8BDD-4F1F0EB42EBC} - C:\WINDOWS\system32\ddabb.dll (disabled by BHODemon)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {639BC63C-1F26-43C0-B160-914078103B91} - (no file)
O2 - BHO: (no name) - {904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4} - (no file)
O2 - BHO: (no name) - {93EF16B6-4E80-478B-8CC1-8E758B00256D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (disabled by BHODemon)
O2 - BHO: (no name) - {BC08C629-5C96-4EF2-904C-B41F5044F587} - (no file)
O2 - BHO: (no name) - {BE47878A-1D30-460C-8FC3-4249B9FA935A} - (no file)
O2 - BHO: (no name) - {E0B17033-4510-4DEE-B49D-4816A387C2D0} - (no file)
O2 - BHO: (no name) - {EFCB6030-B343-4836-97F0-9319A3178101} - (no file)
O2 - BHO: (no name) - {F6143B57-425B-432B-9BF6-802D0A81C63A} - (no file)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoAct…stcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/Fujifi…ploadClient.cab
O20 - Winlogon Notify: ddabb - C:\WINDOWS\
O20 - Winlogon Notify: gebya - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkhhi - C:\WINDOWS\
O20 - Winlogon Notify: jkkjk - C:\WINDOWS\
O20 - Winlogon Notify: mljhghf - mljhghf.dll (file missing)
O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll (file missing)
O20 - Winlogon Notify: urqroml - urqroml.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Access Task Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Virtual Audio Adapter (VAPSV) - Unknown owner - C:\WINDOWS\system32\vapsvc.exe (file missing)


**************************************************************
ComboFix 07-08-14.4 - "WebSites" 2007-08-19 22:26:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.42 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-19 21:09 d——– C:\VundoFix Backups
2007-08-19 20:29 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-15 22:38 d——– C:\Program Files\MSXML 6.0
2007-07-31 08:17 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-30 23:24 d——– C:\Program Files\AIM Spyware Remover
2007-07-30 23:16 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-27 20:34 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-27 20:34 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-27 20:34 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-07-27 20:34 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-19 18:16 81,332 –a—— C:\WINDOWS\system32\Bass.Dll
2007-07-19 18:16 733,184 –a—— C:\WINDOWS\system32\NCTAudioLibrary2.dll
2007-07-19 18:16 315,392 –a—— C:\WINDOWS\system32\NCTAudioPlayer2.dll
2007-07-19 18:16 307,200 –a—— C:\WINDOWS\system32\NCTAudioRecord2.dll
2007-07-19 18:16 237,568 –a—— C:\WINDOWS\system32\lame_enc.dll
2007-07-19 18:16 196,608 –a—— C:\WINDOWS\system32\NCTWMAFile2.dll
2007-07-19 18:16 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-07-19 18:16 1,839,104 –a—— C:\WINDOWS\system32\NCTAudioFile2.dll
2007-07-19 18:16 1,662,976 –a—— C:\WINDOWS\system32\NCTAudioCompress2.dll
2007-07-19 18:16 d——– C:\Program Files\SoftwareClub.ws


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 17:42 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-07-30 23:42 ——— d——– C:\Program Files\Lavasoft
2007-07-30 23:35 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-23 09:32 ——— d——– C:\Program Files\Common Files\AOL
2007-07-22 09:13 ——— d——– C:\Program Files\Image-Line
2007-07-20 15:13 ——— d——– C:\Program Files\Windows Movie Maker 2
2007-07-19 02:59 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-12 19:31 765952 –a–c— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 10:34 823808 –a–c— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 10:34 671232 –a–c— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 10:34 6058496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 10:34 52224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 10:34 477696 –a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 10:34 459264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 10:34 44544 —–c— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 10:34 384512 —–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 10:34 383488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 10:34 27648 –a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 10:34 267776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 10:34 232960 –a–c— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 10:34 230400 —–c— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 10:34 193024 –a–c— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 10:34 153088 —–c— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 10:34 132608 –a–c— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 10:34 124928 —–c— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:34 1152000 –a–c— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 10:34 105984 –a–c— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 10:34 102400 –a–c— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 04:27 63488 —–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 04:27 625152 –a–c— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 04:27 13824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 03:00 161792 —–c— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 02:08 1104896 –a–c— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 17:14 864 –ahs—- C:\zjmjaeh0.sys
2007-06-23 16:41 ——— d——– C:\Program Files\MtStudio
2007-06-19 09:31 282112 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a–c— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 –a–c— C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-07 10:06 3798528 –a—— C:\Program Files\SymADataWeb.msi
2006-12-18 20:58 796332 –a—— C:\Program Files\flashcreate!.exe
2006-12-18 17:48 1771096 –a—— C:\Program Files\MP3-Audio-Mixer.exe
2006-11-29 20:55 474 –a—— C:\Program Files\Shortcut to mstudioZ.lnk
2006-11-29 20:44 646 –a—— C:\Program Files\Video DVD Maker (2).lnk
2006-11-29 20:44 499 –a—— C:\Program Files\DivXInstaller.lnk
2006-11-21 18:55 15926792 –a—— C:\Program Files\DivXInstaller.exe
2006-11-21 16:36 897 –a—— C:\Program Files\Google Video Player.lnk
2006-10-14 16:59 4322816 –a—— C:\Program Files\mstudioZ.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C65A069-5204-40A0-BE11-6D18FF5E3B54}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E155C1A-176A-447C-8BDD-4F1F0EB42EBC}]
C:\WINDOWS\system32\ddabb.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{639BC63C-1F26-43C0-B160-914078103B91}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{93EF16B6-4E80-478B-8CC1-8E758B00256D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BC08C629-5C96-4EF2-904C-B41F5044F587}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE47878A-1D30-460C-8FC3-4249B9FA935A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0B17033-4510-4DEE-B49D-4816A387C2D0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFCB6030-B343-4836-97F0-9319A3178101}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F6143B57-425B-432B-9BF6-802D0A81C63A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 04:51]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 04:50]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-03-14 23:10]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 03:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddabb]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebya]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhi]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjk]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhghf]
mljhghf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjj]
C:\WINDOWS\system32\pmkjj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqroml]
urqroml.dll

R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S2 Access Task Manager;Access Task Manager;"C:\WINDOWS\system32\spoolcs.exe"
S2 VAPSV;Virtual Audio Adapter;"C:\WINDOWS\system32\vapsvc.exe"
S3 LMImirr;LMImirr;C:\WINDOWS\system32\DRIVERS\LMImirr.sys
S3 STVqx3;Intel Play QX3 Microscope;C:\WINDOWS\system32\drivers\STVqx3.sys

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-04-05 16:04:17 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
2007-08-20 01:01:24 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - WebSites.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net[/url">http://w…://www.gmer.net
Rootkit scan 2007-08-19 22:35:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 22:40:00
C:\ComboFix-quarantined-files.txt … 2007-08-19 22:39
C:\ComboFix2.txt … 2007-08-19 20:50

— E O F —

**************************************************************

Logfile of HijackThis v1.99.1
Scan saved at 11:54:32 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\SCANNER.EXE.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {2C65A069-5204-40A0-BE11-6D18FF5E3B54} - (no file)
O2 - BHO: (no name) - {3E155C1A-176A-447C-8BDD-4F1F0EB42EBC} - C:\WINDOWS\system32\ddabb.dll (disabled by BHODemon)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {639BC63C-1F26-43C0-B160-914078103B91} - (no file)
O2 - BHO: (no name) - {904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4} - (no file)
O2 - BHO: (no name) - {93EF16B6-4E80-478B-8CC1-8E758B00256D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (disabled by BHODemon)
O2 - BHO: (no name) - {BC08C629-5C96-4EF2-904C-B41F5044F587} - (no file)
O2 - BHO: (no name) - {BE47878A-1D30-460C-8FC3-4249B9FA935A} - (no file)
O2 - BHO: (no name) - {E0B17033-4510-4DEE-B49D-4816A387C2D0} - (no file)
O2 - BHO: (no name) - {EFCB6030-B343-4836-97F0-9319A3178101} - (no file)
O2 - BHO: (no name) - {F6143B57-425B-432B-9BF6-802D0A81C63A} - (no file)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O20 - Winlogon Notify: ddabb - C:\WINDOWS\
O20 - Winlogon Notify: gebya - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkhhi - C:\WINDOWS\
O20 - Winlogon Notify: jkkjk - C:\WINDOWS\
O20 - Winlogon Notify: mljhghf - mljhghf.dll (file missing)
O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll (file missing)
O20 - Winlogon Notify: urqroml - urqroml.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Access Task Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Virtual Audio Adapter (VAPSV) - Unknown owner - C:\WINDOWS\system32\vapsvc.exe (file missing)
Good Morning,

I know this stuff is frustrating but sometimes its best to just post when you get hit so we can get the whole picture. What you have and is almost gone is the Vundo Trojan.

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

Remove these only because there is one 020 entry that is legit and you don't want to remove.

O2 - BHO: (no name) - {2C65A069-5204-40A0-BE11-6D18FF5E3B54} - (no file)
O2 - BHO: (no name) - {3E155C1A-176A-447C-8BDD-4F1F0EB42EBC} - C:\WINDOWS\system32\ddabb.dll (disabled by BHODemon)
O2 - BHO: (no name) - {639BC63C-1F26-43C0-B160-914078103B91} - (no file)
O2 - BHO: (no name) - {904D005A-4AF4-4ABE-951F-6B1DEBDF5CF4} - (no file)
O2 - BHO: (no name) - {93EF16B6-4E80-478B-8CC1-8E758B00256D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (disabled by BHODemon
O2 - BHO: (no name) - {BC08C629-5C96-4EF2-904C-B41F5044F587} - (no file)
O2 - BHO: (no name) - {BE47878A-1D30-460C-8FC3-4249B9FA935A} - (no file)
O2 - BHO: (no name) - {E0B17033-4510-4DEE-B49D-4816A387C2D0} - (no file)
O2 - BHO: (no name) - {EFCB6030-B343-4836-97F0-9319A3178101} - (no file)
O2 - BHO: (no name) - {F6143B57-425B-432B-9BF6-802D0A81C63A} - (no file)

O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O20 - Winlogon Notify: ddabb - C:\WINDOWS\
O20 - Winlogon Notify: gebya - C:\WINDOWS\
O20 - Winlogon Notify: jkhhi - C:\WINDOWS\
O20 - Winlogon Notify: jkkjk - C:\WINDOWS\
O20 - Winlogon Notify: mljhghf - mljhghf.dll (file missing)
O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll (file missing)
O20 - Winlogon Notify: urqroml - urqroml.dll (file missing)


Rerun Combofix and post the log plus a New HJT log please.
:wavey: Hi Again, Your right about getting help first. I did everything you suggested. Is there a way in the future for me to manually check to see if a file is legitimate? Below are logs. Thanks Again, Lori

ComboFix 07-08-14.4 - "WebSites" 2007-08-21 13:25:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.64 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))


2007-08-19 21:09 d——– C:\VundoFix Backups
2007-08-19 20:29 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-15 22:38 d——– C:\Program Files\MSXML 6.0
2007-07-31 08:17 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-30 23:24 d——– C:\Program Files\AIM Spyware Remover
2007-07-30 23:16 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-27 20:34 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-07-27 20:34 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-07-27 20:34 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-07-27 20:34 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 12:31 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-07-30 23:42 ——— d——– C:\Program Files\Lavasoft
2007-07-30 23:35 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-23 09:32 ——— d——– C:\Program Files\Common Files\AOL
2007-07-22 09:13 ——— d——– C:\Program Files\Image-Line
2007-07-20 15:13 ——— d——– C:\Program Files\Windows Movie Maker 2
2007-07-19 18:16 ——— d——– C:\Program Files\SoftwareClub.ws
2007-07-19 02:59 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-12 19:31 765952 –a–c— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 10:34 823808 –a–c— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 10:34 671232 –a–c— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 10:34 6058496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 10:34 52224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 10:34 477696 –a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 10:34 459264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 10:34 44544 —–c— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 10:34 384512 —–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 10:34 383488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 10:34 27648 –a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 10:34 267776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 10:34 232960 –a–c— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 10:34 230400 —–c— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 10:34 193024 –a–c— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 10:34 153088 —–c— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 10:34 132608 –a–c— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 10:34 124928 —–c— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:34 1152000 –a–c— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 10:34 105984 –a–c— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 10:34 102400 –a–c— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 04:27 63488 —–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 04:27 625152 –a–c— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 04:27 13824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 03:00 161792 —–c— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 02:08 1104896 –a–c— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 17:14 864 –ahs—- C:\zjmjaeh0.sys
2007-06-23 16:41 ——— d——– C:\Program Files\MtStudio
2007-06-19 09:31 282112 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a–c— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 –a–c— C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-07 10:06 3798528 –a—— C:\Program Files\SymADataWeb.msi
2006-12-18 20:58 796332 –a—— C:\Program Files\flashcreate!.exe
2006-12-18 17:48 1771096 –a—— C:\Program Files\MP3-Audio-Mixer.exe
2006-11-29 20:55 474 –a—— C:\Program Files\Shortcut to mstudioZ.lnk
2006-11-29 20:44 646 –a—— C:\Program Files\Video DVD Maker (2).lnk
2006-11-29 20:44 499 –a—— C:\Program Files\DivXInstaller.lnk
2006-11-21 18:55 15926792 –a—— C:\Program Files\DivXInstaller.exe
2006-11-21 16:36 897 –a—— C:\Program Files\Google Video Player.lnk
2006-10-14 16:59 4322816 –a—— C:\Program Files\mstudioZ.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 04:51]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 04:50]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-03-14 23:10]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 03:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S2 Access Task Manager;Access Task Manager;"C:\WINDOWS\system32\spoolcs.exe"
S2 VAPSV;Virtual Audio Adapter;"C:\WINDOWS\system32\vapsvc.exe"
S3 LMImirr;LMImirr;C:\WINDOWS\system32\DRIVERS\LMImirr.sys
S3 STVqx3;Intel Play QX3 Microscope;C:\WINDOWS\system32\drivers\STVqx3.sys

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-04-05 16:04:17 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
2007-08-21 16:33:50 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - WebSites.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 13:52:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 14:01:41
C:\ComboFix-quarantined-files.txt … 2007-08-21 14:01
C:\ComboFix2.txt … 2007-08-19 22:40
C:\ComboFix3.txt … 2007-08-19 20:50

— E O F —
__________________________________________________________________________




Logfile of HijackThis v1.99.1
Scan saved at 2:13:29 PM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\SCANNER.EXE.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Access Task Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Virtual Audio Adapter (VAPSV) - Unknown owner - C:\WINDOWS\system32\vapsvc.exe (file missing)
It looks like Vundo is gone…BUT, you have a couple of other issues we need to get rid of.


Lets tackle this one first .


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
LoriGiz :D

I am so happy that I am finally getting somewhere. I will do this step now.

After your clean, I will give you links to free programs to install to help block this garbage from installing.
Hi again,
Had trouble getting forum page for some reason. I had to go through your profile and get post there. It's working OK now though. :thumbup:

OK- SDFIX log and New HiJackthis log

SDFIX:


DFix: Version 1.99

Run by [removed] on Tue 08/21/2007 at 08:11 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
VAPSV

ImagePath:
"C:\WINDOWS\system32\vapsvc.exe"

VAPSV - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————

Registry Backups: - C:\SDFix\backups\backupreg.zip
Full Registry Backup: - C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE

Files with Hidden Attributes:

C:\zjmjaeh0.sys
C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\ihhkj.tmp
C:\WINDOWS\system32\jjkmp.tmp
C:\WINDOWS\system32\rqstv.tmp
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG

Finished

HIJACKTHIS Log:

Logfile of HijackThis v1.99.1
Scan saved at 9:46:00 PM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\COH\coh32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Hijackthis\SCANNER.EXE.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Access Task Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe







Your doing good :thumbup: Just a little more to do.

FYI This is what SDFix Removed…it was nasty
O23 - Service: Virtual Audio Adapter (VAPSV) - Unknown owner - C:\WINDOWS\system32\vapsvc.exe (file missing)

This is what it was
http://www.castlecops.com/o23list-2689.html


This one we have to do manually.
  • Go to Start> Run and type in services.msc then press Enter
  • Scroll down to Access Task Manager
  • Double Click that service to open it.
  • Click on Stop Service.
  • Then change the Startup Type to Disabled.
  • OK your way out of the program.
  • Open HJT > Misc Tools > Delete an NT Service
  • Type in Access Task Manager
  • Then click on OK, it will ask you to reboot, do so.
Reboot your computer if you have not done so.

Run HJT and if this is still present, have HJT remove it
O23 - Service: Access Task Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)



Run this system cleaner.

Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up

Thank You Atribune


Post a new HJT log and lets hope all this garbage is gone. How are things running now??
Wow! I saw that file before and wondered what it was ( .O23 - Service: Virtual Audio Adapter (VAPSV). I even copied and pasted it and searched for it on the net to see what it was. I noticed that quite a few people had that same file on their hijackthis post. Since I didn't read anything bad I figured it was OK. That's why I was asking about legit files, so I am glad that you can help me with this.

Can you please tell me what makes this file nasty and if I should be overly concerned?
I clicked link for further detail, but didn't quite understand what I was reading, except that the link below led me to other files connected to this problem. ? If that is the case then I have seen the
".net Framework Service.", and I do have a wireless card on my computer for internet access.

O23 List of Windows XP/NT services Deep Dive
Navigate: [
O23 List of Windows XP/NT services]

.NET Framework Service (.NET Connection Service)
NET Framework Service (.NET Connection Service)

ALSO,

I forgot to mention a few things to you before. Although I know that it is not neccessary, there are three accounts on this computer. For example there is account W, and Account Y, and the Administrator account. When I logged into safe mode there was not a choice to log into account W which is the primary account. Account Y and the Admin account were the only choices so I logged onto Administrator and searched for SDFIX and ran from there. When I rebooted I ran the fix in Account W. Did I handle that properly?

Also, Maybe it's nothing, but when I was on the Administrator account I noticed a file that did not look right on the desktop it was called- Mixere.-10.82.bin. When I clicked on properties it had full control to modify, read, and write.

I am going to do your recommended changes now.

Once again Thank you, Thank you, Thankyou! :wavey:
:thumbup: OK did as requested.Access Task Manager was already stopped when I went in, I guess previous program took care of that. I deleted file and when finished and before reboot the following files popped up with execution errors:

Ending program:
ccApp.exe -(I believe this is a symantic program)
msmsgs.exe
tried to end but failed program Font capture
tried to end but failed program SW
dwwin.exe
- initialization error
explorer.exe error


also on last assignment got this error: c:\windows\system32\spoolcs.exe file missing
aaApp.exe error

The internet seems to be running faster and I haven't had any freezing windows. I was able to log on to email surprisely fast. I do lose connection frequently , but that may be due to wireless card. The system still seems sluggish when trying to access files though, especially microsoft works. Tomorrow I will have a better handle on speed etc. Maybe that is a memory issue. Should I run Defrag as well? I am very grateful for this experience. Good Night.

HiJACK LOG:

Logfile of HijackThis v1.99.1
Scan saved at 1:10:25 AM, on 8/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\SCANNER.EXE.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Your log looks fine :thumbup: Sometimes these infections bring other things with it. Why don't you run the free version of AVG Anti Spyware, besure to follow the instructions and save the report for me to see.


Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on How to Act and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found



IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system <– Dont forget this
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5

Go grab some coffee, this may take the better part of an hour.
Hi again,

I had to uninstall previous version AVG, then about 5 file errors, then rebooted, and installed 7.5.
Computer was still sluggish, and kept losing internet connection, however still much better than before.
I disabled Norton Internet security since I think it might be causing some of these problems. - When I installed it originally, I already had these issues and I had a lot of trouble getting it to scan initially. Maybe I should reinstall whole product? By the way, do I need "O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com" since I am out of warranty with them any way?
Below are two reports requested. Whew this is tiring. Good Night. :wavey:

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:02:57 PM 8/22/2007

+ Scan result:

C:\Documents and Settings\WebSites\Cookies\websites@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\WebSites\Cookies\websites@pandasoftware.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\WebSites\Cookies\websites@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\WebSites\Cookies\websites@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\WebSites\Cookies\websites@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\WebSites\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 12:14:45 AM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\SCANNER.EXE.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Good Morning,

All AVG found were cookies :thumbup:

You can remove this with HJT.
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com

net Framework
<–Is needed to run certain printers and such.

net Framework Service. <–Could be a trojan but I don't see it on your system

The rest of your log looks fine. :thumbup:


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places 1000s of web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
    Nice Tutorial

  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Safe Surfin
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI