This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Help! Ie Popups

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After opening internet explorer, new pages will occasionaly pop up in the background. There can be times wheres its 1 at a time or multiple ones at once. I have McAfee Anti-Virus, and it has found nothing after repeated scans, so theres no virus. I've tried Windows Defender and it found 3 files in my system restore folder, but that fixed nothing by removing them.

Heres my HJ log, and I'm curios to the 020 entry of c00c65e4.dat.

Logfile of HijackThis v1.99.1
Scan saved at 1:45:14 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\McAfee\MSC\mcshell.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Shane\Desktop\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155658145395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155658203779
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

So what do you guys think? A lot of the ads are broadcaster.com but theres a wide array of other things thrown into the mix as well.
Hello and welcome to the forums

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Note:
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)


It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
Do not run a scan yet.

Reboot your computer into SafeMode
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.



IMPORTANT: Do not open any other windows or
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:

  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
    • Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
    • Reboot in normal mode and copy the report back to this topic along with a new HijackThis log.
Ok performed as requested. Heres the logs. Note that after running the scan, I was not able to access the forums from that computer to post the logs because the popups came to frequently. It has never been this bad as after the scan.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 6:33:40 PM 8/19/2007

+ Scan result:



:mozilla.237:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.476:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.477:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.478:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.215:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.315:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.336:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.970:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.877:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.208:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.209:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.447:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.448:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.449:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.450:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.451:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.452:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.453:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.457:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.861:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.491:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.492:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.493:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.494:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.495:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.496:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.80:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.423:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.422:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.426:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.427:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.441:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.442:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.443:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.584:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.585:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.234:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.273:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.460:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.461:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.462:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.463:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.464:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.465:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.466:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.467:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.468:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.469:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.331:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.332:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.348:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.359:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.517:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.566:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.568:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.572:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.597:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.749:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.406:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.32:C:\Documents and Settings\Danielle\Application Data\Mozilla\Firefox\Profiles\dtw1o6hl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
[1016] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[1136] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[220] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[288] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[448] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[516] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[560] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[644] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[692] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).
[728] C:\WINDOWS\system32\__c00C65E4.dat -> Trojan.BHO.bd : Cleaned with backup (quarantined).


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 6:59:26 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Shane\Desktop\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155658145395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155658203779
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All then Remove Finally


1. launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


2. Save this text as fixme.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on fixme.reg. When it asks you to merge the information to the registry click Yes.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint <–All Viewpoint programs listed


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deafO4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
While 'Fixing' the things in HJT I received the following error:

An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat)
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 7.0.5730.11
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.

I tried it again to get the same thing.

Here is my new log,

Logfile of HijackThis v1.99.1
Scan saved at 8:22:57 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Shane\Desktop\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155658145395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155658203779
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

I even tried rebooting to clear that O20. Perhaps I should do this is safe mode? Leave that up to you. Oh and at this point, the problem is still not fixed. If I open internet explorer and just leave it at my homepage, within 10 seconds I will start receiving popups and popunders, in a fairly fast manner. Seems to stop at about 6.
Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
ComboFix 07-08-14.4 - "Danielle" 2007-08-19 20:37:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.197 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-19 20:36 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 16:42 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-19 14:33 d——– C:\DOCUME~1\Family\APPLIC~1\Viewpoint
2007-08-19 13:27 d——– C:\VundoFix Backups
2007-08-17 17:33 d——– C:\Program Files\Windows Defender
2007-08-17 16:32 d——– C:\WINDOWS\pss
2007-08-17 00:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 20:40 2,338 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-16 20:16 d——– C:\Program Files\Lavasoft
2007-08-16 20:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-02 17:24 d——– C:\WINDOWS\CSC
2007-08-02 16:36 0 –a—— C:\WINDOWS\nsreg.dat
2007-08-01 19:35 2,883,584 –a—— C:\DOCUME~1\Danielle\ntuser.dat
2007-07-20 21:57 921,872 –a—— C:\WINDOWS\system32\MGX40.DLL
2007-07-20 21:57 81,408 –a—— C:\WINDOWS\system32\LTIMG70N.DLL
2007-07-20 21:57 73,728 –a—— C:\WINDOWS\MVMC14N.DLL
2007-07-20 21:57 69,072 –a—— C:\WINDOWS\MVMC14W.DLL
2007-07-20 21:57 68,608 –a—— C:\WINDOWS\MVIX14N.DLL
2007-07-20 21:57 56,320 –a—— C:\WINDOWS\MVFS14N.DLL
2007-07-20 21:57 51,200 –a—— C:\WINDOWS\MVSR14N.DLL
2007-07-20 21:57 50,688 –a—— C:\WINDOWS\MVTL14N.DLL
2007-07-20 21:57 5,632 –a—— C:\WINDOWS\system32\MFCUIA32.DLL
2007-07-20 21:57 38,400 –a—— C:\WINDOWS\system32\MGXFRM20.DLL
2007-07-20 21:57 322,832 –a—— C:\WINDOWS\system32\MFC30.DLL
2007-07-20 21:57 32,768 –a—— C:\WINDOWS\system32\LFGIF70N.DLL
2007-07-20 21:57 32,768 –a—— C:\WINDOWS\MVMG14N.DLL
2007-07-20 21:57 26,112 –a—— C:\WINDOWS\system32\LFICA70N.DLL
2007-07-20 21:57 25,600 –a—— C:\WINDOWS\MVBK14N.DLL
2007-07-20 21:57 25,088 –a—— C:\WINDOWS\system32\lflmb70n.dll
2007-07-20 21:57 24,064 –a—— C:\WINDOWS\system32\LFPCT70N.DLL
2007-07-20 21:57 20,480 –a—— C:\WINDOWS\system32\LFIMG70N.DLL
2007-07-20 21:57 194,560 –a—— C:\WINDOWS\system32\MGXBM21.DLL
2007-07-20 21:57 19,968 –a—— C:\WINDOWS\system32\LFCAL70N.DLL
2007-07-20 21:57 19,456 –a—— C:\WINDOWS\system32\LFRAS70N.DLL
2007-07-20 21:57 19,456 –a—— C:\WINDOWS\system32\LFMSP70N.DLL
2007-07-20 21:57 18,944 –a—— C:\WINDOWS\system32\LFWFX70N.DLL
2007-07-20 21:57 18,944 –a—— C:\WINDOWS\system32\LFMAC70N.DLL
2007-07-20 21:57 133,904 –a—— C:\WINDOWS\system32\MFCANS32.DLL
2007-07-20 21:57 133,392 –a—— C:\WINDOWS\system32\MFCO30.DLL
2007-07-20 21:57 112,128 –a—— C:\WINDOWS\MVCL14N.DLL
2007-07-20 21:57 10,240 –a—— C:\WINDOWS\MVUT14N.DLL
2007-07-20 21:57 1,483,776 –a—— C:\WINDOWS\MGXRDR32.DLL
2007-07-20 21:57 d——– C:\Program Files\Micrografx


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-17 11:48 ——— d——– C:\Program Files\Google
2007-08-06 14:27 ——— d——– C:\Program Files\McAfee
2007-08-03 12:41 ——— d——– C:\Program Files\Common Files\McAfee
2007-08-02 16:35 ——— d——– C:\DOCUME~1\Danielle\APPLIC~1\U3
2007-07-24 12:02 33800 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-07-24 07:40 79304 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-07-21 21:44 ——— d——– C:\Program Files\eMule
2007-07-21 09:08 40488 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-07-21 09:08 35240 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-07-21 09:08 201288 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-07-19 21:54 ——— d——– C:\Program Files\Trillian
2007-07-19 02:59 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 09:20 113952 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-07-12 19:31 765952 –a–c— C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-12 14:29 ——— d——– C:\DOCUME~1\Danielle\APPLIC~1\Real
2007-07-07 19:17 ——— d——– C:\DOCUME~1\Danielle\APPLIC~1\eMule
2007-06-27 10:34 823808 –a–c— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 10:34 671232 –a–c— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 10:34 6058496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 10:34 52224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 10:34 477696 –a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 10:34 459264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 10:34 44544 —–c— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 10:34 384512 —–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 10:34 383488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 10:34 27648 –a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 10:34 267776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 10:34 232960 —–c— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 10:34 230400 —–c— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 10:34 193024 –a–c— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 10:34 153088 —–c— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 10:34 132608 –a–c— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 10:34 124928 —–c— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:34 1152000 –a–c— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 10:34 105984 —–c— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 10:34 102400 —–c— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 04:27 63488 —–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 04:27 625152 —–c— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 04:27 13824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 03:00 161792 –a–c— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 —–c— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-25 15:50 ——— d——– C:\Program Files\McAfee.com
2007-06-25 15:36 ——— d——– C:\Program Files\Symantec
2007-06-25 15:36 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 —–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 —–c— C:\WINDOWS\system32\dllcache\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 05:50 C:\WINDOWS\LOGI_MWX.EXE]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 12:02]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 21:05]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-25 14:54]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 09:47]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\Danielle\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2005-02-23]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-07-07 16:21:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c00C65E4.dat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

R3 crtaud;Conexant Riptide WDM Audio Driver;C:\WINDOWS\system32\drivers\crtaud.sys
R3 rpfun;Conexant Riptide Dummy Driver;C:\WINDOWS\system32\drivers\rpfun.sys
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;C:\WINDOWS\system32\drivers\rthwcls.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34208c00-d66a-11db-948f-00e0180d4bde}]
AutoRun\command- E:\LaunchU3.exe -a


Contents of the 'Scheduled Tasks' folder
2007-06-25 19:50:46 C:\WINDOWS\Tasks\McDefragTask.job - c:\program files\mcafee\mqc\QcConsol.exe
2007-06-25 19:50:44 C:\WINDOWS\Tasks\McQcTask.job - c:\program files\mcafee\mqc\QcConsol.exe
2007-08-20 00:45:30 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 20:44:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 20:48:01 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-19 20:47

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 8:56:00 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Shane\Desktop\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155658145395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155658203779
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C65E4.dat
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\__c00C65E4.dat

Folder::
C:\DOCUME~1\Family\APPLIC~1\Viewpoint
C:\VundoFix Backups

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34208c00-d66a-11db-948f-00e0180d4bde}]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
ComboFix 07-08-14.4 - "Family" 2007-08-19 22:29:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.181 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Family\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\__c00C65E4.dat


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Family\APPLIC~1\Viewpoint
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\URLCache.ini
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\URLCache.ini
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-586899792.mtj&p2=1&p3=16296206302646515504478914846829&p4=50528303
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\URLCache.ini
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\URLCache.ini
C:\DOCUME~1\Family\APPLIC~1\Viewpoint\Viewpoint Media Player\Resources\UpdateVersionList_v2.mtx
C:\VundoFix Backups


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-19 20:36 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 16:42 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-17 17:33 d——– C:\Program Files\Windows Defender
2007-08-17 16:32 d——– C:\WINDOWS\pss
2007-08-17 00:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 20:40 2,338 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-16 20:16 d——– C:\Program Files\Lavasoft
2007-08-16 20:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-02 17:24 d——– C:\WINDOWS\CSC
2007-08-02 16:36 0 –a—— C:\WINDOWS\nsreg.dat
2007-08-01 19:35 2,883,584 –a—— C:\DOCUME~1\Danielle\ntuser.dat
2007-07-20 21:57 921,872 –a—— C:\WINDOWS\system32\MGX40.DLL
2007-07-20 21:57 81,408 –a—— C:\WINDOWS\system32\LTIMG70N.DLL
2007-07-20 21:57 73,728 –a—— C:\WINDOWS\MVMC14N.DLL
2007-07-20 21:57 69,072 –a—— C:\WINDOWS\MVMC14W.DLL
2007-07-20 21:57 68,608 –a—— C:\WINDOWS\MVIX14N.DLL
2007-07-20 21:57 56,320 –a—— C:\WINDOWS\MVFS14N.DLL
2007-07-20 21:57 51,200 –a—— C:\WINDOWS\MVSR14N.DLL
2007-07-20 21:57 50,688 –a—— C:\WINDOWS\MVTL14N.DLL
2007-07-20 21:57 5,632 –a—— C:\WINDOWS\system32\MFCUIA32.DLL
2007-07-20 21:57 38,400 –a—— C:\WINDOWS\system32\MGXFRM20.DLL
2007-07-20 21:57 322,832 –a—— C:\WINDOWS\system32\MFC30.DLL
2007-07-20 21:57 32,768 –a—— C:\WINDOWS\system32\LFGIF70N.DLL
2007-07-20 21:57 32,768 –a—— C:\WINDOWS\MVMG14N.DLL
2007-07-20 21:57 26,112 –a—— C:\WINDOWS\system32\LFICA70N.DLL
2007-07-20 21:57 25,600 –a—— C:\WINDOWS\MVBK14N.DLL
2007-07-20 21:57 25,088 –a—— C:\WINDOWS\system32\lflmb70n.dll
2007-07-20 21:57 24,064 –a—— C:\WINDOWS\system32\LFPCT70N.DLL
2007-07-20 21:57 20,480 –a—— C:\WINDOWS\system32\LFIMG70N.DLL
2007-07-20 21:57 194,560 –a—— C:\WINDOWS\system32\MGXBM21.DLL
2007-07-20 21:57 19,968 –a—— C:\WINDOWS\system32\LFCAL70N.DLL
2007-07-20 21:57 19,456 –a—— C:\WINDOWS\system32\LFRAS70N.DLL
2007-07-20 21:57 19,456 –a—— C:\WINDOWS\system32\LFMSP70N.DLL
2007-07-20 21:57 18,944 –a—— C:\WINDOWS\system32\LFWFX70N.DLL
2007-07-20 21:57 18,944 –a—— C:\WINDOWS\system32\LFMAC70N.DLL
2007-07-20 21:57 133,904 –a—— C:\WINDOWS\system32\MFCANS32.DLL
2007-07-20 21:57 133,392 –a—— C:\WINDOWS\system32\MFCO30.DLL
2007-07-20 21:57 112,128 –a—— C:\WINDOWS\MVCL14N.DLL
2007-07-20 21:57 10,240 –a—— C:\WINDOWS\MVUT14N.DLL
2007-07-20 21:57 1,483,776 –a—— C:\WINDOWS\MGXRDR32.DLL
2007-07-20 21:57 d——– C:\Program Files\Micrografx


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 21:37 ——— d——– C:\Program Files\Trillian
2007-08-17 11:48 ——— d——– C:\Program Files\Google
2007-08-06 14:27 ——— d——– C:\Program Files\McAfee
2007-08-03 12:41 ——— d——– C:\Program Files\Common Files\McAfee
2007-07-24 12:02 33800 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-07-24 07:40 79304 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-07-21 21:44 ——— d——– C:\Program Files\eMule
2007-07-21 09:08 40488 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-07-21 09:08 35240 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-07-21 09:08 201288 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-07-19 02:59 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 09:20 113952 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-07-12 19:31 765952 –a–c— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-27 10:34 823808 –a–c— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 10:34 671232 –a–c— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 10:34 6058496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 10:34 52224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 10:34 477696 –a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 10:34 459264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 10:34 44544 —–c— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 10:34 384512 —–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 10:34 383488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 10:34 27648 –a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 10:34 267776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 10:34 232960 —–c— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 10:34 230400 —–c— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 10:34 193024 –a–c— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 10:34 153088 —–c— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 10:34 132608 –a–c— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 10:34 124928 —–c— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:34 1152000 –a–c— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 10:34 105984 —–c— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 10:34 102400 —–c— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 04:27 63488 —–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 04:27 625152 —–c— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 04:27 13824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 03:00 161792 –a–c— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 —–c— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-25 15:50 ——— d——– C:\Program Files\McAfee.com
2007-06-25 15:36 ——— d——– C:\Program Files\Symantec
2007-06-25 15:36 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-06-24 20:39 ——— d——– C:\DOCUME~1\Family\APPLIC~1\AdobeUM
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 —–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 —–c— C:\WINDOWS\system32\dllcache\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 05:50 C:\WINDOWS\LOGI_MWX.EXE]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 12:02]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 21:05]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-25 14:54]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 09:47]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\Family\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-08-15 15:22:35]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-07-07 16:21:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c00C65E4.dat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

R3 crtaud;Conexant Riptide WDM Audio Driver;C:\WINDOWS\system32\drivers\crtaud.sys
R3 rpfun;Conexant Riptide Dummy Driver;C:\WINDOWS\system32\drivers\rpfun.sys
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;C:\WINDOWS\system32\drivers\rthwcls.sys

*Newly Created Service* - CATCHME

Contents of the 'Scheduled Tasks' folder
2007-06-25 19:50:46 C:\WINDOWS\Tasks\McDefragTask.job - c:\program files\mcafee\mqc\QcConsol.exe
2007-06-25 19:50:44 C:\WINDOWS\Tasks\McQcTask.job - c:\program files\mcafee\mqc\QcConsol.exe
2007-08-20 00:45:30 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 22:31:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 22:33:12
C:\ComboFix-quarantined-files.txt … 2007-08-19 22:32
C:\ComboFix2.txt … 2007-08-19 20:48

— E O F —


From what I can tell after leaving Internet Explorer open, my problem is fixed. Before I consider my problem resolved, would you mind explaining to me the details of what was inside my system? It looked like a Trojan-like Browser Helper Object to me.
The file was nowhere to be found.

Logfile of HijackThis v1.99.1
Scan saved at 11:04:32 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Shane\Desktop\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155658145395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155658203779
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
You can remove any programs / Tools I had you install. Use Add/Remove Programs to remove if listed there otherwise just delete them and empty recycle bin.

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.



If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.


Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.

Only run one Anti-Virus and Firewall program.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware


Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI