This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde, Popups, Winantivirus.. Help!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am new here.. I hope someone can help me with this.

Today this started happening where my computer was trying to connect to a web page when i was offline. Then when I did get online, popups from "winantivirus" started. So i ran SpyBot and it found a few things and fixed them. It also found "virtumonde" but can't fix it. So now I have very annoying popups happening.

Here is my HijackThis log. Can anyone please help me? I would appreciate it so much!

EDIT: I just read the self help section after I panicked. Sorry for posting without reading! I followed the instructions for Vundo removal and here is my VundoFix log and also my new HijackThis log.



VundoFix V6.5.7

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 9:51:14 AM 8/21/2007

Listing files found while scanning….

C:\windows\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\ssqpm.dll

Beginning removal…

Attempting to delete C:\windows\system32\mpqss.bak1
C:\windows\system32\mpqss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqpm.dll Has been deleted!

Performing Repairs to the registry.
Done!



Logfile of HijackThis v1.99.1
Scan saved at 10:01:36 AM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\NMSAccess.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grave.livejournal.com/friends?

show=P&filter=0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2E2A8507-459E-4903-AB02-9CD4A36E9977} - C:\WINDOWS\system32\ssqpm.dll

(file missing)
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1

\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1

\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {C84D8A0A-E708-42B6-90CA-9C30956A87C6} - C:\WINDOWS\system32

\ssqnklm.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!

\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1

\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden

/tgcmdwrapper
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r

"C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}

\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1112078643

\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] "C:\Program

Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common

Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL

Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11

\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-

WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-

WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-

WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-

WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32

\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!

\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4

\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) -

http://ibhost.dancik.com/download/combo1.0.6.0614.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) -

http://download.games.yahoo.com/games/web_…itched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) -

http://www.shockwave.com/content/sandscrip…pt.1.0.0.21.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) -

http://www.shockwave.com/content/sweetopia…ia.1.0.0.22.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnklm - C:\WINDOWS\SYSTEM32\ssqnklm.dll
O20 - Winlogon Notify: winjyg32 - winjyg32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4

\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4

\ashWebSv.exe" /service (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\WINDOWS\system32\NMSAccess.exe
Hello grave and welcome to the SpywareSupport Forums

My name is Trevuren and I will be helping you with your problem.

Good job on the first part of your cleanup. There is still more to do.


A. I need you to post your log in single space format instead of double space as it currently is.

To remove the double spacing in your log, please do the following:
  • Please go to Start >> Run… and type notepad.exe
  • Hit OK.
  • Now go to Format and uncheck WordWrap.
  • Close Notepad.


B. Please download this file - combofix.exe by sUBs
  • You must download it to and run it from your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
OK, I did as you said. Here is the ComboFix log along with the HijackThis log below it. I had to run ComboFix twice because the first time around Avast thought it was a virus and I clicked it as such by accident. Whoops!


ComboFix 07-08-22.1 - "Owner" 2007-08-21 22:00:49.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.222 [GMT -4:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\kernel32.exe


((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))


2007-08-21 21:02 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-21 10:52 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-08-21 10:52 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-08-21 10:52 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-08-21 10:52 4,212 –ah—– C:\WINDOWS\system32\zllictbl.dat
2007-08-21 10:52 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-08-21 10:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-21 10:51 739,360 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-21 10:51 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-08-21 10:51 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-08-21 10:51 d——– C:\WINDOWS\system32\ZoneLabs
2007-08-21 10:50 d——– C:\WINDOWS\Internet Logs
2007-08-21 09:51 d——– C:\VundoFix Backups
2007-08-21 07:33 87,616 –a—— C:\WINDOWS\system32\eoaxqsjq.dll
2007-08-20 09:31 1,819 –a—— C:\WINDOWS\system32\sdbackup.reg
2007-08-20 01:08 5,248 –a—— C:\WINDOWS\system32\drivers\d347prt.sys
2007-08-20 01:08 155,136 –a—— C:\WINDOWS\system32\drivers\d347bus.sys
2007-08-20 01:08 d——– C:\Program Files\D-Tools
2007-08-18 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\ashampoo
2007-08-15 18:50 d——– C:\DOCUME~1\Owner\APPLIC~1\uTorrent
2007-08-13 15:26 d——– C:\Program Files\ACTIMAGE
2007-08-05 22:00 d——– C:\WINDOWS\system32\NtmsData
2007-08-02 17:16 d——– C:\DOCUME~1\Owner\APPLIC~1\iWin
2007-08-02 05:58 d——– C:\Program Files\QuickTime
2007-08-02 05:57 d——– C:\Program Files\Apple Software Update
2007-08-02 05:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-29 19:34 d——– C:\Program Files\MySpace
2007-07-29 19:34 d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\MySpace


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 20:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\uTorrent
2007-08-21 10:55 1484 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-21 10:13 ——— d——– C:\Program Files\Yahoo! Games
2007-08-21 10:12 ——— d——– C:\Program Files\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:10 ——— d——– C:\Program Files\Jig Words
2007-08-21 05:10 ——— d——– C:\Program Files\EA GAMES
2007-08-15 18:51 ——— d——– C:\Program Files\uTorrent
2007-08-12 23:19 ——— d——– C:\Program Files\Semagic
2007-08-12 18:32 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\dvdcss
2007-08-11 11:48 ——— d——– C:\Program Files\Quake III Arena
2007-08-09 16:30 ——— d——– C:\Program Files\Microsoft Picture It! PhotoPub
2007-08-05 18:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Apple Computer
2007-08-02 05:57 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-01 18:37 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\LimeWire
2007-07-22 20:45 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Canon
2007-07-20 11:36 ——— d——– C:\Program Files\Common Files\Motive
2007-07-17 07:17 532480 –a—— C:\WINDOWS\system32\The Simpsons Movie.scr
2007-07-14 03:18 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-07-12 10:08 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
2007-07-09 07:24 ——— d——– C:\Program Files\The Adventure Company
2007-06-30 15:04 ——— d——– C:\Program Files\BurnQuick
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-24 23:47 ——— dr-h—– C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-06-24 23:47 ——— d——– C:\Program Files\Yahoo!
2007-06-24 20:22 737280 –a—— C:\WINDOWS\iun6002.exe
2007-06-24 20:22 57344 –a—— C:\WINDOWS\system32\WNASPINT.DLL
2007-06-24 19:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 18:16 ——— d——– C:\Program Files\PeoplePC
2007-06-21 23:59 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-06-15 12:00 66269 –a—— C:\Program Files\INSTALL.LOG
2005-02-01 06:39:56 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A94BA5A-0F0E-4571-98C3-618D59114BE3}]
C:\WINDOWS\system32\pmkji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E2A8507-459E-4903-AB02-9CD4A36E9977}]
C:\WINDOWS\system32\ssqpm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 C:\WINDOWS\system32\VTTimer.exe]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 12:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-09-06 09:29]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 14:14]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 11:17]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 20:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" []
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" []
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 14:03]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 12:16]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 07:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 07:15]
"HostManager"="C:\Program Files\Common Files\AOL\1112078643\EE\AOLHostManager.exe" []
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" [2007-01-28 12:14]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-01-15 13:28]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"svhost"="C:\WINDOWS\svhost.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkji]
C:\WINDOWS\system32\pmkji.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnklm]
ssqnklm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winjyg32]
winjyg32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)

S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINDOWS\system32\DRIVERS\usbscan.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 22:09:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 22:10:22
C:\ComboFix-quarantined-files.txt … 2007-08-21 22:10

— E O F —



Logfile of HijackThis v1.99.1
Scan saved at 10:20:06 PM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\NMSAccess.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grave.livejournal.com/friends?show=P&filter=0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1A94BA5A-0F0E-4571-98C3-618D59114BE3} - C:\WINDOWS\system32\pmkji.dll (file missing)
O2 - BHO: (no name) - {2E2A8507-459E-4903-AB02-9CD4A36E9977} - C:\WINDOWS\system32\ssqpm.dll (file missing)
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1112078643\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] "C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://ibhost.dancik.com/download/combo1.0.6.0614.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://download.games.yahoo.com/games/web_…itched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://www.shockwave.com/content/sandscrip…pt.1.0.0.21.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://www.shockwave.com/content/sweetopia…ia.1.0.0.22.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: pmkji - C:\WINDOWS\system32\pmkji.dll (file missing)
O20 - Winlogon Notify: ssqnklm - ssqnklm.dll (file missing)
O20 - Winlogon Notify: winjyg32 - winjyg32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\WINDOWS\system32\NMSAccess.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Sorry but seeing your ComboFix.txt tells me that I need to see a list of programs on your system. There are some not so good ones.

Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
Here you go! A+ CBT for Managing and Maintaining Your PC, Third Edition Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Flash Player ActiveX Adobe Photoshop Album Starter Edition Adobe Reader 6.0 Adobe Shockwave Player Agere Systems PCI Soft Modem AOL Instant Messenger Apple Software Update ArcSoft PhotoStudio 5.5 avast! Antivirus Battle.net BellSouth Application Management BellSouth FastAccess DSL Help Center BellSouth Internet Security - Alert Manager 1.5.11 BellSouth Toolbar 1.0 Bullseye Caesar 3 Canon MP Navigator 2.0 Canon MP150 Canon Utilities Easy-PhotoPrint CEP - Color Enable Package Cheetah DVD Burner clown_screen Screen Saver Collapse! Deluxe Compaq Connections Compaq Instant Support Compaq Organize DAEMON Tools darkarts2_screen Screen Saver Dawn of the Dead - Screensaver 2 Diablo Direct Show Ogg Vorbis Filter (remove only) DVD Shrink 3.2 DVDFab Decrypter 2.9.8.3 Easy Internet Sign-up Easy-WebPrint EVEREST Home Edition v2.01 EZface ActiveX 203 FreeThrow GameShark Media Manager for PSP GoPets Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format SDK (KB902344) HP Deskjet Preloaded Printer Drivers HP Image Zone 3.5 HP Photo & Imaging 3.5 - HP Devices HP PSC & OfficeJet 3.0 HP Software Update IntelliMover Data Transfer Demo InterActual Player InterVideo WinDVD Creator 2 InterVideo WinDVD Player iTunes J2SE Runtime Environment 5.0 Update 3 Java 2 Runtime Environment, SE v1.4.2_03 JEOPARDY! (remove only) KBD Learn2 Player (Uninstall Only) LimeWire 4.12.11 LiveReg (Symantec Corporation) LiveUpdate 1.80 (Symantec Corporation) MagicBall Mah Jong Tiles Deluxe Max Media Creator MaxDrive PS2 Memorex exPressit Label Design Studio Memories Disc Creator 2.0 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 2.0 Microsoft Learning and Research Plus Support Files Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office Standard Edition 2003 Microsoft Office XP Professional with FrontPage Microsoft Picture It! Express 7.0 Microsoft Picture It! Publishing Platinum 2001 Microsoft Plus! Digital Media Edition Microsoft Works 7.0 MSN Internet Software MSN Messenger 5.0 MSXML4 Parser Multimedia Card Reader Musicmatch® Jukebox MySpaceIM NVIDIA GART Driver Paint Shop Pro 7 Anniversary Edition PC-Doctor for Windows Pharaoh and Cleopatra Photosmart 140,240,7200,7600,7700,7900 Series PrintMaster Gold 3.00 PS2 Python 2.2 combined Win32 extensions Python 2.2.1 QuickTime RealPlayer RecordNow! Rockstar Custom Tracks 1.0 S3 S3Display S3 S3Gamma2 S3 S3Info2 S3 S3Overlay Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB928843) Semagic (remove only) Shanghai Shockwave SimPE 0.60b (alpha) Sims2Pack Clean Installer Sonic Update Manager Spybot - Search & Destroy 1.4 TextTwist Deluxe The Black Mirror 1.0 The Simpsons Movie Screen Saver The Sims 2 The Sims 2 Family Fun Stuff The Sims 2 Glamour Life Stuff The Sims 2 HomeCrafter Plus The Sims 2 Nightlife The Sims 2 Open For Business The Sims 2 Pets The Sims 2 University The Sims Art Studio The Sims Complete Collection The Sims File Cop The Sims™ 2 Celebration! Stuff The Sims™ 2 Seasons Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) VIA Rhine-Family Fast Ethernet Adapter VIA/S3G Display Driver VideoLAN VLC media player 0.8.5 Viewpoint Media Player Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB884020 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver Yahoo! extras Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Messenger Explorer Bar Yahoo! Toolbar Zeus & Poseidon ZoneAlarm
A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O2 - BHO: (no name) - {1A94BA5A-0F0E-4571-98C3-618D59114BE3} - C:\WINDOWS\system32\pmkji.dll (file missing)
    O2 - BHO: (no name) - {2E2A8507-459E-4903-AB02-9CD4A36E9977} - C:\WINDOWS\system32\ssqpm.dll (file missing)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O20 - Winlogon Notify: pmkji - C:\WINDOWS\system32\pmkji.dll (file missing)
    O20 - Winlogon Notify: ssqnklm - ssqnklm.dll (file missing)
    O20 - Winlogon Notify: winjyg32 - winjyg32.dll (file missing)


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\sdbackup.reg
C:\WINDOWS\system32\eoaxqsjq.dll
C:\WINDOWS\ALCXMNTR.EXE

Folder::
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
C:\Program Files\PeoplePC


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
OK, here you go.. though the clock in my taskbar did not reappear after reboot. is this normal?


ComboFix 07-08-22.1 - "Owner" 2007-08-21 23:33:49.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.189 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\sdbackup.reg
C:\WINDOWS\system32\eoaxqsjq.dll
C:\WINDOWS\ALCXMNTR.EXE



Logfile of HijackThis v1.99.1
Scan saved at 00:01, on 2007-08-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\NMSAccess.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\ComboFix\catchme.cfexe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grave.livejournal.com/friends?show=P&filter=0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1112078643\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] "C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" /AUTORUN
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://ibhost.dancik.com/download/combo1.0.6.0614.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://download.games.yahoo.com/games/web_…itched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://www.shockwave.com/content/sandscrip…pt.1.0.0.21.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://www.shockwave.com/content/sweetopia…ia.1.0.0.22.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\WINDOWS\system32\NMSAccess.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi again.. well the only file i found was C:\combofix2.txt ..and here it is


ComboFix 07-08-22.1 - "Owner" 2007-08-21 22:00:49.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.222 [GMT -4:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\kernel32.exe


((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))


2007-08-21 21:02 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-21 10:52 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-08-21 10:52 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-08-21 10:52 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-08-21 10:52 4,212 –ah—– C:\WINDOWS\system32\zllictbl.dat
2007-08-21 10:52 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-08-21 10:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-21 10:51 739,360 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-21 10:51 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-08-21 10:51 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-08-21 10:51 d——– C:\WINDOWS\system32\ZoneLabs
2007-08-21 10:50 d——– C:\WINDOWS\Internet Logs
2007-08-21 09:51 d——– C:\VundoFix Backups
2007-08-21 07:33 87,616 –a—— C:\WINDOWS\system32\eoaxqsjq.dll
2007-08-20 09:31 1,819 –a—— C:\WINDOWS\system32\sdbackup.reg
2007-08-20 01:08 5,248 –a—— C:\WINDOWS\system32\drivers\d347prt.sys
2007-08-20 01:08 155,136 –a—— C:\WINDOWS\system32\drivers\d347bus.sys
2007-08-20 01:08 d——– C:\Program Files\D-Tools
2007-08-18 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\ashampoo
2007-08-15 18:50 d——– C:\DOCUME~1\Owner\APPLIC~1\uTorrent
2007-08-13 15:26 d——– C:\Program Files\ACTIMAGE
2007-08-05 22:00 d——– C:\WINDOWS\system32\NtmsData
2007-08-02 17:16 d——– C:\DOCUME~1\Owner\APPLIC~1\iWin
2007-08-02 05:58 d——– C:\Program Files\QuickTime
2007-08-02 05:57 d——– C:\Program Files\Apple Software Update
2007-08-02 05:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-29 19:34 d——– C:\Program Files\MySpace
2007-07-29 19:34 d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\MySpace


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 20:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\uTorrent
2007-08-21 10:55 1484 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-21 10:13 ——— d——– C:\Program Files\Yahoo! Games
2007-08-21 10:12 ——— d——– C:\Program Files\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:10 ——— d——– C:\Program Files\Jig Words
2007-08-21 05:10 ——— d——– C:\Program Files\EA GAMES
2007-08-15 18:51 ——— d——– C:\Program Files\uTorrent
2007-08-12 23:19 ——— d——– C:\Program Files\Semagic
2007-08-12 18:32 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\dvdcss
2007-08-11 11:48 ——— d——– C:\Program Files\Quake III Arena
2007-08-09 16:30 ——— d——– C:\Program Files\Microsoft Picture It! PhotoPub
2007-08-05 18:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Apple Computer
2007-08-02 05:57 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-01 18:37 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\LimeWire
2007-07-22 20:45 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Canon
2007-07-20 11:36 ——— d——– C:\Program Files\Common Files\Motive
2007-07-17 07:17 532480 –a—— C:\WINDOWS\system32\The Simpsons Movie.scr
2007-07-14 03:18 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-07-12 10:08 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
2007-07-09 07:24 ——— d——– C:\Program Files\The Adventure Company
2007-06-30 15:04 ——— d——– C:\Program Files\BurnQuick
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-24 23:47 ——— dr-h—– C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-06-24 23:47 ——— d——– C:\Program Files\Yahoo!
2007-06-24 20:22 737280 –a—— C:\WINDOWS\iun6002.exe
2007-06-24 20:22 57344 –a—— C:\WINDOWS\system32\WNASPINT.DLL
2007-06-24 19:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-23 18:16 ——— d——– C:\Program Files\PeoplePC
2007-06-21 23:59 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-06-15 12:00 66269 –a—— C:\Program Files\INSTALL.LOG
2005-02-01 06:39:56 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A94BA5A-0F0E-4571-98C3-618D59114BE3}]
C:\WINDOWS\system32\pmkji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E2A8507-459E-4903-AB02-9CD4A36E9977}]
C:\WINDOWS\system32\ssqpm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 C:\WINDOWS\system32\VTTimer.exe]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 12:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-09-06 09:29]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 14:14]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 11:17]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 20:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" []
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" []
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 14:03]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 12:16]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 07:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 07:15]
"HostManager"="C:\Program Files\Common Files\AOL\1112078643\EE\AOLHostManager.exe" []
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" [2007-01-28 12:14]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-01-15 13:28]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"svhost"="C:\WINDOWS\svhost.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkji]
C:\WINDOWS\system32\pmkji.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnklm]
ssqnklm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winjyg32]
winjyg32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)

S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINDOWS\system32\DRIVERS\usbscan.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 22:09:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 22:10:22
C:\ComboFix-quarantined-files.txt … 2007-08-21 22:10

— E O F —
Please DELETE your current version of ComboFix and download a newer version from HERE

Save it to your desktop.

Now run the CFScript that I posted last and post the finished log.

Trevuren
Done and done, here you are! By the way, thanks for all your help, I really do appreciate your time!


ComboFix 07-08-22.1 - "Owner" 2007-08-22 0:47:33.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.222 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\sdbackup.reg
C:\WINDOWS\system32\eoaxqsjq.dll
C:\WINDOWS\ALCXMNTR.EXE


((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))


2007-08-21 21:02 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-21 10:52 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-08-21 10:52 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-08-21 10:52 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-08-21 10:52 4,212 –ah—– C:\WINDOWS\system32\zllictbl.dat
2007-08-21 10:52 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-08-21 10:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-21 10:51 739,360 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-21 10:51 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-08-21 10:51 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-08-21 10:51 d——– C:\WINDOWS\system32\ZoneLabs
2007-08-21 10:50 d——– C:\WINDOWS\Internet Logs
2007-08-21 09:51 d——– C:\VundoFix Backups
2007-08-20 01:08 5,248 –a—— C:\WINDOWS\system32\drivers\d347prt.sys
2007-08-20 01:08 155,136 –a—— C:\WINDOWS\system32\drivers\d347bus.sys
2007-08-20 01:08 d——– C:\Program Files\D-Tools
2007-08-18 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\ashampoo
2007-08-15 18:50 d——– C:\DOCUME~1\Owner\APPLIC~1\uTorrent
2007-08-13 15:26 d——– C:\Program Files\ACTIMAGE
2007-08-05 22:00 d——– C:\WINDOWS\system32\NtmsData
2007-08-02 17:16 d——– C:\DOCUME~1\Owner\APPLIC~1\iWin
2007-08-02 05:58 d——– C:\Program Files\QuickTime
2007-08-02 05:57 d——– C:\Program Files\Apple Software Update
2007-08-02 05:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-29 19:34 d——– C:\Program Files\MySpace
2007-07-29 19:34 d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\MySpace


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 23:43 3524 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-21 20:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\uTorrent
2007-08-21 10:13 ——— d——– C:\Program Files\Yahoo! Games
2007-08-21 10:12 ——— d——– C:\Program Files\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-08-21 10:10 ——— d——– C:\Program Files\Jig Words
2007-08-21 05:10 ——— d——– C:\Program Files\EA GAMES
2007-08-15 18:51 ——— d——– C:\Program Files\uTorrent
2007-08-12 23:19 ——— d——– C:\Program Files\Semagic
2007-08-12 18:32 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\dvdcss
2007-08-11 11:48 ——— d——– C:\Program Files\Quake III Arena
2007-08-09 16:30 ——— d——– C:\Program Files\Microsoft Picture It! PhotoPub
2007-08-05 18:55 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Apple Computer
2007-08-02 05:57 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-01 18:37 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\LimeWire
2007-07-22 20:45 ——— d——– C:\DOCUME~1\HELLHO~1\APPLIC~1\Canon
2007-07-20 11:36 ——— d——– C:\Program Files\Common Files\Motive
2007-07-17 07:17 532480 –a—— C:\WINDOWS\system32\The Simpsons Movie.scr
2007-07-14 03:18 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-07-12 10:08 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
2007-07-09 07:24 ——— d——– C:\Program Files\The Adventure Company
2007-06-30 15:04 ——— d——– C:\Program Files\BurnQuick
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-28 19:53 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-06-24 23:47 ——— dr-h—– C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-06-24 23:47 ——— d——– C:\Program Files\Yahoo!
2007-06-24 20:22 57344 –a—— C:\WINDOWS\system32\WNASPINT.DLL
2007-06-24 19:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-06-15 12:00 66269 –a—— C:\Program Files\INSTALL.LOG
2005-02-01 06:39:56 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 C:\WINDOWS\system32\VTTimer.exe]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 12:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-09-06 09:29]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 14:14]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 11:17]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 20:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" []
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" []
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 14:03]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 12:16]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 07:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 07:15]
"HostManager"="C:\Program Files\Common Files\AOL\1112078643\EE\AOLHostManager.exe" []
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" [2007-01-28 12:14]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-01-15 13:28]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)

S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINDOWS\system32\DRIVERS\usbscan.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-22 00:52:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-22 0:54:09
C:\ComboFix-quarantined-files.txt … 2007-08-22 00:54
C:\ComboFix2.txt … 2007-08-21 22:10

— E O F —
Your log looks clean. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
there doesn't seem to be anything suspicious going on at all anymore. browsing is completely normal and there aren't anymore annoying popups! we can proceed..
Congratulations, your log looks CLEAN

There are a few things you must do once you are completely clean:

1. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.

2. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

3. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI