This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijackthis log ...need help.

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

2 problems will have to be solved before i can do this:

1.

Avenger.exe now comes up with and eroor of some sort saying" integrity check failed!This file has been modified. Reason might be a possible virus infection.



2. I cant open task manager…..it says my administrator disabled it, i believe i told you that in my first post,

since i cant re install avenger….what would be a fix?

task manager? is there reg key i can edit and make it enabled instead of disabled? or a setting somewhere that i can change it to enabled…..REG KEY change would proboly be easier.
Lets do this…….

Download combofix.exe from the link below:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click combofix.exe & follow the prompts.
A window will open with a warning.
Type "Y" (and Enter) to start the fix.
When the scan completes it will open a text window.
Please attach that log back here together with a fresh HJT log.
Caution - do not touch your mouse/keyboard until the scan has completed.
The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt

Post a fresh HJT log and the log from ComboFix, MrC
alright heres the logs,let me know whats next. hard to watch football and do this at the same time…Dallas better pick it up.
EDIT: TaskManager WORKS!!!!!!!!!!!!! MrC your the man, hopefully there aint to much more to do.



ComboFIx Log

ComboFix 07-10-12.4 - Pepsi or Coke 2007-10-14 16:47:14.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\Downloads\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\d.exe
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin1.zip
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\bck1.dat
C:\WINDOWS\bck1.dat
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\winh32.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_ASC3550O
——-\LEGACY_NTMLSVC
——-\NtmlSvc


((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
.

2007-10-14 16:52 158,432 –a—— C:\WINDOWS\system32\48537aca.sys
2007-10-14 16:46 57,856 –a—— C:\WINDOWS\NirCmd.exe
2007-10-14 15:18 158,432 –a—— C:\WINDOWS\system32\6d38306d.sys
2007-10-14 14:23 51,921 –a—— C:\WINDOWS\system32\detectd2.exe
2007-10-14 14:23 50,176 –a—— C:\WINDOWS\system32\sockver2.dll
2007-10-14 14:23 34,844 –a—— C:\uuuj.exe
2007-10-14 11:04 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-14 11:04 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-14 11:04 61,440 –a—— C:\WINDOWS\system32\Process.exe
2007-10-14 11:04 35,840 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-14 10:54 158,496 –a—— C:\WINDOWS\system32\90dbebfb.sys
2007-10-14 10:54 50,176 –a—— C:\WINDOWS\system32\sockver1.dll
2007-10-14 10:54 39,941 –a—— C:\WINDOWS\system32\conf.dat
2007-10-14 10:53 d——– C:\Program Files\SUPERAntiSpyware
2007-10-14 10:53 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\SUPERAntiSpyware.com
2007-10-14 10:53 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-13 16:08 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Abra Academy2
2007-10-13 12:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-13 03:18 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-13 03:17 d——– C:\WINDOWS\system32\acespy
2007-10-12 17:22 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\ForgottenRiddles
2007-10-12 16:02 d——– C:\Program Files\iWin Games
2007-10-12 15:34 d——– C:\Program Files\Profitville_at
2007-10-12 15:27 d——– C:\Program Files\PiratePoppers_at
2007-10-11 13:47 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Gearbox Software
2007-10-11 06:09 d——– C:\Program Files\Wise Registry Cleaner
2007-10-11 06:09 d——– C:\Program Files\Wise Disk Cleaner
2007-10-11 03:56 d—s—- C:\Documents and Settings\Pepsi or Coke\UserData
2007-10-11 03:54 d——– C:\WINDOWS\SxsCaPendDel
2007-10-11 03:20 d——– C:\WINDOWS\system32\AGEIA
2007-10-11 03:20 d——– C:\Program Files\AGEIA Technologies
2007-10-11 03:19 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-10 15:58 d——– C:\Program Files\Cannon Blast
2007-10-10 12:23 d——– C:\Program Files\Windows Installer Clean Up
2007-10-10 12:23 d——– C:\Program Files\MSECACHE
2007-10-10 07:52 d——– C:\Program Files\SystemRequirementsLab
2007-10-10 07:51 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\SystemRequirementsLab
2007-10-09 18:49 153 –a—— C:\WINDOWS\system32\delFSF.bat
2007-10-08 18:44 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\PlayFirst
2007-10-08 18:44 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-08 10:34 27,648 –a—— C:\whekdwjb.exe
2007-10-08 10:34 19,456 –a—— C:\dcksdix.exe
2007-10-07 20:06 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Big Fish Games
2007-10-07 19:33 9,216 –a—— C:\WINDOWS\_MSRSTRT.EXE
2007-10-07 11:08 d——– C:\Program Files\Ubisoft
2007-10-06 19:27 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Legends of pirates
2007-10-05 17:07 438,272 –a—— C:\WINDOWS\system32\vp6vfw.dll
2007-10-05 17:07 118,832 –a—— C:\WINDOWS\system32\SHW32.DLL
2007-10-05 17:01 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-10-05 17:01 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-10-05 17:01 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-10-05 17:01 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-10-05 17:01 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-10-05 17:01 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-10-05 17:01 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-10-05 14:08 dr-h—– C:\Documents and Settings\Pepsi or Coke\Application Data\SecuROM
2007-10-05 14:08 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-10-05 14:00 d——– C:\Program Files\EA Sports
2007-10-05 12:02 d——– C:\Program Files\USB TWIN SHOCK
2007-10-05 12:02 344,064 –a—— C:\WINDOWS\Property.exe
2007-10-05 12:02 291,840 –a—— C:\WINDOWS\FCVAP64.dll
2007-10-05 12:02 163,904 –a—— C:\WINDOWS\GetWinVer.exe
2007-10-05 12:02 152,064 –a—— C:\WINDOWS\setreg.exe
2007-10-05 12:02 86,016 –a—— C:\WINDOWS\EZFRD64.dll
2007-10-05 08:14 d——– C:\Program Files\PowerISO
2007-10-04 09:07 d——– C:\Documents and Settings\All Users\Application Data\RealArcade
2007-10-02 16:00 d——– C:\Documents and Settings\All Users\Application Data\55-68-q8-17-55-4p
2007-09-29 20:54 d–hs—- C:\WINDOWS\ftpcache
2007-09-24 17:59 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Pogo Games
2007-09-23 01:11 d——– C:\Program Files\Common Files\LogiShrd
2007-09-15 19:40 d——– C:\Program Files\Star Defender 4
2007-09-14 22:20 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-09-14 22:12 602,112 ——— C:\WINDOWS\system32\ati2sgag.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-14 18:51 ——— d—–w C:\Program Files\Shockwave.com
2007-10-14 17:55 ——— d—–w C:\Program Files\Games
2007-10-14 14:43 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Azureus
2007-10-13 21:08 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-13 19:47 ——— d—–w C:\Program Files\iWin.com
2007-10-12 22:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\7Wonders2
2007-10-12 19:58 ——— d—–w C:\Program Files\Oberon Media
2007-10-11 08:29 ——— d—–w C:\Program Files\GHOSTHunters_at
2007-10-11 08:27 ——— d—–w C:\Program Files\Azureus
2007-10-11 07:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-10 19:34 ——— d—–w C:\Program Files\Common Files\Real
2007-10-10 19:05 ——— d—–w C:\Program Files\Common Files\Labtec
2007-10-10 18:59 ——— d—–w C:\Program Files\GameHouse
2007-10-10 11:38 ——— d—–w C:\Program Files\Full Tilt Poker
2007-10-10 09:07 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-07 20:47 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\LimeWire
2007-10-04 19:11 ——— d–h–r C:\Documents and Settings\Pepsi or Coke\Application Data\yahoo!
2007-10-04 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-04 19:09 ——— d—–w C:\Program Files\Yahoo!
2007-10-01 10:55 ——— d—–w C:\Program Files\America's Army
2007-09-23 05:11 ——— d—–w C:\Program Files\Labtec
2007-09-15 02:22 ——— d—–w C:\Program Files\Creative
2007-09-15 02:06 ——— d—–w C:\Program Files\Driver Cleaner Pro
2007-09-14 14:03 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\GameHouse
2007-09-13 18:58 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\pixelStorm
2007-09-13 17:39 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\AlwaysNeat
2007-09-13 04:45 ——— d—–w C:\Program Files\LimeWire
2007-09-12 17:43 ——— d—–w C:\Program Files\MSXML 4.0
2007-09-11 15:12 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-09-11 15:12 ——— d—–w C:\Program Files\Real
2007-09-11 12:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\iWin Games
2007-09-10 14:35 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\vlc
2007-09-10 14:34 ——— d—–w C:\Program Files\VideoLAN
2007-09-09 22:20 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\iWin
2007-09-09 22:11 ——— d—–w C:\Program Files\Mysteryville
2007-09-09 21:02 ——— d—–w C:\Program Files\ReflexiveArcade
2007-09-09 19:26 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\SpinTop
2007-09-09 18:27 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Mysteryville2
2007-09-09 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-09-09 03:36 ——— d—–w C:\Program Files\MSN Messenger
2007-09-09 00:21 ——— d—–w C:\Program Files\NEC DISPLAY SOLUTIONS
2007-09-08 22:13 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\atitray
2007-09-08 22:12 ——— d—–w C:\Program Files\Ray Adams
2007-09-08 20:22 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-09-08 19:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2007-09-08 10:55 ——— d—–w C:\Program Files\Java
2007-09-08 10:54 ——— d—–w C:\Program Files\Common Files\Java
2007-09-07 22:47 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Creative
2007-09-07 22:21 ——— d—–w C:\Program Files\Trend Micro
2007-09-07 22:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro
2007-09-07 22:02 ——— d—–w C:\Program Files\microsoft frontpage
2007-08-22 02:33 46,432 —-a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-08-22 02:07 2,417,664 —-a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-08-22 01:13 49,152 —-a-w C:\WINDOWS\system32\drivers\ati2erec.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-08-25 11:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 17:48]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 08:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-08-18 13:06]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sysfldr]
sysfldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Program Files\Labtec\WebCam10\WebCam10.exe" /hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"LVSrvLauncher"=2 (0x2)

R1 atitray;atitray;\??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command - E:\Autorun.exe

.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-14 16:52:25
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-14 16:56:16 - machine was rebooted
.
— E O F —


Hijackthis log


Logfile of HijackThis v1.99.1
Scan saved at 5:01:50 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: sysfldr - sysfldr.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Just get this one:


Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items if found:

O20 - Winlogon Notify: sysfldr - sysfldr.dll (file missing)

Click on Fix Checked and exit HijackThis.


Reboot and post a fresh HijackThis log and we'll take another look.

Please let me know how it's running, MrC
here it is….any tips on keeping my pc clean if this is my last step ? currently im running PCcillin….seemed like a decent protection program till now Logfile of HijackThis v1.99.1 Scan saved at 5:18:31 PM, on 10/14/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Looks OK.

I may have you delete some more files after I carefully look at your ComboFix log….so don't delete ComboFix yet.

——————

Here's my Preventive Maintenance tips:

————–

Some Preventive Maintenance:

Some of the programs you may have run create backups of what was deleted - you can safely delete them now: (delete folders in blue) You can also delete/uninstall the programs themselves.

C:\!KillBox (KillBox)
C:\VundoFix Backups (VundoFix)
C:\QooBox (ComboFix)
C:\SDFix\backups\backups.zip (SDFix)
C:\avenger\backup.zip (Avenger)

If you used AVG Anti-Spyware and/or SuperAntiSpyware………..

Open up SuperAntiSpyware > Preferences > General and Start-up > Start-up Options > Uncheck > Start SAS when Windows Starts.
"SAS free" provides no real time protection so there's no need for it to be running, I suggest you keep the program and update regularly - you can use it to scan for malware. It's an excellent program. When you want to start it - just double click on the SAS icon.

AVG Anti-Spyware will provide 30 days of real time protection and then after that you can use it to scan for malware - you'll have to manually update it first.


——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point (XP only):

Note: This will remove all previous Restore Points!

1. Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer,

2. Turn on System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UnCheck Turn off System Restore.
Click Apply, and then click OK.

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File
Direct Download - MVPS HOSTS <==> MVPS HOSTS Tutorial

Need a free anti virus?
AVG*free
Avast Free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
Windows firewall is not suffient…install a better one.
Comodo Free Firewall
ZoneAlarm*free
Other free firewalls

Keep those temp files off your system use
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected"
or
CCleaner
Uncheck "Cookies" under "Internet Explorer".
That will clear out all the temp files on the system.

IMPORTANT!!
Keep your Sun Java up-to-date JRE Version 6 Update 3<–newest version
Delete ALL old versions from add/remove programs if listed first!
Check HERE

Keep the registry backed up - use ERUNT
Print this out and save it
ERUNT Tutorial

Starter Manage you startup programs and services.

———-Free malware removal programs:———-

AVG Anti-Spyware<—VERY GOOD! (XP and 2K only)
SUPERAntiSpyware (free edition)<—Excellent!
AVG Anti-Rootkit Free Edition Run it!!
SpyBot
AD-Aware
CW-Shredder

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable "Windows Messenger Service" XP - 2K (stops pop-up ads -etc):
Shoot The Messenger

Anti-Rootkit Software - Detection, Removal & Protection

Reduce Online Fraud

Slow Computer - Check Here

Don't open e-mail attachments without first scanning them with an up-to-date anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Don't believe e-mails from your bank, financial institution, etc asking for personal informations - they're most likely fraudulent no matter how authentic they look.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

I'll get back to you tomorrow on any other files we have to delete, MrC
thanks alot man, ill be keeping this thread bookmarked for a long time…incase this happens again.I'll follow your steps to keep it clean. ill be checking back tomorrow.
OK, here's the files from ComboFix that have to be deleted.
Use the Avenger….you should download and install a fresh copy since you had trouble with the first one…….here's the code:


2. Copy all the text contained in the code box below to your Clipboard by highlighting it, then right click on it and choose Copy [or by pressing (Ctrl+C)]:


Files to delete:
C:\WINDOWS\system32\48537aca.sys
C:\WINDOWS\system32\6d38306d.sys
 C:\WINDOWS\system32\detectd2.exe
C:\WINDOWS\system32\sockver2.dll
 C:\WINDOWS\system32\90dbebfb.sys
 C:\WINDOWS\system32\sockver1.dll
 C:\WINDOWS\system32\stfv.bin
 C:\WINDOWS\system32\delFSF.bat
 C:\whekdwjb.exe
 C:\dcksdix.exe
C:\uuuj.exe

3. Now, start The Avenger program by clicking on its icon on your desktop.

* Under "Script file to execute" choose "Input Script Manually".
* Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
* Right click in the new window and choose Paste or use (Ctrl+V). This will paste the text from the clipboard into the new window.
* Click Done
* Now click on the Green Light to begin execution of the script
* Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

* It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
* On reboot, it will briefly open a black command window on your desktop, this is normal.
* After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
* The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

Let me know, MrC
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI