Lots of pop ups about computer at risk, changed wallpater, etc.
9 min read
thats a log from sdfix, not hjt. sounds like the classic symptoms of smithfraud.
ok two downloads to get: the first one we will use in SAFE MODE:
Download SmitfraudFix (by S!Ri) to your Desktop:
http://www.bleepingcomputer.com/files/smitfraudfix.php
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
—————————————
you might want to copy/paste this into notepad and save it so you can read it in safe mode:
boot computer into safe mode.
to reach safe mode: restart your computer and tap the f8 key during the boot up. chose the first option from the list: safe mode. log on the your regular account.
once at the safe mode desktop:
Open the SmitfraudFix Folder–then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
——————————————
next get and run a copy of hjt:
HiJackThis log - Trend Micro HijackThis 2.0.2
http://www.trendsecure.com/portal/en-US/th…/HJTInstall.exe
* Save HJTInstall.exe to your desktop.
* Doubleclick on the HJTInstall.exe icon on your desktop.
* By default it will install to C:\Program Files\Trend Micro\HijackThis .
* Click on Install.
* It will create a HijackThis icon on the desktop.
* Once installed, it will launch Hijackthis.
* Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
* Click on "Edit > Select All" then click on "Edit > Copy" and Paste the entire contents of the log (no attachments) in your next reply.
please provide the smitfraud log and a new hjt log.
shelf life
hi flashsrus,
thats a log from sdfix, not hjt. sounds like the classic symptoms of smithfraud.
ok two downloads to get: the first one we will use in SAFE MODE:
Download SmitfraudFix (by S!Ri) to your Desktop:
http://www.bleepingcomputer.com/files/smitfraudfix.php
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
—————————————
you might want to copy/paste this into notepad and save it so you can read it in safe mode:
boot computer into safe mode.
to reach safe mode: restart your computer and tap the f8 key during the boot up. chose the first option from the list: safe mode. log on the your regular account.
once at the safe mode desktop:
Open the SmitfraudFix Folder–then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
——————————————
next get and run a copy of hjt:
HiJackThis log - Trend Micro HijackThis 2.0.2
http://www.trendsecure.com/portal/en-US/th…/HJTInstall.exe
* Save HJTInstall.exe to your desktop.
* Doubleclick on the HJTInstall.exe icon on your desktop.
* By default it will install to C:\Program Files\Trend Micro\HijackThis .
* Click on Install.
* It will create a HijackThis icon on the desktop.
* Once installed, it will launch Hijackthis.
* Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
* Click on "Edit > Select All" then click on "Edit > Copy" and Paste the entire contents of the log (no attachments) in your next reply.
please provide the smitfraud log and a new hjt log.
shelf life
Ok, here we go. Finally got loose to work on this. Here are the logs:
SmitFraudFix v2.240
Scan done at 21:14:32.53, Mon 10/22/2007
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ace16win.dll Deleted
C:\WINDOWS\system32\msole32.exe Deleted
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
________________________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:21:23 PM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\KARRI THOMPSON\Desktop\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [045e8745] rundll32.exe "C:\WINDOWS\system32\sacesywd.dll",sitypnow
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 6700 bytes
ok good. one more download to get:
Please download ComboFix (by sUBs) from one of the following links:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Save it to the Desktop.
Double-click combofix.exe and follow the prompts.
CAUTION: Do not mouse-click ComboFix's window while it is running.
It may cause it to stall.
When finished, it produces a log.
Please provide the contents of the ComboFix log in your reply–
shelf life
ComboFix 07-10-23.2 - Administrator 2007-10-24 7:02:02.2 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.391 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\KARRI THOMPSON\Application Data\ECURIT~1\?ecurity\
C:\Documents and Settings\KARRI THOMPSON\Desktop\internet.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\ISM\archupd.exe
C:\Program Files\ISM\BndDrive7.dll
C:\Program Files\ISM\dictionary.gz
C:\Program Files\ISM\ISMModule7.exe
C:\Program Files\ISM\targets.gz
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\ISM2\cringupd.exe
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\ISMPack5.exe
C:\Program Files\ISM2\ISMPack7.exe
C:\Program Files\ISM2\targets.gz
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\awtsq.dll
C:\WINDOWS\system32\drivers\bg_bg.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\close_ico.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\icon_warning_big.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\remove_spyware_header.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\spyware_detected.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_ico.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
C:\WINDOWS\system32\dtuaimvw.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\hdgrxfpu.dll
C:\WINDOWS\system32\lvtenvsl.dll
C:\WINDOWS\system32\nusrmgr.exe
C:\WINDOWS\system32\oembios32.dll
C:\WINDOWS\system32\oyodfrdb.dll
C:\WINDOWS\system32\pppatc~1\w?auclt.exe
C:\WINDOWS\system32\qstwa.bak1
C:\WINDOWS\system32\qstwa.bak2
C:\WINDOWS\system32\qstwa.ini
C:\WINDOWS\system32\qstwa.ini2
C:\WINDOWS\system32\qstwa.tmp
C:\WINDOWS\system32\smdjpjfw.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnstssv32.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
—- Previous Run ——-
.
C:\Documents and Settings\KARRI THOMPSON\Application Data\DOBE~1
C:\Documents and Settings\KARRI THOMPSON\Application Data\ECURIT~1
C:\Documents and Settings\KARRI THOMPSON\Application Data\ECURIT~1\?ecurity\
C:\Documents and Settings\KARRI THOMPSON\Application Data\ICROSO~1.NET
C:\Documents and Settings\KARRI THOMPSON\Desktop\internet.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Outerinfo
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\crosof~1
C:\Program Files\dobe~1
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\ISM
C:\Program Files\ISM\archupd.exe
C:\Program Files\ISM\BndDrive7.dll
C:\Program Files\ISM\dictionary.gz
C:\Program Files\ISM\ISMModule7.exe
C:\Program Files\ISM\targets.gz
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\ISM2
C:\Program Files\ISM2\cringupd.exe
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\ISMPack5.exe
C:\Program Files\ISM2\ISMPack7.exe
C:\Program Files\ISM2\targets.gz
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\ppatch~1
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\drivers\bg_bg.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\close_ico.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\icon_warning_big.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\remove_spyware_header.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\spyware_detected.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_ico.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
C:\WINDOWS\system32\dtuaimvw.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\hdgrxfpu.dll
C:\WINDOWS\system32\lvtenvsl.dll
C:\WINDOWS\system32\nusrmgr.exe
C:\WINDOWS\system32\oembios32.dll
C:\WINDOWS\system32\oyodfrdb.dll
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~1\w?auclt.exe
C:\WINDOWS\system32\qstwa.bak1
C:\WINDOWS\system32\qstwa.bak2
C:\WINDOWS\system32\qstwa.ini
C:\WINDOWS\system32\qstwa.ini2
C:\WINDOWS\system32\qstwa.tmp
C:\WINDOWS\system32\smdjpjfw.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnstssv32.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-24 to 2007-10-24 )))))))))))))))))))))))))))))))
.
2007-10-24 06:29 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-22 21:14 3,858 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-22 20:53 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 20:53 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 20:53 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-22 20:53 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-22 20:53 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-18 12:12 83,008 –a—— C:\WINDOWS\system32\sacesywd.dll
2007-10-18 11:04 22,112 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-10-17 16:57 d——– C:\WINDOWS\ERUNT
2007-10-17 13:32 60,944,116 –a—— C:\registrybackup.reg
2007-10-16 14:55 d——– C:\Documents and Settings\KARRI THOMPSON\.housecall6.6
2007-10-16 14:05 d——– C:\WINDOWS\pss
2007-10-15 23:44 d–h—– C:\WINDOWS\PIF
2007-10-15 23:11 d——– C:\Program Files\Norton Internet Security
2007-10-15 23:05 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-15 23:05 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-15 22:57 d——– C:\Program Files\Symantec
2007-10-15 22:49 d——– C:\Program Files\Common Files\Symantec Shared
2007-10-15 21:58 d——– C:\Documents and Settings\KARRI THOMPSON\Application Data\Sammsoft
2007-10-15 21:54 d——– C:\Program Files\Advanced Registry Optimizer
2007-10-14 22:58 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-14 22:16 d——– C:\WINDOWS\system32\acespy
2007-10-14 22:08 376,832 –a—— C:\WINDOWS\system32\wvusqnk.dll
2007-10-14 21:58 376,832 –a—— C:\WINDOWS\system32\mljkhgf.dll
2007-10-14 12:41 26,069 –a—— C:\WINDOWS\system32\drivers\smss.exe
2007-10-14 12:41 26,069 –a—— C:\Documents and Settings\KARRI THOMPSON\smss.exe
2007-10-10 18:00 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-16 21:17 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-16 21:17 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 19:49 ——— d—–w C:\Program Files\Viewpoint
2007-09-19 02:35 ——— d—–w C:\Program Files\LimeWire
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 19:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 19:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 19:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 19:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 19:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 19:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 19:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-07-05 17:10:18 56 –sh–r C:\WINDOWS\system32\879F2A6573.sys
2007-07-05 17:10:21 3,766 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 07:36]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 11:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 11:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 11:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"SigmatelSysTrayApp"="stsystra.exe" [2005-08-24 00:42 C:\WINDOWS\stsystra.exe]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-08-01 17:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-12-08 03:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 13:46]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 13:46]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 12:06]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 21:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"045e8745"="C:\WINDOWS\system32\sacesywd.dll" [2007-10-18 12:12]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 03:24]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 20:39]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-08-22 10:45:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdaxu]
iifdaxu.dll
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-07-29 18:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-16 04:35:44 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - KARRI THOMPSON.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-24 07:07:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-24 7:09:25 - machine was rebooted
.
— E O F —
ok we are making progress. from what combofix found lets run another tool:
download and run vundofix.exe:
http://www.atribune.org/ccount/click.php?id=4
* Double-click VundoFix.exe to run it.
* Click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
—————————————-
ok after the above please run combofix once more and post:
the vundo log
the new combofix log
a new hjt log
shelf life
ComboFix 07-10-23.2 - Administrator 2007-10-24 16:48:59.3 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-24 to 2007-10-24 )))))))))))))))))))))))))))))))
.
2007-10-24 16:40 d——– C:\VundoFix Backups
2007-10-24 06:29 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-22 21:14 3,858 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-22 20:53 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 20:53 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 20:53 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-22 20:53 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-22 20:53 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-18 12:12 83,008 –a—— C:\WINDOWS\system32\sacesywd.dll
2007-10-18 11:04 22,112 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-10-17 16:57 d——– C:\WINDOWS\ERUNT
2007-10-17 13:32 60,944,116 –a—— C:\registrybackup.reg
2007-10-16 14:55 d——– C:\Documents and Settings\KARRI THOMPSON\.housecall6.6
2007-10-16 14:05 d——– C:\WINDOWS\pss
2007-10-15 23:44 d–h—– C:\WINDOWS\PIF
2007-10-15 23:11 d——– C:\Program Files\Norton Internet Security
2007-10-15 23:05 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-15 23:05 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-15 22:57 d——– C:\Program Files\Symantec
2007-10-15 22:49 d——– C:\Program Files\Common Files\Symantec Shared
2007-10-15 21:58 d——– C:\Documents and Settings\KARRI THOMPSON\Application Data\Sammsoft
2007-10-15 21:54 d——– C:\Program Files\Advanced Registry Optimizer
2007-10-14 22:58 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-14 22:16 d——– C:\WINDOWS\system32\acespy
2007-10-14 22:08 376,832 –a—— C:\WINDOWS\system32\wvusqnk.dll
2007-10-14 21:58 376,832 –a—— C:\WINDOWS\system32\mljkhgf.dll
2007-10-14 12:41 26,069 –a—— C:\WINDOWS\system32\drivers\smss.exe
2007-10-14 12:41 26,069 –a—— C:\Documents and Settings\KARRI THOMPSON\smss.exe
2007-10-10 18:00 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-16 21:17 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-16 21:17 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 19:49 ——— d—–w C:\Program Files\Viewpoint
2007-09-19 02:35 ——— d—–w C:\Program Files\LimeWire
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 19:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 19:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 19:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 19:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 19:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 19:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 19:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-08-22 13:12 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-05 17:10:18 56 –sh–r C:\WINDOWS\system32\879F2A6573.sys
2007-07-05 17:10:21 3,766 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 07:36]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 11:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 11:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 11:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"SigmatelSysTrayApp"="stsystra.exe" [2005-08-24 00:42 C:\WINDOWS\stsystra.exe]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-08-01 17:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-12-08 03:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 13:46]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 13:46]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 12:06]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 21:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"045e8745"="C:\WINDOWS\system32\sacesywd.dll" [2007-10-18 12:12]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 03:24]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 20:39]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-08-22 10:45:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdaxu]
iifdaxu.dll
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-07-29 18:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-16 04:35:44 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - KARRI THOMPSON.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-24 16:51:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-24 16:53:00
C:\ComboFix2.txt … 2007-10-24 07:09
.
— E O F —
____________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:46 PM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\KARRI THOMPSON\Desktop\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [045e8745] rundll32.exe "C:\WINDOWS\system32\sacesywd.dll",sitypnow
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: iifdaxu - iifdaxu.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 8945 bytes
ok thanks for the info. look in add/remove programs panel and uninstall: viewpoint manager and MyWay or My way Search Assistant
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked:
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
you can select all those 02 items that end in (no file)
O20 - Winlogon Notify: iifdaxu - iifdaxu.dll (file missing)
———————————————-
after the above, please reboot computer once, rescan and post:
a new hjt log
rerun combofix and post its log also.
shelf life
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:17:43 AM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\KARRI THOMPSON\Desktop\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AcademicPlanet
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [045e8745] rundll32.exe "C:\WINDOWS\system32\sacesywd.dll",sitypnow
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Sezk] C:\WINDOWS\system32\?ppPatch\w?auclt.exe
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\system32\drivers\smss.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\KARRI THOMPSON\smss.exe
O4 - HKCU\..\Run: [ISMModule7] "C:\Program Files\ISM\ISMModule7.exe"
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WebMail - {23790A05-C992-44A0-8DFB-BD882E68A9AE} - http://webmail.academicplanet.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 10198 bytes
_____________________________________________________________________
ComboFix 07-10-23.2 - KARRI THOMPSON 2007-10-25 8:19:57.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.37 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-25 to 2007-10-25 )))))))))))))))))))))))))))))))
.
2007-10-24 16:40 d——– C:\VundoFix Backups
2007-10-24 06:29 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-22 21:14 3,858 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-22 20:53 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 20:53 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 20:53 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-22 20:53 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-22 20:53 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-18 12:12 83,008 –a—— C:\WINDOWS\system32\sacesywd.dll
2007-10-18 11:04 22,112 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-10-17 16:57 d——– C:\WINDOWS\ERUNT
2007-10-17 13:32 60,944,116 –a—— C:\registrybackup.reg
2007-10-16 14:55 d——– C:\Documents and Settings\KARRI THOMPSON\.housecall6.6
2007-10-16 14:05 d——– C:\WINDOWS\pss
2007-10-15 23:44 d–h—– C:\WINDOWS\PIF
2007-10-15 23:11 d——– C:\Program Files\Norton Internet Security
2007-10-15 23:05 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-15 23:05 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-15 22:57 d——– C:\Program Files\Symantec
2007-10-15 22:49 d——– C:\Program Files\Common Files\Symantec Shared
2007-10-15 21:58 d——– C:\Documents and Settings\KARRI THOMPSON\Application Data\Sammsoft
2007-10-15 21:54 d——– C:\Program Files\Advanced Registry Optimizer
2007-10-14 22:58 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-14 22:16 d——– C:\WINDOWS\system32\acespy
2007-10-14 22:08 376,832 –a—— C:\WINDOWS\system32\wvusqnk.dll
2007-10-14 21:58 376,832 –a—— C:\WINDOWS\system32\mljkhgf.dll
2007-10-14 12:41 26,069 –a—— C:\WINDOWS\system32\drivers\smss.exe
2007-10-14 12:41 26,069 –a—— C:\Documents and Settings\KARRI THOMPSON\smss.exe
2007-10-10 18:00 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-16 21:17 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-16 21:17 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 19:49 ——— d—–w C:\Program Files\Viewpoint
2007-09-19 02:35 ——— d—–w C:\Program Files\LimeWire
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 19:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 19:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 19:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 19:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 19:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 19:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 19:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-08-22 13:12 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-05 17:10:18 56 –sh–r C:\WINDOWS\system32\879F2A6573.sys
2007-07-05 17:10:21 3,766 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 07:36]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 11:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 11:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 11:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"SigmatelSysTrayApp"="stsystra.exe" [2005-08-24 00:42 C:\WINDOWS\stsystra.exe]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-08-01 17:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-12-08 03:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 13:46]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 13:46]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 12:06]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 21:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"045e8745"="C:\WINDOWS\system32\sacesywd.dll" [2007-10-18 12:12]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 03:24]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 20:39]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Aim6"="" []
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"Sezk"="C:\WINDOWS\system32\?ppPatch\w?auclt.exe" []
"ISMModule7"="C:\Program Files\ISM\ISMModule7.exe" []
"AROReminder"="C:\Program Files\Advanced Registry Optimizer\aro.exe" [2007-07-23 09:34]
"ISMPack7"="C:\Program Files\ISM2\ISMPack7.exe" []
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-08-22 10:45:55]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-07-29 18:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-16 04:35:44 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - KARRI THOMPSON.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-25 08:25:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-25 8:26:07
C:\ComboFix2.txt … 2007-10-24 16:53
C:\ComboFix3.txt … 2007-10-24 07:09
.
— E O F —
ok thanks for the info. you still have some stuff going on though. looks like you have two antivirus? norton and trend micro?? if thats the case, only need one. two isnt better than one in this case. you can also uninstall Viewpoint or Viewpoint Manager via the add/remove programs panel
first we will use hjt, boot into safe mode and last : get another download to run
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked:
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O4 - HKCU\..\Run: [Sezk] C:\WINDOWS\system32\?ppPatch\w?auclt.exe
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\system32\drivers\smss.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\KARRI THOMPSON\smss.exe
O4 - HKCU\..\Run: [ISMModule7] "C:\Program Files\ISM\ISMModule7.exe"
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
—————————————————————————————–
now we will boot computer into safe mode, so you might want to copy paste this safe mode part into notepad and save it so you can read it in safe mode:
to reach safe mode you would tap the f8 key during a computer restart. chose the first option from the list: safe mode.
once at the safe mode desktop:
to show all files:
FOr XP: on the desktop double click my computer,go to tools>folder options>view> then select "show hidden files and folders", then UNcheck "hide protected operating system files " also UNcheck "hide extensions for known file types" click apply to all folders, apply then ok
ok time to look for and delete some files;
navigate to
C:\Documents and Settings\KARRI THOMPSON
delete this file >>smss.exe
navigate to: C:\WINDOWS\system32\drivers\smss.exe
delete the file>>smss.exe
note: there is a legit file called smss.exe also, but its not where the above two are located.
navigate here:
C:\Program Files
and delete the entire folder called:>>ISM and ISM2
after the above, reboot computer normally.
—————————————————————————————-
i suggest you get this as a anti-malware app: superantispyware or SAS for short:
http://www.superantispyware.com/
download, install, update and do full system scan. follow the install wizard. or follow this:
Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click Yes.
Under Configuration and Preferences, click the Preferences button.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:
* Close browsers before scanning
* Scan for tracking cookies
* Terminate memory threats before quarantining.
* Ignore System Restore/Volume Information on ME and XP
* Please leave the others unchecked.
* Click the Close button to leave the control center screen.
On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click
Yes.
—————————–
you can get the SAS log like this:
To retrieve the removal information - please do the following:
* After reboot, double-click the SUPERAntispyware icon on your desktop.
* Click Preferences . Click the Statistics/Logs tab .
* Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
* It will open in your default text editor (Notepad).
* Please highlight everything , then right-click and choose copy.
* Click close and close again to exit the program.
please paste the SAS log along with a new HijackThis log in your next reply.
shelf life
Any way, here you go:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 10/26/2007 at 01:28 AM
Application Version : 3.9.1008
Core Rules Database Version : 3331
Trace Rules Database Version: 1332
Scan type : Complete Scan
Total Scan Time : 01:59:07
Memory items scanned : 659
Memory threats detected : 0
Registry items scanned : 5165
Registry threats detected : 101
File items scanned : 54101
File threats detected : 139
Adware.AdSponsor/ISM
HKLM\Software\Classes\CLSID\{1ED6A320-8AF3-4f06-868A-9BA95585712E}
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}#AppID
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\Implemented Categories
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\InprocServer32
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\InprocServer32#ThreadingModel
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\ProgID
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\TypeLib
HKCR\CLSID\{1ED6A320-8AF3-4F06-868A-9BA95585712E}\VersionIndependentProgID
C:\PROGRAM FILES\ISM\BNDDRIVE7.DLL
HKLM\Software\Classes\CLSID\{8C6D5A56-791E-4fe8-9D64-81781FA15D68}
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}#AppID
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}\InprocServer32
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}\InprocServer32#ThreadingModel
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}\ProgID
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}\TypeLib
HKCR\CLSID\{8C6D5A56-791E-4FE8-9D64-81781FA15D68}\VersionIndependentProgID
C:\PROGRAM FILES\ISM\BNDDRIVE6.DLL
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{1ED6A320-8AF3-4f06-868A-9BA95585712E}
HKU\S-1-5-21-3664803263-2521997316-2408358801-1007\Software\BndDrive
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\KARRI THOMPSON\Start Menu\Programs\Internet Speed Monitor
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\BNDDRIVE7.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\ISMMODULE7.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM2\ISMPACK5.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM2\ISMPACK7.EXE.VIR
MyWay Search Assistant Computers
HKLM\Software\Classes\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\Programmable
C:\PROGRAM FILES\MYWAYSA\SRCHASDE\DESRCAS.DLL
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{971D5B7B-F7DF-43ee-B771-6B7FA09975C3}
HKCR\CLSID\{971D5B7B-F7DF-43EE-B771-6B7FA09975C3}
HKCR\CLSID\{971D5B7B-F7DF-43EE-B771-6B7FA09975C3}\TypeLib
Adware.Tracking Cookie
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@burstnet[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@upspiral[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@screensavers[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed]-sys[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@2o7[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@tribalfusion[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@zedo[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@fastclick[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@tacoda[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@berlinads2[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@serving-sys[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@exitexchange[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@atdmt[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@interclick[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@adrevolver[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@doubleclick[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@revsci[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@adrevolver[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@spamblockerutility[2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@systemerrorfixer[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@2o7[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ad.afy11[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ad.yieldmanager[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ad.yieldx[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adbrite[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adinterax[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adlegend[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adopt.euroclick[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adopt.specificclick[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adrevolver[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adrevolver[3].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ads.adbrite[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ads.pointroll[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ads.realtechnetwork[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adserver[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@adserving.cpxinteractive[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@advertising[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@anad.tacoda[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@atdmt[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@atwola[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@azjmp[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@bluestreak[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@bs.serving-sys[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@casalemedia[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@citi.bridgetrack[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@doubleclick[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@edge.ru4[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@ehg-dig.hitbox[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@fastclick[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@freecodesource.advertserve[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@hitbox[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@interclick[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@login.tracking101[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@mediaplex[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@msnportal.112.2o7[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@perf.overture[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@questionmarket[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@realmedia[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@revsci[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@serving-sys[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@specificclick[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@statcounter[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@stats.espinthebottle[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@stats[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@tacoda[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@tradedoubler[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@trafficmp[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@tremor.adbureau[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@tribalfusion[2].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@www.macromedia[1].txt
C:\Documents and Settings\Angeleak!\Cookies\angeleak!@zedo[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri thompson@mediatraffic[1].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
C:\Documents and Settings\KARRI THOMPSON\Cookies\karri [removed][2].txt
Adware.180solutions/Seekmo
HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}
HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0
HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\HELPDIR
Adware.Zango Toolbar/Hb
HKCR\Srv.CoreServices
HKCR\Srv.CoreServices\CLSID
HKCR\Srv.CoreServices\CurVer
HKCR\Srv.CoreServices.1
HKCR\Srv.CoreServices.1\CLSID
HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}
HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\TypeLib
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\LocalServer32
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\ProgID
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\Programmable
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\TypeLib
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\VersionIndependentProgID
HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}
HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0
HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\HELPDIR
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\win32
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\FLAGS
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\HELPDIR
HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}
HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0
HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\HELPDIR
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\HELPDIR
HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}
HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0
HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\HELPDIR
HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}
HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0
HKCR\TypeLib\{C23FA5A4-1FEA-419F-8B14-F7465DF062BC}\1.0\HELPDIR
HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}
HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0
HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\HELPDIR
HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}
HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0
HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\HELPDIR
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid32
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib#Version
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid32
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib#Version
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid32
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib#Version
Adware.AdSponsor
HKCR\AppId\AdBand.DLL
HKCR\AppId\AdBand.DLL#AppID
Trojan.Net-MSV/VPS-H
HKCR\BndDrive2.Band
HKCR\BndDrive2.Band\CLSID
HKCR\BndDrive2.Band\CurVer
HKCR\BndDrive2.Band.1
HKCR\BndDrive2.Band.1\CLSID
HKCR\BndDrive2.BHO
HKCR\BndDrive2.BHO\CLSID
HKCR\BndDrive2.BHO\CurVer
HKCR\BndDrive2.BHO.1
HKCR\BndDrive2.BHO.1\CLSID
Malware.Installer-Pkg/Gen
C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE
C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{989E4C3B-B2C9-4486-9A09-D5A8F953837C}.EXE
C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRIVERS\BG_BG.GIF.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSTSSV32.EXE.VIR
Trojan.Downloader-FakeRX
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\OEMBIOS32.DLL.VIR
Trace.Known Threat Sources
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\jess_boots_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\jess3_04[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\zango_home[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\bar_header[1].gif
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\zango_common[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\jess1_03[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\default[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\jess_skuba_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\jennifer_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\jess_wet_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\jess_ss[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\jlh_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\zango[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\Zangologo[1].gif
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\paris_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\adriana_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\jessicasimpson[1].htm
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\master[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\pc_ss[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\brit_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\s_code[1].js
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\1[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\jess_bikini_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\jess_tshirt_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\anna_green_100x75[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\JessicaSimpsonLP2[1].htm%3Fref%3D51594%26PUB%3D11047%26CID%3D1104791217%26BAID%3D14111370&web_uid=2900d6bea7c64fb85833101b72d91db3&kl_s=&r=0
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\jess1_04[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\jess1_02[1].jpg
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\inactive_tab_right[1].gif
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\kefta[1].js
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\7JY5TPLA\addRef[1].js
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\active_tab_left[1].gif
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\R6N771J4\TabNavigation[1].css
C:\Documents and Settings\Angeleak!\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\inactive_tab_left[1].gif
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:46:48 AM, on 10/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Documents and Settings\KARRI THOMPSON\Desktop\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [045e8745] rundll32.exe "C:\WINDOWS\system32\sacesywd.dll",sitypnow
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WebMail - {23790A05-C992-44A0-8DFB-BD882E68A9AE} - http://webmail.academicplanet.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 9540 bytes
how about a door stop instead. just kidding, theres hope.Is there any hope for this computer? I need a good boat anchor!
thanks for the info. did you uninstall one of your antivirus apps, if you have two. you missed viewpoint manager?
————————–
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked:
O4 - HKLM\..\Run: [045e8745] rundll32.exe "C:\WINDOWS\system32\sacesywd.dll",sitypnow
reboot and post a new hjt log please.
shelf life
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:02:11 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\KARRI THOMPSON\Desktop\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WebMail - {23790A05-C992-44A0-8DFB-BD882E68A9AE} - http://webmail.academicplanet.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
–
End of file - 8241 bytes
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI