This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Warning Potential Spyware Operation! (Ken, I attempted to do what

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ken (or anyone else)…if you're out there. I just read the thread with you and Buck (http://forums.whatthetech.com/HELP_Getting_Windows_Security_Alert_t84422.html&hl=unauthorized) as I am having the same issues. I did everything you suggested. My PC is running much faster now which is great but I am still getting the pop up that says Warning Potential Spyware Operation! Your computer is making unauthorized coopies…..etc. I'm also having some other issues running my work's webmail program. Other than that its fine.

Should I uninstall all of the programs you suggested and start over or is there another way to fix this?

I've posted my logs from HiJack This, ComboFix & SmitfraudFix….

Please help!

Thanks!
KL


_____________________________________________

HiJack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:32 AM, on 10/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\LOGI_MWX.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ShowLOMControl] 
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dlcdmon.exe] "C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 944\memcard.exe
O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Elephant Desktop] C:\Program Files\ElephantDrive\ElephantDesktop.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: infos.exe
O4 - Global Startup: autos.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 10186 bytes

__________________________________


ComboFix Log:

ComboFix 07-10-29.1** - Kevin Lange 2007-10-31 10:20:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.332 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\Y6XCQSBG\ComboFix[1].exe
.

((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-31 )))))))))))))))))))))))))))))))
.

2007-10-31 00:33 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-31 00:12 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-31 00:12 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-31 00:12 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-10-31 00:12 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-31 00:12 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-31 00:12 4,670 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-30 22:53 d——– C:\Program Files\Trend Micro
2007-10-30 20:14 d——– C:\Program Files\Lavasoft
2007-10-30 20:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-30 20:13 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-30 19:37 120,024 –a—— C:\WINDOWS\dream43.exe
2007-10-30 01:23 12,800 –a—— C:\WINDOWS\system32\bronto.dll
2007-10-30 01:23 7,680 –a—— C:\WINDOWS\system32\winter.exe
2007-10-30 01:23 7,680 –a—— C:\WINDOWS\system32\proper.exe
2007-10-30 01:23 6,144 –a—— C:\WINDOWS\system32\skuns.dat
2007-10-30 00:41 d——– C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-10-30 00:40 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-10-29 20:17 d——– C:\Program Files\Smart Projects
2007-10-25 00:00 d——– C:\Documents and Settings\LocalService\Application Data\TeamViewer
2007-10-24 22:38 d——– C:\Documents and Settings\Kevin Lange\Application Data\DivX
2007-10-23 19:35 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\TeamViewer
2007-10-23 19:35 d——– C:\Program Files\TeamViewer3
2007-10-23 19:35 d——– C:\Documents and Settings\Kevin Lange\Application Data\TeamViewer
2007-10-20 00:08 d——– C:\Incomplete
2007-10-20 00:07 d——– C:\Program Files\Incomplete
2007-10-18 00:52 d——– C:\Program Files\LimeWire
2007-10-18 00:13 737,280 –a—— C:\WINDOWS\iun6002.exe
2007-10-09 22:52 582,656 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-09-30 18:04 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-09-10 15:39 24,896 –a—— C:\Documents and Settings\Kevin Lange\Application Data\GDIPFONTCACHEV1.DAT
2007-09-09 22:12 d——– C:\Program Files\VideoLAN
2007-09-08 14:10 d——– C:\Program Files\Real
2007-09-08 14:10 d——– C:\Program Files\Common Files\xing shared
2007-09-08 13:20 630,784 –a—— C:\WINDOWS\system32\vp7vfw.dll
2007-09-08 13:20 564,224 –a—— C:\WINDOWS\system32\x264vfw.dll
2007-09-08 13:20 438,272 –a—— C:\WINDOWS\system32\vp6vfw.dll
2007-09-08 13:20 217,088 –a—— C:\WINDOWS\system32\i420vfw.dll
2007-09-08 13:20 144,384 –a—— C:\WINDOWS\system32\Iacenc.dll
2007-09-08 13:20 39,936 –a—— C:\WINDOWS\system32\huffyuv.dll
2007-09-02 19:30 d——– C:\WINDOWS\pss
2007-09-02 19:15 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-09-02 19:15 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-09-02 19:15 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-09-02 19:14 40,738,456 –a—— C:\Program Files\zlsSetup_70_337_000_en.exe
2007-09-02 18:35 d——– C:\Program Files\CONEXANT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 13:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-31 06:54 ——— d—–w C:\Program Files\Dl_cats
2007-10-31 06:04 ——— d—–w C:\Documents and Settings\Kevin Lange\Application Data\AVG7
2007-10-31 04:13 ——— d—–w C:\Program Files\Java
2007-10-31 02:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-30 06:26 ——— d—–w C:\Documents and Settings\Kevin Lange\Application Data\uTorrent
2007-10-30 05:44 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-30 05:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-30 05:11 ——— d—–w C:\Program Files\Google
2007-10-30 00:50 ——— d—–w C:\Program Files\DivX
2007-10-06 16:53 ——— d—–w C:\Documents and Settings\Kevin Lange\Application Data\AdobeUM
2007-09-08 19:10 ——— d—–w C:\Program Files\Common Files\Real
2007-09-08 18:20 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-09-03 02:20 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-02 23:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\GTek
2007-09-02 23:39 ——— d—–w C:\Program Files\PowerISO
2007-09-02 23:39 ——— d—–w C:\Program Files\CyberLink
2007-09-02 23:38 ——— d—–w C:\Program Files\MUSICMATCH
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-15 22:33 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-12 23:31 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-09 13:16 582,656 —-a-w C:\WINDOWS\system32\rpcrt4.dll
2007-06-05 03:47 7,183,768 —-a-w C:\Program Files\IP5_2Eng.exe
2007-06-05 03:45 7,773,568 —-a-w C:\Program Files\IP64Eng.exe
2007-04-10 09:18 87,608 —-a-w C:\Documents and Settings\Kevin Lange\Application Data\ezpinst.exe
2007-04-10 09:18 47,360 —-a-w C:\Documents and Settings\Kevin Lange\Application Data\pcouffin.sys
2007-03-14 04:18 3,018,824 —-a-w C:\Documents and Settings\Kevin Lange\Application Data\prg.exe
2006-05-31 01:52:44 88 –sh–r C:\WINDOWS\system32\00402F3EAC.sys
2006-07-05 02:42:49 56 –sh–r C:\WINDOWS\system32\E183A9120E.sys
2006-07-14 20:32:07 6,736 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-10-31_ 0.43.20.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-31 05:39:59 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-10-31 06:50:59 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-31 05:39:59 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-31 06:50:59 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-31 05:39:59 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-31 06:50:59 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D27987B8-7244-4DE0-AE10-39B826B492F1}]
2007-10-30 01:23 12800 –a—— C:\WINDOWS\system32\bronto.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 23:44]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 23:41]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 23:45]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 11:55]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 11:56]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 21:35 C:\WINDOWS\stsystra.exe]
"ShowLOMControl"="1 (0x1)" []
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 19:05]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-23 09:14]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"dlcdmon.exe"="C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 11:01]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 944\memcard.exe" [2005-09-07 08:37]
"Logitech Utility"="LOGI_MWX.EXE" [2003-12-17 10:50 C:\WINDOWS\LOGI_MWX.EXE]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 17:22]
"Elephant Desktop"="C:\Program Files\ElephantDrive\ElephantDesktop.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-24 18:33]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 18:56]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-12-06 10:45]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-08 14:10]
"Undefined"="C:\WINDOWS\system32\winter.exe" [2007-10-30 01:23]
"DLCDCATS"="C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 08:51]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"Undefined"="C:\WINDOWS\system32\winter.exe" [2007-10-30 01:23]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

C:\Documents and Settings\Kevin Lange\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50]
infos.exe [2007-10-30 01:23:25]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
autos.exe [2007-10-30 01:23:25]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-29 05:56:13]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll

R2 TeamViewer;TeamViewer 3;"C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS
R3 dlcd_device;dlcd_device;C:\WINDOWS\system32\dlcdcoms.exe -service
R3 PLUsbbc2;Hi-Speed USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc2.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-10-25 11:21:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 10:22:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-31 10:23:27
C:\ComboFix2.txt … 2007-10-31 00:43
.
— E O F —

__________________________________________________________

Smitfraud Fix Log:

SmitFraudFix v2.245

Scan done at 10:24:43.53, Wed 10/31/2007
Run from C:\Documents and Settings\Kevin Lange\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\LOGI_MWX.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

192.168.200.3 download.microsoft.com
192.168.200.3 downloads.microsoft.com
192.168.200.3 go.microsoft.com
192.168.200.3 microsoft.com
192.168.200.3 msdn.microsoft.com
192.168.200.3 office.microsoft.com
192.168.200.3 support.microsoft.com
192.168.200.3 windowsupdate.microsoft.com
192.168.200.3 www.microsoft.com
192.168.200.3 pandasoftware.com
192.168.200.3 www.pandasoftware.com

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kevin Lange


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kevin Lange\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KEVINL~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: ADMtek ADM8511 USB To Fast Ethernet Converter - Packet Scheduler Miniport
DNS Server Search Order: 207.172.3.8
DNS Server Search Order: 207.172.3.9

HKLM\SYSTEM\CCS\Services\Tcpip\..\{93368321-D5F7-4B7E-A3B7-70CFCF2A330B}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{93368321-D5F7-4B7E-A3B7-70CFCF2A330B}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\..\{93368321-D5F7-4B7E-A3B7-70CFCF2A330B}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Your post has been Moved, Closed or Edited for one of the following reasons:

1.) You posted multiple topics and only one is required

2.) You are spamming links to other places without approval

3.) You have posted your hijackthis log to the wrong forum:
( http://forums.whatthetech.com/HijackThis_L…emoval_f27.html ) <— correct forum for HijackThis Logs

4.) Abusive language or other problems in your text

5.) Your log is too old (20 days or more) and no replies from you after a volunteer tried to help you

If you came here for help, and you have not posted a Hijackthis log to the proper forum, then you may do so now, if you came here to spam or abuse, you will be dealt with harsher on your next offense

This is a family oriented forum to help those that need help.

==============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI