Hi LDT. The Firefox browser is begining to shut down again. Pop ups from DCads are continuing. Posted this reply through internet explorer due to not being able to reach this site on Firefox. Here`s the Combofix report and a new Hijackthis log. Thanks again
ComboFix 07-11-19.3 - Doug & Natalie 2007-11-25 19:02:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1069 [GMT 10:00]
Running from: C:\TEMP\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\nsgF.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.
2007-11-25 19:00 1,545,623 --a------ C:\TEMP\ComboFix.exe
2007-11-20 20:43 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-13 11:43 <DIR> C:\Documents and Settings\Doug 2007-11-13 11:43 <DIR> Natalie\Application Data\Apple Computer
2007-11-11 11:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-09 23:19 <DIR> C:\Documents and Settings\Doug 2007-11-09 23:19 <DIR> Natalie\Application Data\Grisoft
2007-11-09 22:52 532,480 --a------ C:\TEMP\cwshredder.exe
2007-11-09 21:27 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-09 21:26 12,413,440 --a------ C:\TEMP\avgas-setup-7.5.1.43.exe
2007-11-07 18:40 <DIR> d-------- C:\Program Files\BingoCafe
2007-11-03 14:43 40,731 --a------ C:\WINDOWS\system32\superiorads-uninst.exe
2007-11-01 21:23 <DIR> C:\Documents and Settings\Doug 2007-11-01 21:23 <DIR> Natalie\Application Data\Azureus
2007-11-01 21:22 <DIR> d-------- C:\Program Files\Azureus
2007-10-29 15:53 <DIR> C:\Documents and Settings\Doug 2007-10-29 15:53 <DIR> Natalie\Application Data\Macromedia
2007-10-27 11:03 <DIR> C:\Documents and Settings\Doug 2007-10-27 11:03 <DIR> Natalie\Shared
2007-10-27 11:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-10-27 11:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-10-27 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-27 10:58 <DIR> d-------- C:\WINDOWS\Sun
2007-10-27 10:58 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-10-27 10:57 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-10-27 10:57 <DIR> C:\Documents and Settings\Doug 2007-10-27 10:57 <DIR> Natalie\WINDOWS
2007-10-27 10:56 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-27 10:55 <DIR> d-------- C:\Program Files\BigPond
2007-10-27 10:55 <DIR> d-------- C:\Program Files\ATI Technologies
2007-10-27 10:34 36,864 --a------ C:\WINDOWS\system32\RtlGina2.dll
2007-10-27 10:34 36,864 --a------ C:\WINDOWS\system32\RtlGina2(2)(2).dll
2007-10-27 10:23 4,194,304 C:\Documents and Settings\Doug 2007-10-27 10:23 4,194,304 Natalie\ntuser.dat
2007-10-27 10:13 15,781 --a------ C:\WINDOWS\system32\drivers\mdc8021x.sys
2007-10-27 10:06 147,456 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-10-27 09:38 <DIR> C:\Documents and Settings\Doug 2007-10-27 09:38 <DIR> Natalie\Application Data\ImgBurn
2007-10-27 09:33 <DIR> d-------- C:\XBOX360
2007-10-27 09:31 <DIR> d-------- C:\Program Files\ImgBurn
2007-10-26 21:01 <DIR> d-------- C:\Program Files\EA Games
2007-10-26 20:13 <DIR> d-------- C:\Program Files\Acoustica MP3 To Wave Converter PLUS
2007-10-26 20:05 <DIR> d-------- C:\Program Files\Ulead Systems
2007-10-26 20:05 <DIR> C:\Documents and Settings\Doug 2007-10-26 20:05 <DIR> Natalie\Application Data\Ulead Systems
2007-10-26 20:04 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2007-10-26 20:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2007-10-26 20:00 <DIR> d-------- C:\Program Files\QuickTime
2007-10-26 20:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-26 19:58 <DIR> d-------- C:\Program Files\LimeWire
2007-10-26 19:58 <DIR> d-------- C:\Program Files\DVD Shrink
2007-10-26 19:58 <DIR> C:\Documents and Settings\Doug 2007-10-26 19:58 <DIR> Natalie\Incomplete
2007-10-26 19:58 <DIR> C:\Documents and Settings\Doug 2007-10-26 19:58 <DIR> Natalie\Application Data\LimeWire
2007-10-26 19:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-10-26 19:54 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-10-26 19:52 <DIR> C:\Documents and Settings\Doug 2007-10-26 19:52 <DIR> Natalie\Application Data\Ahead
2007-10-26 19:49 <DIR> d-------- C:\Program Files\Nero
2007-10-26 19:49 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-10-26 19:20 <DIR> d-------- C:\Program Files\eMule
2007-10-26 19:02 <DIR> d-------- C:\Program Files\DivX
2007-10-26 18:33 <DIR> d-------- C:\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-24 22:45 --------- d-----w C:\Program Files\SpywareBlaster
2007-11-23 06:31 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\AVG7
2007-11-20 10:06 --------- d-----w C:\Program Files\Bonjour
2007-11-13 01:44 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\LimeWire
2007-11-13 01:43 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\Apple Computer
2007-11-09 13:19 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\Grisoft
2007-11-09 13:19 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\Azureus
2007-11-09 11:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-01 11:56 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\Ahead
2007-10-27 01:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-27 01:04 --------- d-----w C:\Program Files\NETGEAR
2007-10-27 01:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-27 01:00 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-27 01:00 --------- d-----w C:\Program Files\SpywareGuard
2007-10-27 01:00 --------- d-----w C:\Program Files\HP
2007-10-27 01:00 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-27 01:00 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-27 00:57 --------- d-----w C:\Program Files\Common Files\HP
2007-10-27 00:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-10-26 23:38 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\ImgBurn
2007-10-26 11:10 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-26 10:05 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\Ulead Systems
2007-10-26 10:04 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-21 09:10 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-10-21 08:49 --------- d-----w C:\Program Files\Java
2007-10-21 08:47 --------- d-----w C:\Program Files\Common Files\Java
2007-10-21 08:33 --------- d-----w C:\Program Files\Lavasoft
2007-10-21 08:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-21 08:11 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-10-21 07:30 237,568 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(2).DAT
2007-10-21 07:30 --------- d-----w C:\Documents and Settings\Doug & Natalie\Application Data\InstallShield
2007-10-21 07:24 21,035 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-10-21 05:30 --------- d-----w C:\Program Files\Realtek Sound Manager
2007-10-21 05:30 --------- d-----w C:\Program Files\AvRack
2007-10-21 05:27 --------- d-----w C:\Program Files\VIA
2007-10-21 04:43 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-29 05:46 47,376 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-09-29 03:05 2,456,064 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-09-29 02:19 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 20:48 C:\WINDOWS\SOUNDMAN.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-24 10:46]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 08:56]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-24 10:46]
C:\Documents and Settings\Doug & Natalie\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111T\wlan111t.exe [2007-10-27 10:06:27]
Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2007-10-27 10:13:49]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
backup=C:\WINDOWS\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Smart Wizard Wireless Settings.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk
backup=C:\WINDOWS\pss\Smart Wizard Wireless Settings.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 03:06 40048 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 18:05 143360 --a------ C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 16:24 54840 --a------ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 --a------ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 01:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-11-25 07:14:08 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-25 19:07:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-25 19:09:06 - machine was rebooted
.
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 7:14:58 PM, on 25/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Doug & Natalie\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bigpond.com/homepage/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -
http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1192961180062
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe