[Resolved] Security Toolbar 7.1 ?
16 min read
Since we cant use Combo anymore, we need to use another tool for me to see what's going on.
Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
- Close all applications and windows.
- Double-click on dss.exe to run it, and follow the prompts.
- When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
- Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
Sorry for the delay. Here are the two files:
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-20 21:44:39
Computer is in Normal Mode.
——————————————————————————–
– System Restore ————————————————————–
Successfully created a Deckard's System Scanner Restore Point.
– Last 3 Restore Point(s) –
3: 2007-11-21 02:44:50 UTC - RP877 - Deckard's System Scanner Restore Point
2: 2007-11-20 01:55:58 UTC - RP876 - System Checkpoint
1: 2007-11-19 00:18:00 UTC - RP875 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 256 MiB (512 MiB recommended).
– HijackThis (run as Steve.exe) ———————————————–
Logfile of HijackThis v1.99.1
Scan saved at 9:45:31 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Steve\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Steve.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
– File Associations ———————————————————–
All associations okay.
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R2 SbcpHid - c:\windows\system32\drivers\sbcphid.sys
R3 catchme - c:\docume~1\steve\locals~1\temp\catchme.sys (file missing)
R3 pc22nd5 (Toshiba PCX2200 USB Cable Modem networking driver (NDIS)) - c:\windows\system32\drivers\pc22nd5.sys
Strangely, there is mention of McAfee Shredder in the logs, but no McAfee in the programs list. Have you uninstalled that at some point?
You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended.
I see that Viewpoint Manager & Viewpoint Media Player is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.
Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
- Click Start, point to Settings, and then click Control Panel.
- In Control Panel, double-click Add or Remove Programs.
- In Add or Remove Programs, highlight Viewpoint Manager , click Remove.
- Do the same for each Viewpoint component.
- Close all programs so that you are at your desktop.
- Double-click on the My Computer icon (or click Start, then select My Computer)
- Select the Tools menu and click Folder Options.
- After the new window appears select the View tab.
- Put a checkmark in the checkbox labeled Display the contents of system folders.
- Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
- Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
- Remove the checkmark from the checkbox labeled Hide protected operating system files.
- Press the Apply button and then the OK button and shutdown My Computer.
Now your computer is configured to show all hidden files.
Download Killbox
Open Killbox.exe
Check the following boxes:
- Delete on Reboot
C:\WINDOWS\system32\geeda.dll
Then in Killbox, click File>>Paste from Clipboard
At this point the "All Files" button should be enabled so you can click it.
Click the "All Files" button.
Then click the Red X …and for the confirmation message that will appear, you will need to click Yes.
A second message will ask to Reboot now? You will need to click Yes to allow the reboot.
Note: Killbox will let you know if a file does not exist.
If you have any issues with this method, you can copy and paste the lines one at a time into the Killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click Yes to allow the Reboot.
Warning. Please note that this fix is specific for this poster and should not be used by anyone else:
1. Before we make changes to your registry, we need to make a back up of the key that we are going to work on:
To back up the key please do the following
- Copy the contents of the Code Box below to Notepad.
- Name the file export.bat
- Change the "Save as Type" to All Files
- and Save it on the desktop
regedit /e C:\export-run.reg "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa"Double-click the export.bat file
The backup file will be placed in your C:\ directory as export-run.reg .
If there is a fatal error you can simply double click on the export-run.reg you just created to restore the registry to the state it was in before you began.
Warning. Do not click it except if I tell you to do so. Double clicking it will reintroduce the maleware to your computer and can have other unexpected effects.
2. Please do this:
- Copy the contents of the Code Box below to Notepad.
- Name the file as fix.reg
- Change the Save as Type to All Files
- and Save it on the desktop
REGEDIT4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
Make sure there are NO blank lines before REGEDIT4
Then double-click on the fix.reg file, and when it prompts to merge say yes.
Now post back with a new log from Deckards System Scanner.
Sorry for the delay. I have followed all your suggestions with the anti-virus and the viewpoint manager. The following is the dss log:
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-23 22:16:27
Computer is in Normal Mode.
——————————————————————————–
Total Physical Memory: 256 MiB (512 MiB recommended).
– HijackThis (run as Steve.exe) ———————————————–
Logfile of HijackThis v1.99.1
Scan saved at 10:16:39 PM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Steve\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Steve.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
– Files created between 2007-10-23 and 2007-11-23 —————————–
2007-11-23 22:13:35 8780 –a—— C:\export-run.reg
2007-11-23 21:38:59 0 d——– C:\!KillBox
2007-11-23 11:26:42 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-23 11:23:45 0 d——– C:\Program Files\Nick Arcade
2007-11-23 09:52:25 0 dr-h—– C:\$VAULT$.AVG
2007-11-23 09:00:55 0 d——– C:\Documents and Settings\Steve\Application Data\AVG7
2007-11-23 09:00:05 0 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-23 08:59:19 0 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-11-21 12:42:52 0 d——– C:\Program Files\Infogrames Interactive
2007-11-21 08:33:07 0 d——– C:\Documents and Settings\Guest\Application Data\Macromedia
2007-11-21 08:29:10 0 d——– C:\Documents and Settings\Guest\Application Data\Grisoft
2007-11-21 08:28:51 0 d——– C:\Documents and Settings\Guest\Application Data\Identities
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\Templates
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\Start Menu
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\SendTo
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\Recent
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\PrintHood
2007-11-21 08:28:38 786432 –ah—– C:\Documents and Settings\Guest\NTUSER.DAT
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\NetHood
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\My Documents
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\Local Settings
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\Favorites
2007-11-21 08:28:38 0 d——– C:\Documents and Settings\Guest\Desktop
2007-11-21 08:28:38 0 d–hs—- C:\Documents and Settings\Guest\Cookies
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\Application Data
2007-11-21 08:28:38 0 d—s—- C:\Documents and Settings\Guest\Application Data\Microsoft
2007-11-18 20:12:25 0 d——– C:\WINDOWS\ERUNT
2007-11-17 21:30:27 0 d——– C:\Documents and Settings\Steve\Application Data\Grisoft
2007-11-17 01:18:54 0 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-16 17:26:22 0 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-16 17:25:36 0 d——– C:\Program Files\SUPERAntiSpyware
2007-11-16 17:25:35 0 d——– C:\Documents and Settings\Steve\Application Data\SUPERAntiSpyware.com
2007-11-16 17:24:14 0 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 16:27:03 396 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-16 12:09:32 0 d——– C:\Program Files\Common Files\mkok
2007-11-16 12:09:31 0 d——– C:\WINDOWS\mkok
2007-11-15 23:24:41 0 d——– C:\Program Files\Lavasoft
2007-11-15 23:19:36 0 d——– C:\Documents and Settings\Steve\Application Data\Lavasoft
2007-11-14 21:29:22 0 d——– C:\WINDOWS\system32\909096989B9498
2007-11-07 14:54:08 0 d——– C:\Document
2007-11-06 15:09:45 0 d——– C:\WINDOWS\network diagnostic
2007-10-24 14:11:36 2917 –a—— C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
– Find3M Report —————————————————————
2007-11-23 11:44:23 0 dr-h—– C:\Documents and Settings\Steve\Application Data\yahoo!
2007-11-22 00:00:02 0 d——– C:\Program Files\PokerStars
2007-11-17 21:03:02 0 d——– C:\Program Files\Common Files
2007-11-15 22:16:42 0 d——– C:\Program Files\Google
2007-11-14 21:28:20 0 d——– C:\Program Files\Microsoft Encarta
2007-11-07 15:44:29 62016 –a—-c- C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2007-10-15 22:01:53 0 d——– C:\Documents and Settings\Steve\Application Data\Adobe
2007-10-11 22:29:11 0 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-10-11 22:28:17 0 d——– C:\Program Files\Common Files\Adobe
2007-10-11 22:22:02 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-09-27 16:41:31 0 d——– C:\Documents and Settings\Steve\Application Data\AdobeUM
– Registry Dump —————————————————————
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 04:25 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/16/2006 09:43 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [11/23/2007 08:59 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/09/2006 03:41 PM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [08/18/2005 01:49 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [11/07/2006 10:29 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"DelayShred"="C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" /q C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\G5MR0TMF\INDEX_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\INDEX_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\1Z735DKE\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\7UO37T0L\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\7UO37T0L\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UTZWTCJU\EBED21~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\F91B31~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\6DCV25EX\060A9C~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\8TCR4FOZ\AE8F31~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\8DYFKLMN\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\0VQ9S5UJ\TN67E3~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CXYZG52N\393254~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UPLM3MHK\FDEE8D~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\4JD36M7X\560615~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UPLM3MHK\2C9BE8~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\VL3C1RBC\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\VL3C1RBC\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\M0H33E9V\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\ZTOWXBVT\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\ZTOWXBVT\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\9K7WCYAJ\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UM4PU4SM\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\E0YWIJ59\AIM_UA~1.SH!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/11/2007 10:28:17 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/24/2005 1:05:26 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 3:01:04 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Steve^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=C:\Documents and Settings\Steve\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=C:\WINDOWS\pss\Greetings Workshop Reminders.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ymetray]
"C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
– End of Deckard's System Scanner: finished at 2007-11-23 22:17:03 ————
- Click START then RUN
- Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.
[external image: Posted Image]
- When shown the disclaimer, Select "2"
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
+ Extended(If available otherwise Standard) - Scan Options:
+ Scan Archives
+ Scan Mail Bases
- Scan using the following Anti-Virus database:
- Click OK
- Now under select a target to scan select My Computer
- The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button
- Save the file to your desktop.
- Copy and paste that information in your next post.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
Navigate to and delete the following files and folder (if they are present):
Files:
C:\Documents and Settings\Steve\Shared\01 Track 1 (blacklight).wma
C:\Program Files\Microsoft Encarta\holemuv83122.dll
Folder::
C:\Documents and Settings\Steve\Desktop\SmitfraudFix
Run Spybot S&D and go to the Recovery section and delete everything in there.
You may wish to keep hold of the Kaspersky Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs
Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
- Close any programmes you may have running, ESPECIALLY your web browser
- Click Start > Control Panel.
- Click Add/Remove Programs.
- Check any item with Java Runtime Environment (JRE or J2SE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove all versions of Java.
- Reboot your computer once all Java components are removed.
Finally, post a new Deckards log and tell me how the computer is behaving now.
Computer is running MUCH MUCH better. Here is the Deckards log:
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-24 15:49:35
Computer is in Normal Mode.
——————————————————————————–
Total Physical Memory: 256 MiB (512 MiB recommended).
– HijackThis (run as Steve.exe) ———————————————–
Logfile of HijackThis v1.99.1
Scan saved at 3:49:51 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Steve\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Steve.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
– Files created between 2007-10-24 and 2007-11-24 —————————–
2007-11-24 15:45:09 0 d——– C:\Program Files\Common Files\Java
2007-11-24 09:01:25 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-24 09:01:23 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-23 22:13:35 8780 –a—— C:\export-run.reg
2007-11-23 21:38:59 0 d——– C:\!KillBox
2007-11-23 11:26:42 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-23 11:23:45 0 d——– C:\Program Files\Nick Arcade
2007-11-23 09:52:25 0 dr-h—– C:\$VAULT$.AVG
2007-11-23 09:00:55 0 d——– C:\Documents and Settings\Steve\Application Data\AVG7
2007-11-23 09:00:05 0 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-23 08:59:19 0 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-11-21 12:42:52 0 d——– C:\Program Files\Infogrames Interactive
2007-11-21 08:33:07 0 d——– C:\Documents and Settings\Guest\Application Data\Macromedia
2007-11-21 08:29:10 0 d——– C:\Documents and Settings\Guest\Application Data\Grisoft
2007-11-21 08:28:51 0 d——– C:\Documents and Settings\Guest\Application Data\Identities
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\Templates
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\Start Menu
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\SendTo
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\Recent
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\PrintHood
2007-11-21 08:28:38 786432 –ah—– C:\Documents and Settings\Guest\NTUSER.DAT
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\NetHood
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\My Documents
2007-11-21 08:28:38 0 d–h—– C:\Documents and Settings\Guest\Local Settings
2007-11-21 08:28:38 0 dr——- C:\Documents and Settings\Guest\Favorites
2007-11-21 08:28:38 0 d——– C:\Documents and Settings\Guest\Desktop
2007-11-21 08:28:38 0 d–hs—- C:\Documents and Settings\Guest\Cookies
2007-11-21 08:28:38 0 dr-h—– C:\Documents and Settings\Guest\Application Data
2007-11-21 08:28:38 0 d—s—- C:\Documents and Settings\Guest\Application Data\Microsoft
2007-11-18 20:12:25 0 d——– C:\WINDOWS\ERUNT
2007-11-17 21:30:27 0 d——– C:\Documents and Settings\Steve\Application Data\Grisoft
2007-11-17 01:18:54 0 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-16 17:26:22 0 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-16 17:25:36 0 d——– C:\Program Files\SUPERAntiSpyware
2007-11-16 17:25:35 0 d——– C:\Documents and Settings\Steve\Application Data\SUPERAntiSpyware.com
2007-11-16 17:24:14 0 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 16:27:03 396 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-16 12:09:32 0 d——– C:\Program Files\Common Files\mkok
2007-11-16 12:09:31 0 d——– C:\WINDOWS\mkok
2007-11-15 23:24:41 0 d——– C:\Program Files\Lavasoft
2007-11-15 23:19:36 0 d——– C:\Documents and Settings\Steve\Application Data\Lavasoft
2007-11-14 21:29:22 0 d——– C:\WINDOWS\system32\909096989B9498
2007-11-07 14:54:08 0 d——– C:\Document
2007-11-06 15:09:45 0 d——– C:\WINDOWS\network diagnostic
2007-10-24 14:11:36 2917 –a—— C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
– Find3M Report —————————————————————
2007-11-24 15:46:55 0 d——– C:\Program Files\Java
2007-11-24 15:45:09 0 d——– C:\Program Files\Common Files
2007-11-24 15:22:28 0 d——– C:\Program Files\Bodog Poker
2007-11-24 15:21:02 0 d——– C:\Program Files\Yahoo!
2007-11-24 14:09:53 0 d——– C:\Program Files\Microsoft Encarta
2007-11-23 11:44:23 0 dr-h—– C:\Documents and Settings\Steve\Application Data\yahoo!
2007-11-22 00:00:02 0 d——– C:\Program Files\PokerStars
2007-11-15 22:16:42 0 d——– C:\Program Files\Google
2007-11-07 15:44:29 62016 –a—-c- C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2007-10-15 22:01:53 0 d——– C:\Documents and Settings\Steve\Application Data\Adobe
2007-10-11 22:29:11 0 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-10-11 22:28:17 0 d——– C:\Program Files\Common Files\Adobe
2007-10-11 22:22:02 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-09-27 16:41:31 0 d——– C:\Documents and Settings\Steve\Application Data\AdobeUM
– Registry Dump —————————————————————
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 04:25 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/16/2006 09:43 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [11/23/2007 08:59 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [08/18/2005 01:49 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [11/07/2006 10:29 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"DelayShred"="C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" /q C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\G5MR0TMF\INDEX_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\INDEX_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\1Z735DKE\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\7UO37T0L\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\7UO37T0L\YAHOO_~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UTZWTCJU\EBED21~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CLEBS5IB\F91B31~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\6DCV25EX\060A9C~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\8TCR4FOZ\AE8F31~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\8DYFKLMN\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\0VQ9S5UJ\TN67E3~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\CXYZG52N\393254~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UPLM3MHK\FDEE8D~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\4JD36M7X\560615~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UPLM3MHK\2C9BE8~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\VL3C1RBC\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\VL3C1RBC\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\M0H33E9V\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\ZTOWXBVT\AIMTOD~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\ZTOWXBVT\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\9K7WCYAJ\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\UM4PU4SM\AIM_UA~1.SH! C:\DOCUME~1\Steve\LOCALS~1\TEMPOR~1\Content.IE5\E0YWIJ59\AIM_UA~1.SH!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/11/2007 10:28:17 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/24/2005 1:05:26 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 3:01:04 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Steve^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=C:\Documents and Settings\Steve\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=C:\WINDOWS\pss\Greetings Workshop Reminders.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ymetray]
"C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
– End of Deckard's System Scanner: finished at 2007-11-24 15:50:15 ————
Why have you still got files waiting to be shredded? Is there a problem there?
Double-click the HijackThis icon on your Desktop, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.
You may wish to keep hold of the Kaspersky Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs
This is my usual speech for when you are clean, which you appear to be.
- Click Start | Help and Support | Undo changes to your computer with System Restore.
- Click Create A Restore Point then click Next. Give it a name it and then click Create, then Close.
- Close the Help and Support Center box.
- Click Start | Run and type Cleanmgr
- Select (C: ) then click OK.
- Click the More Options tab.
- Click Clean Up in the System Restore Section.
This will remove all previous restore points except the newly created one.
Re hide your system files To do so, please follow the steps below:
- Double-click My Computer.
- Click the Tools menu, and then click Folder Options.
- Click the View tab.
- Put a check by "Hide file extensions for known file types."
- Under the "Hidden files" folder, select "Do not show hidden files and folders."
- Check "Hide protected operating system files."
- Click Apply, and then click OK.
Here are some free programs I recommend, although you will not need them all.
Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here
Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here
Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here
Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here
Make sure your Windows is ALWAYS up to date!
An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.
Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
Please check out Tony Klein's article "How did I get infected in the first place?"
Follow this list and your potential for being infected again will reduce dramatically.
I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI