This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware and safe mode problem

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I had repeated popups and the yellow triangle in the bottom bar and "Online Security Guide" & "Live Safety Center" shortcuts on my computer after a recent reboot.

When I deleted the icons and rebooted the system planning to run some virus scans the system booted in safe mode without access to the internet.

I ran spybot, and AVG antispy and vundofix and found and deleted alot of cookies and 7 copies of vundo related files.

Rebooted and it was still in safe mode. Tried F8 to start in normal and it still booted in safe mode.
Re ran vundofix which did not find any files remaining, and the yellow trinangle is gone and so are the popup.

Now the obvious remaining problem is the inability to boot up in normal windows mode, with internet connection. I have another computer next to the infected one that I am accessing the internet with.

Here is the hijackthis log I ran after these initial cleanup efforts.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:19:22 PM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: {751c384a-26c6-cd48-a014-b21ace03d583} - {385d30ec-a12b-410a-84dc-6c62a483c157} - C:\WINDOWS\system32\gaskcxwi.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: FormFiller.clsIEInterface - {C668F19A-93FB-49A1-86C4-091E0D624443} - C:\Program Files\Zeus\FormFiller.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Hardware\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [AS00_Gear311T] C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe -hide
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [WorkFlowTray] "C:\Program Files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe"
O4 - HKLM\..\Run: [Opware14] "C:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe"
O4 - HKLM\..\Run: [OpScheduler] "C:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe"
O4 - HKLM\..\Run: [PDF Converter Registry Controller] "C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\RegistryController.exe"
O4 - HKLM\..\Run: [SSPrnAgent] C:\Program Files\ScanSoft\OmniPagePro14.0\PdfPrn\SPrnAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "F:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA6535] command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4629] cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB1870] command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2539] cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: USB Manager.lnk = C:\Program Files\Belkin\Belkin Wireless USB Adapter Manager\WlanMonitor.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: &Zeus Form Filler - C:\Program Files\Zeus\DragAndDrop.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\IEShellExt.dll /100
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1148337015811
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_9.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8567BDF0-2D23-4AF4-A326-000F08DE4FE8}: NameServer = 208.200.248.1,208.200.248.8
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 11654 bytes

Thanks in advance for your help
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

Do you have a USB memory stick or similar that you could transfer tools from this computer to your infected computer with?

jpshortstuff
Yes I do have a usb stick, that is how I got the current version of hijack on the infected computer and got this log from the infected computer to this one.
Hi

Open HijackThis. Hit Do A System Scan Only. Place a check next to the following items (if present):
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: {751c384a-26c6-cd48-a014-b21ace03d583} - {385d30ec-a12b-410a-84dc-6c62a483c157} - C:\WINDOWS\system32\gaskcxwi.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


Close all browsers and windows except for HijackThis and click Fix Checked.


Please download the following two items, save them to your memory stick and transfer them to the infected computer, saving them to your desktop.
Download - ATF Cleaner»
Download ComboFix by sUBs from here or here


Now, on your infected computer:

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Thanks,

jpshortstuff
Done



ComboFix 07-11-08.1 - John 2007-11-18 14:51:46.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1249 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\John\Favorites\Online Security Guide.lnk
C:\Program Files\sks~1
C:\Program Files\sks~1\??sks\
C:\temp\17o7
C:\WINDOWS\sks~1
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\FTPx.dll
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-18 to 2007-11-18 )))))))))))))))))))))))))))))))
.

2007-11-18 03:37 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-11-17 22:29 d——– C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-11-17 20:11 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-11-16 21:53 83,085 –a—— C:\WINDOWS\system32\gtwhafln.dll
2007-11-16 18:11 36,352 –a—— C:\WINDOWS\system32\efcywvs.dll.vir
2007-11-16 18:10 d——– C:\WINDOWS\system32\rMa02yy
2007-11-16 18:10 d——– C:\Temp\abW9
2007-11-14 11:56 d——– C:\Documents and Settings\All Users\Application Data\{D9AA4D17-9292-410D-9AA5-84526D062900}
2007-11-14 11:55 d——– C:\Documents and Settings\All Users\Application Data\{EF257B1A-26EA-4A90-9BCC-54CA818488E8}
2007-11-14 11:55 d——– C:\Documents and Settings\All Users\Application Data\{B0AFCE64-DF3F-4824-8985-B21DB0EEE07B}
2007-11-14 11:55 d——– C:\Documents and Settings\All Users\Application Data\{8737778F-82C6-4680-A660-E8B2B8C8C22B}
2007-11-14 11:54 d——– C:\WINDOWS\SxsCaPendDel
2007-11-14 11:52 36 –ah—– C:\WINDOWS\system32\f9t.dat
2007-10-29 12:05 d——– C:\WINDOWS\system32\Mz08r
2007-10-29 12:05 d——– C:\Temp\mZOr
2007-10-20 12:59 d——– C:\Documents and Settings\Shipping\Application Data\InstallShield
2007-10-20 12:03 d——– C:\Program Files\proDAD
2007-10-20 12:00 d——– C:\Program Files\AdorageI-SAL
2007-10-20 12:00 d——– C:\Program Files\AdorageI-GfxDatas
2007-10-20 11:20 466,624 ——— C:\WINDOWS\system32\LTRPR13n.DLL
2007-10-20 11:20 401,408 ——— C:\WINDOWS\system32\pvmjpg30.dll
2007-10-20 11:20 194,248 ——— C:\WINDOWS\system32\LTRFD13n.DLL
2007-10-20 11:20 185,856 ——— C:\WINDOWS\system32\lfpng13s.dll
2007-10-20 11:20 79,360 ——— C:\WINDOWS\system32\lfeps13s.dll
2007-10-20 11:20 74,752 ——— C:\WINDOWS\system32\lfgif13s.dll
2007-10-20 11:20 44,544 ——— C:\WINDOWS\system32\msxml4a.dll
2007-10-20 11:16 765,952 ——— C:\WINDOWS\system32\msvcp71d.dll
2007-10-20 11:16 544,768 ——— C:\WINDOWS\system32\msvcr71d.dll
2007-10-20 11:16 33,340 ——— C:\WINDOWS\system32\dbmsqlgc.dll
2007-10-20 11:16 24,576 ——— C:\WINDOWS\system32\dbmsgnet.dll
2007-10-20 11:09 d——– C:\Program Files\SmartSound Software
2007-10-20 11:09 d——– C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2007-10-20 11:08 84,992 ——— C:\WINDOWS\system32\ATL70.DLL
2007-10-20 11:05 171,008 ——— C:\WINDOWS\system32\drivers\MarvinBus.sys
2007-10-20 11:05 41,219 ——— C:\WINDOWS\RSETPATH.exe
2007-10-20 11:04 49,152 ——— C:\WINDOWS\system32\PCLEGetGuid.dll
2007-10-20 11:03 d——– C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2007-10-20 11:00 d——– C:\Documents and Settings\All Users\Application Data\Pinnacle
2007-10-20 10:59 14,165 ——— C:\WINDOWS\system32\drivers\Pclepci.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-18 20:32 ——— d—–w C:\Program Files\hijackthis2
2007-11-18 08:35 6,252 —-a-w C:\WINDOWS\system32\tmp.reg
2007-11-18 06:32 ——— d—–w C:\Program Files\SUPERAntiSpyware
2007-11-17 07:57 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-17 06:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-16 17:15 ——— d—–w C:\Program Files\Norton Internet Security
2007-11-14 19:56 ——— d—–w C:\Program Files\Stamps.com Internet Postage
2007-10-31 05:39 ——— d–h–w C:\Documents and Settings\John\Application Data\Move Networks
2007-10-31 05:26 ——— d—–w C:\Program Files\PDFtoDOC
2007-10-26 03:39 ——— d–h–w C:\Documents and Settings\Shipping\Application Data\Move Networks
2007-10-20 19:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-20 19:19 ——— d—–w C:\Program Files\Pinnacle
2007-10-20 19:16 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-10-20 19:05 ——— d—–w C:\Program Files\DivX
2007-10-20 18:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-09-24 02:46 ——— d—–w C:\Documents and Settings\John\Application Data\uTorrent
2007-09-24 02:43 ——— d—–w C:\Program Files\Common Files\Fellowes
2007-09-20 20:24 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-09-20 20:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-09-20 20:24 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-09-20 20:24 10,676 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-09-20 20:24 ——— d—–w C:\Program Files\Symantec
2007-09-18 21:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 21:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 21:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 21:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 21:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 21:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 21:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 21:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 21:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-15 23:10:42 1,494,201 –sh–w C:\WINDOWS\system32\rqstv.bak1
2007-05-16 04:15:52 1,540,168 –sh–w C:\WINDOWS\system32\rqstv.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 15:04]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-08-12 17:45 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"Mixersel"="C:\Program Files\Realtek\InstallShield\mixersel.exe" [2003-11-10 18:23]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-11 21:10]
"SoundMan"="SOUNDMAN.EXE" [2004-10-21 15:20 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-21 18:44 C:\WINDOWS\ALCWZRD.EXE]
"LWBMOUSE"="C:\Program Files\Hardware\Wheel Mouse\5.2\MOUSE32A.EXE" [2002-05-24 04:54]
"AS00_Gear311T"="C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe" [2003-12-04 16:13]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22]
"WorkFlowTray"="C:\Program Files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe" [2003-10-29 03:29]
"Opware14"="C:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe" [2003-10-29 03:28]
"OpScheduler"="C:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe" [2003-10-29 03:30]
"PDF Converter Registry Controller"="C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\RegistryController.exe" [2003-09-30 09:55]
"SSPrnAgent"="C:\Program Files\ScanSoft\OmniPagePro14.0\PdfPrn\SPrnAgent.exe" [2003-10-29 02:07]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 17:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-19 23:52]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 C:\WINDOWS\LOGI_MWX.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-10 23:26]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 11:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 18:34]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingB1870"=command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
"SpybotDeletingD2539"=cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Spybot - Search & Destroy"="F:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
"SpybotDeletingA6535"=command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
"SpybotDeletingC4629"=cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-16 18:49:29]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
USB Manager.lnk - C:\Program Files\Belkin\Belkin Wireless USB Adapter Manager\WlanMonitor.exe [2006-01-15 15:02:34]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

S2 CX23880;AVerMedia AVerTV MPEG Video Capture (!);C:\WINDOWS\system32\drivers\A88VidBB.sys
S2 CX88ENC;AVerMedia AVerTV MPEG Encoder;C:\WINDOWS\system32\drivers\A88EncBB.sys
S2 CX88XBAR;AVerMedia AVerTV MPEG Crossbar (Dual-Input);C:\WINDOWS\system32\drivers\A88BarBB.sys
S2 CXTUNE;AVerMedia AVerTV Tuner;C:\WINDOWS\system32\drivers\A88TunBB.sys
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 AWINDIS5;AWINDIS5 Protocol Driver;\??\C:\WINDOWS\system32\AWINDIS5.SYS
S3 CXAVSAUD;AVerMedia AVerTV AvStream Audio Capture;C:\WINDOWS\system32\drivers\A88AudBB.sys
S3 NETGEAR_WG311T_SERVICE;NETGEAR WG311T Wireless Adapter Service;C:\WINDOWS\system32\DRIVERS\wg311tn5.sys
S3 USBFVNETR;Belkin 11Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-17 01:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-11 23:02:10 C:\WINDOWS\Tasks\Shipping Full system backup weekly.job"
"2007-11-17 05:35:07 C:\WINDOWS\Tasks\SmartFTP Client.job"
- C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-18 14:54:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-18 14:54:54
.
— E O F —






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:31 PM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: FormFiller.clsIEInterface - {C668F19A-93FB-49A1-86C4-091E0D624443} - C:\Program Files\Zeus\FormFiller.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Hardware\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [AS00_Gear311T] C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe -hide
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [WorkFlowTray] "C:\Program Files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe"
O4 - HKLM\..\Run: [Opware14] "C:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe"
O4 - HKLM\..\Run: [OpScheduler] "C:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe"
O4 - HKLM\..\Run: [PDF Converter Registry Controller] "C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\RegistryController.exe"
O4 - HKLM\..\Run: [SSPrnAgent] C:\Program Files\ScanSoft\OmniPagePro14.0\PdfPrn\SPrnAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "F:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA6535] command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4629] cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB1870] command /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2539] cmd /c del "C:\WINDOWS\system32\crwntktk.dllbox"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: USB Manager.lnk = C:\Program Files\Belkin\Belkin Wireless USB Adapter Manager\WlanMonitor.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: &Zeus Form Filler - C:\Program Files\Zeus\DragAndDrop.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\IEShellExt.dll /100
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1148337015811
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_9.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8567BDF0-2D23-4AF4-A326-000F08DE4FE8}: NameServer = 208.200.248.1,208.200.248.8
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 10928 bytes
I figured out the likely problem with the safe mode boot. in my boot.ini file there was appended /safeboot:minimal - I removed that command Still could not connect to my inhouse network and internet - the wireless adpater was not being recognized. uninstalled and reinstalled the drivers and adpater, The computer is now booting normally, and able to connect to the internet
Hi

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\gtwhafln.dll
C:\WINDOWS\system32\efcywvs.dll.vir
C:\WINDOWS\system32\f9t.dat
C:\WINDOWS\system32\rqstv.bak1
C:\WINDOWS\system32\rqstv.ini2

Folder::
C:\WINDOWS\system32\rMa02yy
C:\Temp\abW9
C:\Documents and Settings\All Users\Application Data\{D9AA4D17-9292-410D-9AA5-84526D062900}
C:\Documents and Settings\All Users\Application Data\{EF257B1A-26EA-4A90-9BCC-54CA818488E8}
C:\Documents and Settings\All Users\Application Data\{B0AFCE64-DF3F-4824-8985-B21DB0EEE07B}
C:\Documents and Settings\All Users\Application Data\{8737778F-82C6-4680-A660-E8B2B8C8C22B}
C:\WINDOWS\system32\Mz08r
C:\Temp\mZOr


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.
Please post the results of the Kaspersky scan in your next reply, along with a fresh HijackThis log and the ComboFix log.

Thanks,

jpshortstuff
ComboFix 07-11-08.3 - John 2007-11-19 14:26:38.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.951 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\efcywvs.dll.vir
C:\WINDOWS\system32\f9t.dat
C:\WINDOWS\system32\gtwhafln.dll
C:\WINDOWS\system32\rqstv.bak1
C:\WINDOWS\system32\rqstv.ini2
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\FTPx.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.

2007-11-18 20:11 d——– C:\Program Files\NETGEAR
2007-11-18 20:11 344,448 –a—— C:\WINDOWS\system32\drivers\wg311tn5.sys
2007-11-18 20:11 11,861 –a—— C:\WINDOWS\system32\drivers\mdc8021x.sys
2007-11-18 03:37 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-11-17 22:29 d——– C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-11-17 20:11 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-11-14 11:54 d——– C:\WINDOWS\SxsCaPendDel
2007-10-20 12:59 d——– C:\Documents and Settings\Shipping\Application Data\InstallShield
2007-10-20 12:03 d——– C:\Program Files\proDAD
2007-10-20 12:00 d——– C:\Program Files\AdorageI-SAL
2007-10-20 12:00 d——– C:\Program Files\AdorageI-GfxDatas
2007-10-20 11:20 466,624 ——— C:\WINDOWS\system32\LTRPR13n.DLL
2007-10-20 11:20 401,408 ——— C:\WINDOWS\system32\pvmjpg30.dll
2007-10-20 11:20 194,248 ——— C:\WINDOWS\system32\LTRFD13n.DLL
2007-10-20 11:20 185,856 ——— C:\WINDOWS\system32\lfpng13s.dll
2007-10-20 11:20 79,360 ——— C:\WINDOWS\system32\lfeps13s.dll
2007-10-20 11:20 74,752 ——— C:\WINDOWS\system32\lfgif13s.dll
2007-10-20 11:20 44,544 ——— C:\WINDOWS\system32\msxml4a.dll
2007-10-20 11:16 765,952 ——— C:\WINDOWS\system32\msvcp71d.dll
2007-10-20 11:16 544,768 ——— C:\WINDOWS\system32\msvcr71d.dll
2007-10-20 11:16 33,340 ——— C:\WINDOWS\system32\dbmsqlgc.dll
2007-10-20 11:16 24,576 ——— C:\WINDOWS\system32\dbmsgnet.dll
2007-10-20 11:09 d——– C:\Program Files\SmartSound Software
2007-10-20 11:09 d——– C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2007-10-20 11:08 84,992 ——— C:\WINDOWS\system32\ATL70.DLL
2007-10-20 11:05 171,008 ——— C:\WINDOWS\system32\drivers\MarvinBus.sys
2007-10-20 11:05 41,219 ——— C:\WINDOWS\RSETPATH.exe
2007-10-20 11:04 49,152 ——— C:\WINDOWS\system32\PCLEGetGuid.dll
2007-10-20 11:03 d——– C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2007-10-20 11:00 d——– C:\Documents and Settings\All Users\Application Data\Pinnacle
2007-10-20 10:59 14,165 ——— C:\WINDOWS\system32\drivers\Pclepci.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-19 22:12 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-19 04:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 20:32 ——— d—–w C:\Program Files\hijackthis2
2007-11-18 06:32 ——— d—–w C:\Program Files\SUPERAntiSpyware
2007-11-17 06:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-16 17:15 ——— d—–w C:\Program Files\Norton Internet Security
2007-11-14 19:56 ——— d—–w C:\Program Files\Stamps.com Internet Postage
2007-10-31 05:39 ——— d–h–w C:\Documents and Settings\John\Application Data\Move Networks
2007-10-31 05:26 ——— d—–w C:\Program Files\PDFtoDOC
2007-10-26 03:39 ——— d–h–w C:\Documents and Settings\Shipping\Application Data\Move Networks
2007-10-20 19:19 ——— d—–w C:\Program Files\Pinnacle
2007-10-20 19:16 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-10-20 19:05 ——— d—–w C:\Program Files\DivX
2007-10-20 18:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-09-24 02:46 ——— d—–w C:\Documents and Settings\John\Application Data\uTorrent
2007-09-24 02:43 ——— d—–w C:\Program Files\Common Files\Fellowes
2007-09-20 20:24 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-09-20 20:24 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-09-20 20:24 10,676 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-09-20 20:24 ——— d—–w C:\Program Files\Symantec
.

((((((((((((((((((((((((((((( snapshot@2007-11-19_14.06.25.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-19 04:27:47 71,392 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-19 22:27:12 71,392 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-19 04:27:47 423,578 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-19 22:27:12 423,578 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-19 22:30:43 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_5c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 15:04]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-08-12 17:45 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"Mixersel"="C:\Program Files\Realtek\InstallShield\mixersel.exe" [2003-11-10 18:23]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-11 21:10]
"SoundMan"="SOUNDMAN.EXE" [2004-10-21 15:20 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-21 18:44 C:\WINDOWS\ALCWZRD.EXE]
"LWBMOUSE"="C:\Program Files\Hardware\Wheel Mouse\5.2\MOUSE32A.EXE" [2002-05-24 04:54]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22]
"WorkFlowTray"="C:\Program Files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe" [2003-10-29 03:29]
"Opware14"="C:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe" [2003-10-29 03:28]
"OpScheduler"="C:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe" [2003-10-29 03:30]
"PDF Converter Registry Controller"="C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\RegistryController.exe" [2003-09-30 09:55]
"SSPrnAgent"="C:\Program Files\ScanSoft\OmniPagePro14.0\PdfPrn\SPrnAgent.exe" [2003-10-29 02:07]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 17:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-19 23:52]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 C:\WINDOWS\LOGI_MWX.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-10 23:26]
"AS00_Gear311T"="C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe" [2003-12-04 16:13]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 11:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 18:34]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-16 18:49:29]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
USB Manager.lnk - C:\Program Files\Belkin\Belkin Wireless USB Adapter Manager\WlanMonitor.exe [2006-01-15 15:02:34]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 CX23880;AVerMedia AVerTV MPEG Video Capture (!);C:\WINDOWS\system32\drivers\A88VidBB.sys
R2 CX88ENC;AVerMedia AVerTV MPEG Encoder;C:\WINDOWS\system32\drivers\A88EncBB.sys
R2 CX88XBAR;AVerMedia AVerTV MPEG Crossbar (Dual-Input);C:\WINDOWS\system32\drivers\A88BarBB.sys
R2 CXTUNE;AVerMedia AVerTV Tuner;C:\WINDOWS\system32\drivers\A88TunBB.sys
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 AWINDIS5;AWINDIS5 Protocol Driver;\??\C:\WINDOWS\system32\AWINDIS5.SYS
R3 CXAVSAUD;AVerMedia AVerTV AvStream Audio Capture;C:\WINDOWS\system32\drivers\A88AudBB.sys
R3 NETGEAR_WG311T_SERVICE;NETGEAR WG311T Wireless Adapter Service;C:\WINDOWS\system32\DRIVERS\wg311tn5.sys
S3 USBFVNETR;Belkin 11Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-17 01:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-11 23:02:10 C:\WINDOWS\Tasks\Shipping Full system backup weekly.job"
"2007-11-19 04:07:43 C:\WINDOWS\Tasks\SmartFTP Client.job"
- C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 14:31:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-19 14:32:48 - machine was rebooted
C:\ComboFix2.txt … 2007-11-19 14:25
C:\ComboFix3.txt … 2007-11-18 14:54
.
— E O F —





All those backup emails could be deleted they are quite old in the
Kaspersky scan could just be deleted

All 3 logs attached
Highjack log attached
along with copy of combofix

Attachments:

Open Spybot S&D and click on the Recovery button. In the box labled "Backups", select he following items:
Virtumonde.Generic
and then click on Purge selected items at the top.
Click Yes at the prompt.


You can delete all those email backups if you wish.


Hows the computer running now?
The computer is running fine, but I have restricted it's use so far. I have another task right now it will be about 30 minutes or so before I can get to spybot
The others are up to you. The entry I had you remove was contributing to infected objects in your Kaspersky scan, may be picked up by other scanners so best to get rid of it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI