Spyware / Malware / Virus Removal
[Resolved] savetheinformation.com pop-ups, blinking triangle in t
11 min read
helpmeouthere
Topic Starter
Hi, I'm new here cuz I'm desperate to get this thing off of my computer. I have this virus/worm/trojan that brings pop-ups in Internet Explorer to savetheinformation.com, among other things. I also have a blinking yellow triangle in the taskbar that has balloon pop-ups telling me to click on it to download more anti-virus software. System alerts will also try to get me to download more stuff. I've been trying solutions across several boards to fix it, but it seems that everyone who gets this virus has to go through a different process.
Also, Trend Micro Internet Security 2008 and Ad-Aware Personal SE failed to eliminate it.
HiJackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:46 PM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
D:\Program Files\Cursor XP\CursorXP.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
D:\Program Files\Process Viewer\PrcView.exe
C:\WINDOWS\explorer.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\cftokhxg.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 5971 bytes
Help is GREATLY appreciated.
Simon V.
Hello, and welcome to the forum.
My name is Simon V., and I'll be glad to help you with your computer problems.
Step 1
Please right-click on HijackThis.exe and choose Rename. Rename it to Scanner.exe.
Step 2
Please download VundoFix.exe to your desktop.
Step 3
Please download SDFix and save it to your desktop.
Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows directory, typically C:\SDFix)
Please download and install CCleaner.
In your next reply, please post:
My name is Simon V., and I'll be glad to help you with your computer problems.
Step 1
Please right-click on HijackThis.exe and choose Rename. Rename it to Scanner.exe.
Step 2
Please download VundoFix.exe to your desktop.
- Double-click VundoFix.exe to run it.
- Click the Scan for Vundo button.
- Once it's done scanning, click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES.
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will reboot your computer, click OK.
- A logfile will be saved at C:\vundofix.txt.
Step 3
Please download SDFix and save it to your desktop.
Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows directory, typically C:\SDFix)
- Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
- Please reboot into Safe Mode. To do this, go to Start>Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)
- Open the extracted SDFix folder and double-click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any trojan services and registry entries that it finds, then prompt you to press any key to reboot; press any key and it will restart the PC.
- When the PC restarts SDFix will run again and complete the removal process then display Finished. Press any key to end the script and load your desktop icons.
- Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to clipboard ready for posting back on the forum).
Please download and install CCleaner.
- Open CCleaner. In the Left Pane, click Tools.
- Verify that Uninstall is highlighted in color, or click on it.
- In the lower right, click Save to Text File.
- Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
- You can leave the filename as install.txt.
- Click Save.
- Exit Ccleaner by clicking on the X button in the upper right of the CCleaner window.
In your next reply, please post:
- the VundoFix log (C:\vundofix.txt)
- the SDFix log (C:\SDFix\Report.txt)
- the CCleaner Uninstall List
- a new HijackThis (Scanner) log
helpmeouthere
First of all, thank you so much for your response. I'm sure all the "victims" and I are truly thankful for forums such as these and guys like you.
Second, a few things I think you should be aware of.
- I saw that other people were having this same problem and tried a few things while I was waiting for a response. I ran VundoFix in this waiting period, and then I deleted it and re-downloaded it, and ran it as intstructed. So the log this time shows nothing removed. However, I recall the first time the three files it deleted were like ctfmon, ctfmon, and ywvsav.
- I also ran SmitFraudFix.
- I had run SDFix before I posted, but not since then. I think I should also note that it appears as RunThis.cmd instead of Runthis.bat on my computer.
- No pop-ups, no-blinking triangle, no false system messages.
So without further adieu…
VUNDOFIX LOG
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 4:43:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
SDFIX LOG
SDFix: Version 1.115
Run by [removed] on Mon 11/19/2007 at 05:16 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 17:30:18
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\elfsdhwn.exe"="C:\\WINDOWS\\system32\\elf"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\\WINDOWS\\system32\\yuavaiha.exe"="C:\\WINDOWS\\system32\\yua"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
—————
Files with Hidden Attributes:
Thu 1 Nov 2007 230,400 ..SHR — "C:\WINDOWS\AppPatch\i?xplore.exe"
Fri 21 May 2004 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 28 Nov 2005 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Sun 17 Jul 2005 72 A..H. — "C:\Program Files\InterActual\InterActual Player\iti176.tmp"
Sat 6 Jan 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 11 Apr 2005 400 A.SH. — "C:\Documents and Settings\Greg\My Documents\My Music\drmv2key.bak"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoC.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoD.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoE.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoF.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico12.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico40.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico41.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico42.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico43.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico4.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico5.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico6.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico7.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico8.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico9.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoA.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoB.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico13.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico14.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico15.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico16.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico17.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico18.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico19.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico20.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico21.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico22.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico23.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico24.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico25.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico26.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico27.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico28.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico29.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico30.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico31.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico32.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico33.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico34.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico35.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico36.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico37.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico38.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico39.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\Greg\Application Data\U3\temp\Launchpad Removal.exe"
Mon 9 Jul 2007 27,136 …H. — "C:\Documents and Settings\Kim\My Documents\UCLA\T2957 Counseling College Bound Student (Klaar)\~WRL1986.tmp"
Mon 9 Jul 2007 20,992 …H. — "C:\Documents and Settings\Kim\My Documents\UCLA\T2957 Counseling College Bound Student (Klaar)\~WRL3111.tmp"
Thu 4 Oct 2007 44,544 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL3139.tmp"
Thu 4 Oct 2007 47,104 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL0769.tmp"
Thu 4 Oct 2007 46,592 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL0518.tmp"
Wed 4 Jan 2006 2,090 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\PIONEER__DVD-ROM_DVD-117R_1.04_300_DICV018_DRGV2050102.TMP"
Wed 4 Jan 2006 2,111 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\SONY_____CD-RW__CRX175E___1.1a_310_DICV018_DRGV2050102.TMP"
Wed 28 Jun 2006 2,082 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\PIONEER__DVD-ROM_DVD-117R_1.04_300_DICV018_DRGV2050107.TMP"
Wed 28 Jun 2006 2,103 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\SONY_____CD-RW__CRX175E___1.1a_310_DICV018_DRGV2050107.TMP"
Finished!
CCCLEANER LOG
Acez Mp3 Wav Converter v3.0
Ad-Aware SE Personal
Adobe Acrobat 5.0
AIM 6
AutoUpdate
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon CanoScan Toolbox 4.1
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
CD-R Writing Module
ConvertMovie 2.0
Creative Jukebox Driver
Creative Removable Disk Manager
Creative System Information
Creative Zen Micro (PlaysForSure)
CursorXP
Deus Ex - Invisible War
DigitalPrint 1.0
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DVD Audio Extractor 4.2.2
DVDExpress
DVgate
f.y.e. Download Zone
Filzip 3.06
Fraps
GameSpy Arcade
Ghost Recon
Google Toolbar for Internet Explorer
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB926239)
InterActual Player
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
LogonStudio
Macromedia Flash Player 8
Macromedia Shockwave Player
Media Bar 3.2.11
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft GIF Animator
Microsoft Halo
Microsoft Office 2000 SR-1 Premium
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
Motion JPEG Software Decoder
MovieShaker 3.2
Mozilla Firefox (2.0.0.9)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
Music Visualizer Library 1.1
Napster
Napster 3.5 MP3 Encoder
Napster Burn Engine
Native Instruments Kontakt Player Sibelius
Nero Suite
Norton CleanSweep
Norton Speed Disk 6.0 for Windows NT
Norton SystemWorks 2002
Norton Utilities 2002 for Windows
NVIDIA Drivers
O*NET Assessment Tools
OpenMG Limited Patch 4.3-05-10-05-01
OpenMG Secure Module
OpenMG Secure Module 4.3.00
Paint Shop Pro 7 ESD
PDFCreator
Photo Loader 2.2E
Photohands 1.0E
PicoPlayer
PictureGear 5.1
QuickTime
RealJukebox
RealPlayer
Rhapsody Player Engine
Rome - Total War™
Rome Total War - patch 1.3
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Sibelius 3
Sid Meier's Civilization 4
Smart Capture
Soldier of Fortune II - Double Helix GOLD
Sony Certificate PCH
Sony DV Shared Library
Splinter Cell Pandora Tomorrow
Star Wars Battlefront II
Star Wars Jedi Knight Jedi Academy
Star Wars® Knights of the Old Republic® II: The Sith Lords™
Star Wars®: Knights of the Old Republic ™
Starcraft
Support Actions Win2K,WinXP
Test of Time Patch
Tom Clancy's Splinter Cell Chaos Theory
Trend Micro Internet Security
Trend Micro TrendProtect for Internet Explorer
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VAIO Action Setup
VAIO Grid Wallpaper
VAIO Help & Support
VAIO Registration
VAIO Support
VAIOWorld
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinGroove (Software WaveTable Synthesizer)
WinRAR archiver
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:52:23 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\yuavaiha.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\Scanner.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: {749f5f1f-d827-ba8a-8154-99eb86755154} - {45155768-be99-4518-a8ab-728df1f5f947} - C:\WINDOWS\system32\sjpfreoa.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\khfdedd.dll
O2 - BHO: (no name) - {C86D6590-71CF-4B4E-92C6-69A36990D12A} - C:\WINDOWS\system32\awvvw.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [1052b0e9] rundll32.exe "C:\WINDOWS\system32\newtrddq.dll",b
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - Winlogon Notify: khfdedd - C:\WINDOWS\SYSTEM32\khfdedd.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\yuavaiha.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7178 bytes
Second, a few things I think you should be aware of.
- I saw that other people were having this same problem and tried a few things while I was waiting for a response. I ran VundoFix in this waiting period, and then I deleted it and re-downloaded it, and ran it as intstructed. So the log this time shows nothing removed. However, I recall the first time the three files it deleted were like ctfmon, ctfmon, and ywvsav.
- I also ran SmitFraudFix.
- I had run SDFix before I posted, but not since then. I think I should also note that it appears as RunThis.cmd instead of Runthis.bat on my computer.
- No pop-ups, no-blinking triangle, no false system messages.
So without further adieu…
VUNDOFIX LOG
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 4:43:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
SDFIX LOG
SDFix: Version 1.115
Run by [removed] on Mon 11/19/2007 at 05:16 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 17:30:18
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\elfsdhwn.exe"="C:\\WINDOWS\\system32\\elf"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\\WINDOWS\\system32\\yuavaiha.exe"="C:\\WINDOWS\\system32\\yua"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
—————
Files with Hidden Attributes:
Thu 1 Nov 2007 230,400 ..SHR — "C:\WINDOWS\AppPatch\i?xplore.exe"
Fri 21 May 2004 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 28 Nov 2005 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Sun 17 Jul 2005 72 A..H. — "C:\Program Files\InterActual\InterActual Player\iti176.tmp"
Sat 6 Jan 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 11 Apr 2005 400 A.SH. — "C:\Documents and Settings\Greg\My Documents\My Music\drmv2key.bak"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoC.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoD.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoE.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoF.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico12.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico40.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico41.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico42.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico43.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico4.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico5.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico6.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico7.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico8.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico9.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoA.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\icoB.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico13.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico14.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico15.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico16.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico17.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico18.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico19.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico20.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico21.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico22.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico23.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico24.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico25.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico26.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico27.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico28.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico29.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2B.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2C.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2D.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2E.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico2F.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico30.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico31.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico32.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico33.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico34.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico35.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico36.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico37.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico38.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico39.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico3A.tmp"
Sun 18 Nov 2007 4,286 A..H. — "C:\Documents and Settings\Kim\Local Settings\temp\ico1.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\Greg\Application Data\U3\temp\Launchpad Removal.exe"
Mon 9 Jul 2007 27,136 …H. — "C:\Documents and Settings\Kim\My Documents\UCLA\T2957 Counseling College Bound Student (Klaar)\~WRL1986.tmp"
Mon 9 Jul 2007 20,992 …H. — "C:\Documents and Settings\Kim\My Documents\UCLA\T2957 Counseling College Bound Student (Klaar)\~WRL3111.tmp"
Thu 4 Oct 2007 44,544 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL3139.tmp"
Thu 4 Oct 2007 47,104 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL0769.tmp"
Thu 4 Oct 2007 46,592 …H. — "C:\Documents and Settings\Kim\Application Data\Microsoft\Word\~WRL0518.tmp"
Wed 4 Jan 2006 2,090 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\PIONEER__DVD-ROM_DVD-117R_1.04_300_DICV018_DRGV2050102.TMP"
Wed 4 Jan 2006 2,111 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\SONY_____CD-RW__CRX175E___1.1a_310_DICV018_DRGV2050102.TMP"
Wed 28 Jun 2006 2,082 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\PIONEER__DVD-ROM_DVD-117R_1.04_300_DICV018_DRGV2050107.TMP"
Wed 28 Jun 2006 2,103 A.SH. — "C:\Documents and Settings\Greg\Application Data\Roxio\Dragon\DiscInfoCache\SONY_____CD-RW__CRX175E___1.1a_310_DICV018_DRGV2050107.TMP"
Finished!
CCCLEANER LOG
Acez Mp3 Wav Converter v3.0
Ad-Aware SE Personal
Adobe Acrobat 5.0
AIM 6
AutoUpdate
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon CanoScan Toolbox 4.1
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
CD-R Writing Module
ConvertMovie 2.0
Creative Jukebox Driver
Creative Removable Disk Manager
Creative System Information
Creative Zen Micro (PlaysForSure)
CursorXP
Deus Ex - Invisible War
DigitalPrint 1.0
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DVD Audio Extractor 4.2.2
DVDExpress
DVgate
f.y.e. Download Zone
Filzip 3.06
Fraps
GameSpy Arcade
Ghost Recon
Google Toolbar for Internet Explorer
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB926239)
InterActual Player
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
LogonStudio
Macromedia Flash Player 8
Macromedia Shockwave Player
Media Bar 3.2.11
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft GIF Animator
Microsoft Halo
Microsoft Office 2000 SR-1 Premium
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
Motion JPEG Software Decoder
MovieShaker 3.2
Mozilla Firefox (2.0.0.9)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
Music Visualizer Library 1.1
Napster
Napster 3.5 MP3 Encoder
Napster Burn Engine
Native Instruments Kontakt Player Sibelius
Nero Suite
Norton CleanSweep
Norton Speed Disk 6.0 for Windows NT
Norton SystemWorks 2002
Norton Utilities 2002 for Windows
NVIDIA Drivers
O*NET Assessment Tools
OpenMG Limited Patch 4.3-05-10-05-01
OpenMG Secure Module
OpenMG Secure Module 4.3.00
Paint Shop Pro 7 ESD
PDFCreator
Photo Loader 2.2E
Photohands 1.0E
PicoPlayer
PictureGear 5.1
QuickTime
RealJukebox
RealPlayer
Rhapsody Player Engine
Rome - Total War™
Rome Total War - patch 1.3
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Sibelius 3
Sid Meier's Civilization 4
Smart Capture
Soldier of Fortune II - Double Helix GOLD
Sony Certificate PCH
Sony DV Shared Library
Splinter Cell Pandora Tomorrow
Star Wars Battlefront II
Star Wars Jedi Knight Jedi Academy
Star Wars® Knights of the Old Republic® II: The Sith Lords™
Star Wars®: Knights of the Old Republic ™
Starcraft
Support Actions Win2K,WinXP
Test of Time Patch
Tom Clancy's Splinter Cell Chaos Theory
Trend Micro Internet Security
Trend Micro TrendProtect for Internet Explorer
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VAIO Action Setup
VAIO Grid Wallpaper
VAIO Help & Support
VAIO Registration
VAIO Support
VAIOWorld
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinGroove (Software WaveTable Synthesizer)
WinRAR archiver
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:52:23 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\yuavaiha.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\Scanner.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: {749f5f1f-d827-ba8a-8154-99eb86755154} - {45155768-be99-4518-a8ab-728df1f5f947} - C:\WINDOWS\system32\sjpfreoa.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\khfdedd.dll
O2 - BHO: (no name) - {C86D6590-71CF-4B4E-92C6-69A36990D12A} - C:\WINDOWS\system32\awvvw.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [1052b0e9] rundll32.exe "C:\WINDOWS\system32\newtrddq.dll",b
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - Winlogon Notify: khfdedd - C:\WINDOWS\SYSTEM32\khfdedd.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\yuavaiha.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7178 bytes
Simon V.
Hi 
Step 1
Click on Start, then Control Panel. Double click on Add or Remove Programs.
Please remove the following program(s):
Double-click VundoFix.exe to run it.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Step 3
Please download Deckard's System Scanner (DSS) and save it to your desktop.
In your next reply, please post:
Can you post the log it created? It can normally be found here: C:\rapport.txt.I also ran SmitFraudFix.
That's good to hear, though we're not finished yet. There are still some infections showing.No pop-ups, no-blinking triangle, no false system messages.
Step 1
Click on Start, then Control Panel. Double click on Add or Remove Programs.
Please remove the following program(s):
- J2SE Runtime Environment 5.0
- J2SE Runtime Environment 5.0 Update 10
- J2SE Runtime Environment 5.0 Update 11
- J2SE Runtime Environment 5.0 Update 2
- J2SE Runtime Environment 5.0 Update 4
- J2SE Runtime Environment 5.0 Update 6
- J2SE Runtime Environment 5.0 Update 9
- Java 6 Update 2
- Java SE Runtime Environment 6 Update 1
Double-click VundoFix.exe to run it.
- Click the Scan for Vundo button.
- Once the scan is complete, right-click inside the listbox (white box) and click Add More Files.
- Copy & paste the entries below into the boxes:
C:\WINDOWS\system32\khfdedd.dll C:\WINDOWS\system32\awvvw.dll C:\WINDOWS\system32\newtrddq.dll
- Click Add Files and click Close Window.
- Click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES.
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will reboot your computer, click OK.
- A logfile will be saved at C:\vundofix.txt.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Step 3
Please download Deckard's System Scanner (DSS) and save it to your desktop.
- Close all other windows before proceeding.
- Double-click on dss.exe and follow the prompts.
- When it has finished, Deckard's System Scanner will open two Notepad files: main.txt and extra.txt - please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
In your next reply, please post:
- C:\rapport.txt (if/when found)
- the Vundofix log (C:\vundofix.txt)
- main.txt and extra.txt (from Deckard's System Scanner)
- a new HijackThis log
helpmeouthere
Here we go:
RAPPORT LOG
SmitFraudFix v2.253
Scan done at 22:23:17.50, Sun 11/18/2007
Run from C:\Documents and Settings\Greg\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
VUNDOFIX LOG
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 4:43:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:12:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
Attempting to delete C:\WINDOWS\system32\awvvw.dll
C:\WINDOWS\system32\awvvw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\newtrddq.dll
C:\WINDOWS\system32\newtrddq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal…
DSS LOG
Main
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-19 23:40:48
Computer is in Normal Mode.
——————————————————————————–
– System Restore ————————————————————–
Successfully created a Deckard's System Scanner Restore Point.
– Last 5 Restore Point(s) –
14: 2007-11-20 07:40:56 UTC - RP14 - Deckard's System Scanner Restore Point
13: 2007-11-20 07:07:31 UTC - RP13 - Removed Java™ SE Runtime Environment 6 Update 1
12: 2007-11-20 07:04:59 UTC - RP12 - Removed Java™ 6 Update 2
11: 2007-11-20 06:59:48 UTC - RP11 - Removed J2SE Runtime Environment 5.0 Update 9
10: 2007-11-20 06:57:51 UTC - RP10 - Removed J2SE Runtime Environment 5.0 Update 6
– First Restore Point –
1: 2007-11-18 20:29:24 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 384 MiB (512 MiB recommended).
– HijackThis (run as Greg.exe) ————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:21 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\yuavaiha.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Documents and Settings\Greg\Desktop\dss.exe
C:\Program Files\Trend Micro\Internet Security\UfUpdUi.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe
C:\WINDOWS\system32\wscntfy.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: {749f5f1f-d827-ba8a-8154-99eb86755154} - {45155768-be99-4518-a8ab-728df1f5f947} - C:\WINDOWS\system32\sjpfreoa.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8393FA59-D407-4620-BBBB-EA67F53D007E} - C:\WINDOWS\system32\awvvw.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\khfdedd.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [1052b0e9] rundll32.exe "C:\WINDOWS\system32\newtrddq.dll",b
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\yuavaiha.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7226 bytes
– File Associations ———————————————————–
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.bat - batfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.cmd - cmdfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.inf - inffile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.reg - regfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
.vbs - VBSFile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
RAPPORT LOG
SmitFraudFix v2.253
Scan done at 22:23:17.50, Sun 11/18/2007
Run from C:\Documents and Settings\Greg\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{686D99F5-4AFF-4B28-AE6C-8380E69D6532}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
VUNDOFIX LOG
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 4:43:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:12:08 PM 11/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
Attempting to delete C:\WINDOWS\system32\awvvw.dll
C:\WINDOWS\system32\awvvw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\newtrddq.dll
C:\WINDOWS\system32\newtrddq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\khfdedd.dll
C:\WINDOWS\system32\khfdedd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal…
DSS LOG
Main
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-19 23:40:48
Computer is in Normal Mode.
——————————————————————————–
– System Restore ————————————————————–
Successfully created a Deckard's System Scanner Restore Point.
– Last 5 Restore Point(s) –
14: 2007-11-20 07:40:56 UTC - RP14 - Deckard's System Scanner Restore Point
13: 2007-11-20 07:07:31 UTC - RP13 - Removed Java™ SE Runtime Environment 6 Update 1
12: 2007-11-20 07:04:59 UTC - RP12 - Removed Java™ 6 Update 2
11: 2007-11-20 06:59:48 UTC - RP11 - Removed J2SE Runtime Environment 5.0 Update 9
10: 2007-11-20 06:57:51 UTC - RP10 - Removed J2SE Runtime Environment 5.0 Update 6
– First Restore Point –
1: 2007-11-18 20:29:24 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 384 MiB (512 MiB recommended).
– HijackThis (run as Greg.exe) ————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:21 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\yuavaiha.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Documents and Settings\Greg\Desktop\dss.exe
C:\Program Files\Trend Micro\Internet Security\UfUpdUi.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe
C:\WINDOWS\system32\wscntfy.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: {749f5f1f-d827-ba8a-8154-99eb86755154} - {45155768-be99-4518-a8ab-728df1f5f947} - C:\WINDOWS\system32\sjpfreoa.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8393FA59-D407-4620-BBBB-EA67F53D007E} - C:\WINDOWS\system32\awvvw.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\khfdedd.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [1052b0e9] rundll32.exe "C:\WINDOWS\system32\newtrddq.dll",b
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\yuavaiha.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7226 bytes
– File Associations ———————————————————–
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.bat - batfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.cmd - cmdfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.inf - inffile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.reg - regfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
.vbs - VBSFile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
helpmeouthere
BTW, I get this error when I start up. (Attachment)
Simon V.
Hi 
That error will be fixed - Please do the following:
Step 1
Be sure that you are set to see hidden files and folders:
Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)
Go to File > Save As:. Save the file as "Fix.bat" (Including the quotes)
Step 3
Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
Please reboot into Safe Mode. To do this, go to Start > Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking).
Step 4
Double-click on Fix.bat to run the file.
Next, navigate to the following files/folders using Windows Explorer and delete them when found:
C:\WINDOWS\AppPatch\i?xplore.exe <– File (This file will probably be named iexplore.exe, probably with a weird e)
C:\WINDOWS\?ppPatch\ <– Folder (Note: Do not delete the legit AppPatch folder! This one probably has a weird sign in its name too)
Reboot into Normal Mode.
Step 5
Download OTMoveIt by OldTimer.
Note: Make sure Deckard's System Scanner (dss.exe) is located on your desktop before proceeding.
Go to Start > Run… and copy/paste the text below into the Runbox:
A windows will open. Click on Check All, then click Scan!.
When it has finished, Deckard's System Scanner will open two Notepad files: main.txt and extra.txt- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply, along with the OTMoveIt log and a new HijackThis log. Also tell me how everything is running.
That error will be fixed - Please do the following:
Step 1
Be sure that you are set to see hidden files and folders:
- Close all programs so that you are at your desktop.
- Double-click on the My Computer icon.
- Select the Tools menu and click Folder Options.
- After the new window appears select the View tab.
- Put a checkmark in the checkbox labelled Display the contents of system folders.
- Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
- Remove the checkmark from the checkbox labelled Hide file extensions for known file types.
- Remove the checkmark from the checkbox labelled Hide protected operating system files. Answer Yes to the prompt.
- Press the Apply button and then the OK button and shutdown My Computer.
Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)
@echo off
sc stop nsysaudm
sc delete nsysaudm
sc stop DomainService
sc delete DomainService
FOR %%F IN (
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nsysaudm"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsysaudm"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\nsysaudm"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DomainService"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DomainService"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DomainService"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45155768-be99-4518-a8ab-728df1f5f947}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8393FA59-D407-4620-BBBB-EA67F53D007E}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"
"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1052b0e9"
"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Agcl"
"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iinl"
) DO (
reg delete %%F /f
)
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v 1052b0e9 /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" /v {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} /f
reg delete "HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v C:\\WINDOWS\\system32\\elfsdhwn.exe /f
reg delete "HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v C:\\WINDOWS\\system32\\yuavaiha.exe /f
reg add HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /v "Authentication Packages" /d msv1_0 /t REG_MULTI_SZ /f
exit
Go to File > Save As:. Save the file as "Fix.bat" (Including the quotes)
Step 3
Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
Please reboot into Safe Mode. To do this, go to Start > Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking).
Step 4
Double-click on Fix.bat to run the file.
Next, navigate to the following files/folders using Windows Explorer and delete them when found:
C:\WINDOWS\AppPatch\i?xplore.exe <– File (This file will probably be named iexplore.exe, probably with a weird e)
C:\WINDOWS\?ppPatch\ <– Folder (Note: Do not delete the legit AppPatch folder! This one probably has a weird sign in its name too)
Reboot into Normal Mode.
Step 5
Download OTMoveIt by OldTimer.
- Double-click on OTMoveIt.exe to start the program.
[external image: Posted Image] - Untick the option to Unregister Dll's and Ocx's (1).
- Select the contents of the below codebox, then press Ctrl+C to copy it to the clipboard.
C:\WINDOWS\system32\jkhhg.dll C:\WINDOWS\system32\sjpfreoa.dll C:\WINDOWS\system32\yuavaiha.exe C:\WINDOWS\system32\inrseogq.dll C:\WINDOWS\system32\oivhaitm.dll C:\WINDOWS\system32\wvvwa.ini2 C:\WINDOWS\system32\khfdedd.dll C:\WINDOWS\system32\yuavaiha.exe
- In OTMoveIt right-click on the box labelled Paste List of Files/Folders to be Moved.
- Click Paste (2).
- Click MoveIt! (3).
- If it asks you to reboot allow that.
- A logfile will be created at C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
Note: Make sure Deckard's System Scanner (dss.exe) is located on your desktop before proceeding.
Go to Start > Run… and copy/paste the text below into the Runbox:
"%userprofile%\desktop\dss.exe" /config
A windows will open. Click on Check All, then click Scan!.
When it has finished, Deckard's System Scanner will open two Notepad files: main.txt and extra.txt- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply, along with the OTMoveIt log and a new HijackThis log. Also tell me how everything is running.
helpmeouthere
First off, with the previous round of fixes, I'm not sure "C:\WINDOWS\system32\khfdedd.dll" was deleted, because it didn't delete it the first time, reboot, didn't delete that time either, reboot, and then it wasn't on the list. It probably was though, since I'm looking at \system32 right now, and I don't see it.
DSS LOGS
Main
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-20 16:23:49
Computer is in Normal Mode.
——————————————————————————–
– System Restore ————————————————————–
– Last 5 Restore Point(s) –
14: 2007-11-20 07:40:56 UTC - RP14 - Deckard's System Scanner Restore Point
13: 2007-11-20 07:07:31 UTC - RP13 - Removed Java™ SE Runtime Environment 6 Update 1
12: 2007-11-20 07:04:59 UTC - RP12 - Removed Java™ 6 Update 2
11: 2007-11-20 06:59:48 UTC - RP11 - Removed J2SE Runtime Environment 5.0 Update 9
10: 2007-11-20 06:57:51 UTC - RP10 - Removed J2SE Runtime Environment 5.0 Update 6
– First Restore Point –
1: 2007-11-18 20:29:24 UTC - RP1 - System Checkpoint
Performed disk cleanup.
Total Physical Memory: 384 MiB (512 MiB recommended).
– HijackThis (run as Greg.exe) ————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:24:05 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Documents and Settings\Greg\desktop\dss.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6697 bytes
– File Associations ———————————————————–
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.bat - batfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.cmd - cmdfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.inf - inffile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.reg - regfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
.vbs - VBSFile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
DSS LOGS
Main
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-20 16:23:49
Computer is in Normal Mode.
——————————————————————————–
– System Restore ————————————————————–
– Last 5 Restore Point(s) –
14: 2007-11-20 07:40:56 UTC - RP14 - Deckard's System Scanner Restore Point
13: 2007-11-20 07:07:31 UTC - RP13 - Removed Java™ SE Runtime Environment 6 Update 1
12: 2007-11-20 07:04:59 UTC - RP12 - Removed Java™ 6 Update 2
11: 2007-11-20 06:59:48 UTC - RP11 - Removed J2SE Runtime Environment 5.0 Update 9
10: 2007-11-20 06:57:51 UTC - RP10 - Removed J2SE Runtime Environment 5.0 Update 6
– First Restore Point –
1: 2007-11-18 20:29:24 UTC - RP1 - System Checkpoint
Performed disk cleanup.
Total Physical Memory: 384 MiB (512 MiB recommended).
– HijackThis (run as Greg.exe) ————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:24:05 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Documents and Settings\Greg\desktop\dss.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6697 bytes
– File Associations ———————————————————–
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.bat - batfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.cmd - cmdfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.inf - inffile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - shell\open\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.reg - regfile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
.vbs - VBSFile - shell\edit\command - C:\WINDOWS\ServicePackFiles\i386\notepad.exe %1
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
Simon V.
Hi 
I see you have Norton SystemWorks installed - Does this mean you have two anti-virus programs intalled (Kasperksy and Norton)?
It's a real persistent infection, but we've almost got it
A few files left over to clean:
Step 1
Double-click on OTMoveIt.exe to start the program.
[external image: Posted Image]
Open HijackThis, perform a scan and put a check next to the following items (if present):
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Close all programs except HijackThis and click on Fix checked.
Step 3
Copy the text below into a Notepad (Go to Start > Run, type Notepad and hit Enter) document:
Note: Make sure there is no blank line before REGEDIT4 and one blank line at the end.
Go to File > Save As:. Save the file as "Fix.reg" (Including the quotes)
Double-click on Fix.reg. When asked if you want to merge the file with the registry, click Yes.
Step 4
Please do an online scan with Kaspersky WebScanner.
Click on Kaspersky Online Scanner. On the welcome screen, click Accept.
You will be promted to install an ActiveX component from Kaspersky, click Install.
In your next reply, please post:
I see you have Norton SystemWorks installed - Does this mean you have two anti-virus programs intalled (Kasperksy and Norton)?
It's a real persistent infection, but we've almost got it
Step 1
Double-click on OTMoveIt.exe to start the program.
[external image: Posted Image]
- Untick the option to Unregister Dll's and Ocx's (1).
- Select the contents of the below codebox, then press Ctrl+C to copy it to the clipboard.
C:\WINDOWS\system32\ddaby.dll C:\WINDOWS\system32\mllmm.dll
- In OTMoveIt right-click on the box labelled Paste List of Files/Folders to be Moved.
- Click Paste (2).
- Click MoveIt! (3).
- If it asks you to reboot allow that.
- A logfile will be created at C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
Open HijackThis, perform a scan and put a check next to the following items (if present):
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Close all programs except HijackThis and click on Fix checked.
Step 3
Copy the text below into a Notepad (Go to Start > Run, type Notepad and hit Enter) document:
REGEDIT4 [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\\WINDOWS\\system32\\elfsdhwn.exe"=- "C:\\WINDOWS\\system32\\yuavaiha.exe"=-
Note: Make sure there is no blank line before REGEDIT4 and one blank line at the end.
Go to File > Save As:. Save the file as "Fix.reg" (Including the quotes)
Double-click on Fix.reg. When asked if you want to merge the file with the registry, click Yes.
Step 4
Please do an online scan with Kaspersky WebScanner.
Click on Kaspersky Online Scanner. On the welcome screen, click Accept.
You will be promted to install an ActiveX component from Kaspersky, click Install.
- The program will launch and then begin downloading the latest definition files.
- Once the files have been downloaded click on Next.
- Now click on Scan Settings.
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
Extended (if available, otherwise Standard)
- Scan Options:
Scan Archives
Scan Mail Bases
- Click OK.
- Now under Select a Target to Scan:
Select My Computer.
- The program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button and save the file to your desktop.
In your next reply, please post:
- the OTMoveIt log
- the Kaspersky Online Scan report
- a new HijackThis log
helpmeouthere
Note: Up til now, I've been using Firefox. When the pop-ups came up, they came up in IE, and I noticed a fake "security toolbar". That's gone now. Kaspersky said I needed to use IE, but when I try to install the ActiveX, it just returns me to the Accept/Decline screen. I've tried about 20 times, I've tried turning off Trend Micro Protection, and I tried adding it to Trused Sites. Still won't install. Doesn't work in Firefox either.
Note 2: I have Norton SystemWorks, but not Norton Antivirus. Also, I don't have Kaspersky. Also, I only installed Trend Micro after I got the virus.
OTMOVEIT LOG
C:\WINDOWS\system32\ddaby.dll moved successfully.
C:\WINDOWS\system32\mllmm.dll moved successfully.
Created on 11/21/2007 06:55:00
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:35 AM, on 11/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Trend Micro\HijackThis\Scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.wikipedia.org/wiki/Main_Page
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6539 bytes
Note 2: I have Norton SystemWorks, but not Norton Antivirus. Also, I don't have Kaspersky. Also, I only installed Trend Micro after I got the virus.
OTMOVEIT LOG
C:\WINDOWS\system32\ddaby.dll moved successfully.
C:\WINDOWS\system32\mllmm.dll moved successfully.
Created on 11/21/2007 06:55:00
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:35 AM, on 11/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Cursor XP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Trend Micro\HijackThis\Scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.wikipedia.org/wiki/Main_Page
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\Stardock\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\Cursor XP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton\SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\Norton\SYSTEM~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6539 bytes
helpmeouthere
Also, is it okay that I have seven SVCHOST.exe running?
Simon V.
Also, is it okay that I have seven SVCHOST.exe running?
That's very normal
Those logs look clean… How is your computer running now?
helpmeouthere
Even though I didn't run Kaspersky? Cool. My computer's still a bit slow, but we have been moving around a lot of data. No oddities whatsoever.
If we're completely finished, how do I uninstall/remove all the stuff I downloaded?
And if the "virus" came with a file I downloaded, like a picture or an mp3, how do I know that file isn't still a carrier?
Hoping everything is good here.
helpmeouthere
And every time I open a favorite from my favorites in the Start Menu, I get an error that says that Windows can't find the web address, yet Mozilla goes straight to it. How do I fix that? (Mozilla is my default browser)
Simon V.
Hi 
Note: You will need to use Internet Explorer for this scan.
Please open OTMoveIt.
We can still run another on line scan to be completely sure:Even though I didn't run Kaspersky? Cool.
Note: You will need to use Internet Explorer for this scan.
- Go here to run an online scan from F-Secure.
- Click on Start scanning.
- This will open a new Internet Explorer window.
- It will require an Activex control, please install it.
- Click Accept.
- Click Full System Scan.
- It will now download the scanner, this may take a while, please be patient.
- It will then start scanning, wait for the scan to finish.
- Click Automatic cleaning (recommended).
- Wait for it finish the cleaning process.
- Click Show report.
- This will open up a window with the results of the scan, copy and paste those results as a reply to this topic.
This can be done with OTMoveIt:If we're completely finished, how do I uninstall/remove all the stuff I downloaded?
Please open OTMoveIt.
- Click on the CleanUp! button. If your Firewall gives a warning about OTMoveIt wanting to download a file, allow it.
- Answer Yes to the prompt.
- The program will ask for a reboot. Answer Yes.
If a file is the cause of the infection, it keeps 'carrying' it, until deleted. If you know what caused the infection, you should delete it immediately to prevent future malware on your computer.And if the "virus" came with a file I downloaded, like a picture or an mp3, how do I know that file isn't still a carrier?
Can you give me the exact error message?And every time I open a favorite from my favorites in the Start Menu, I get an error that says that Windows can't find the web address
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI