This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] security toolbar7.1 virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer has been infected with the securuty toolbar 7.1 virus. i have read all the info i can, and have tried to manualy remove the virus, but could not. i need help in remving this virus becouse it is distroing my computer and ha already caused id theift. can anyone PLEASE HELP !!!!
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

The first step in cleaning the malware you have on your computer, is creating a HijackThis log:

Download HJTInstall.exe to your desktop.

  • Doubleclick HJTInstall.exe to install HijackThis.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in Notepad. Post the contents of the log back here please.

Don't use the AnalyseThis button, its findings are dangerous if misinterpreted.
Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
i have followd the instuctions on downloadind combofix and ran the scan, took about 20 min, and gave me the text listed. after it was complete, and i opened my ie, the tool bar was stll there, and i still have the same problomes. WHAT DO I DO. I NEED HEPL!!!
thanx,
paulferguson


ComboFix 07-11-19.3 - Tim 2007-11-23 13:45:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.101 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\D3AAR6RY\ComboFix[1].exe
* Created a new restore point
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Starware381
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\1316_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\1316_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\1317_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\TMB40.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\TMB50.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\TMB60.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\buttons\TMB70.bmp
C:\Documents and Settings\All Users\Application Data\Starware381\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware381\contexts\Related.xml
C:\Documents and Settings\All Users\Application Data\Starware381\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware381\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware381\Tem22.tmp
C:\Documents and Settings\All Users\Application Data\Starware381\TemC9E.tmp
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\LocalService\Application Data\Starware381
C:\Documents and Settings\LocalService\Application Data\Starware381\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Configurator\Configurator.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Configurator\Configurator.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Layouts\ToolbarLayout.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Manager\ManagerOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Music_News\Music_NewsOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Music_News\Music_NewsOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB4\TMB4Options.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB4\TMB4Options.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB5\TMB5Options.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB5\TMB5Options.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB6\TMB6Options.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB6\TMB6Options.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB7\TMB7Options.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\TMB7\TMB7Options.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\RACLE~1
C:\Documents and Settings\Tim\Application Data\Starware381
C:\Documents and Settings\Tim\Application Data\Starware381\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Tim\Application Data\Starware381\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Configurator\Configurator.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Configurator\Configurator.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Layouts\PreferencesLayout.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Layouts\PreferencesLayout.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Manager\ManagerOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Music_News\Music_NewsOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Music_News\Music_NewsOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Tem26E.tmp
C:\Documents and Settings\Tim\Application Data\Starware381\TemCAB.tmp
C:\Documents and Settings\Tim\Application Data\Starware381\TMB4\TMB4Options.xml
C:\Documents and Settings\Tim\Application Data\Starware381\TMB4\TMB4Options.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\TMB5\TMB5Options.xml
C:\Documents and Settings\Tim\Application Data\Starware381\TMB5\TMB5Options.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\TMB6\TMB6Options.xml
C:\Documents and Settings\Tim\Application Data\Starware381\TMB6\TMB6Options.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\TMB7\TMB7Options.xml
C:\Documents and Settings\Tim\Application Data\Starware381\TMB7\TMB7Options.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Tim\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\Tim\Application Data\WinTouch
C:\Documents and Settings\Tim\Application Data\WinTouch\wintouch.cfg
C:\Program Files\inetget2
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\network monitor
C:\Program Files\Starware381
C:\Program Files\Starware381\bin\Starware381.dll
C:\Program Files\Starware381\icons\star_16.ico
C:\Program Files\Starware381\Starware381Config.xml
C:\Program Files\Starware381\Starware381Uninstall.exe
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\WINDOWS\b111.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\BrowserSearch\BrowserSearch.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\BrowserSearch\BrowserSearch.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Configurator\Configurator.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Configurator\Configurator.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ErrorSearch\ErrorSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Layouts\ToolbarLayout.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Layouts\ToolbarLayout.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Manager\ManagerOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Manager\ManagerOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Music_Info_Search\Music_Info_SearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Music_News\Music_NewsOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Music_News\Music_NewsOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\RelatedSearch\RelatedSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB4\TMB4Options.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB4\TMB4Options.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB5\TMB5Options.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB5\TMB5Options.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB6\TMB6Options.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB6\TMB6Options.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB7\TMB7Options.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TMB7\TMB7Options.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Toolbar\TBProductsOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\Toolbar\TBProductsOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware381\TravelSearch\TravelSearchOptions.xml.backup
C:\WINDOWS\system32\nsp3CD.dll
C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\uninstall_nmon.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\Network Monitor


((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-22 18:22 d——– C:\Program Files\Common Files\Download Manager
2007-11-22 12:33 d——– C:\Program Files\Video Add-on
2007-11-21 18:24 d——– C:\Documents and Settings\Tim\Application Data\Sonic
2007-11-21 12:40 d——– C:\Program Files\IrfanView
2007-11-20 14:48 d——– C:\Program Files\Alwil Software
2007-11-20 14:37 d——– C:\Program Files\Ares
2007-11-20 13:16 d——– C:\Program Files\Common Files\Nullsoft
2007-11-20 06:52 74,752 –a—— C:\WINDOWS\system32\gzmrotate.dll
2007-11-18 21:04 0 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-11-18 15:29 d——– C:\Documents and Settings\Tim\Application Data\Move Networks
2007-11-18 00:18 36,352 –a—— C:\WINDOWS\system32\nnnlljh.dll
2007-11-17 23:29 d——– C:\Program Files\InterActual
2007-11-17 23:27 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-11-17 22:52 d–hs—- C:\WINDOWS\VGlt
2007-11-17 13:52 d——– C:\Documents and Settings\Tim\Application Data\RegClean
2007-11-17 13:51 d——– C:\Program Files\RegClean
2007-11-17 13:34 d——– C:\Program Files\Windows Live Safety Center
2007-11-17 00:06 36,352 –a—— C:\WINDOWS\system32\hggedcc.dll
2007-11-16 05:07 36,352 –a—— C:\WINDOWS\system32\ljjgdaa.dll
2007-11-15 22:14 d——– C:\Documents and Settings\Tim\Application Data\Adssite Advanced Toolbar
2007-11-15 22:14 40,733 –a—— C:\WINDOWS\system32\rightonadz-uninst.exe
2007-11-15 22:14 36,352 –a—— C:\WINDOWS\system32\khfgfca.dll
2007-11-15 22:14 4,961 –a—— C:\Documents and Settings\Tim\z.dat
2007-11-15 22:14 3,031 –a—— C:\Documents and Settings\Tim\x.dat
2007-11-15 22:14 120 –a—— C:\n.bat
2007-11-15 22:14 0 –a—— C:\z.dat
2007-11-15 22:14 0 –a—— C:\x.dat
2007-11-15 22:12 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-13 18:12 d——– C:\Program Files\Bullfrog
2007-11-13 18:12 156 –a—— C:\WINDOWS\tmpcpyis.bat
2007-11-13 18:12 122 –a—— C:\WINDOWS\tmpdelis.bat
2007-11-13 18:12 26 –a—— C:\WINDOWS\winstart.bat
2007-11-13 18:11 299,008 –a—— C:\WINDOWS\uninst.exe
2007-11-12 19:32 d——– C:\Documents and Settings\Tim\WINDOWS
2007-11-12 18:27 216,977 –a—— C:\CRACK MA.DAT
2007-11-12 18:06 d——– C:\Games
2007-11-12 00:19 d——– C:\WINDOWS\CinemaTycoonCC
2007-11-12 00:11 d——– C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL
2007-11-11 22:40 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-11-11 19:09 d——– C:\EbayTycoon
2007-11-11 18:04 d——– C:\Program Files\Need2Find
2007-11-11 17:45 10 –a—— C:\WINDOWS\smdat32m.sys
2007-11-11 17:45 0 –a—— C:\WINDOWS\smdat32a.sys
2007-11-11 17:43 d——– C:\Program Files\Kazaa
2007-11-11 17:28 d——– C:\Program Files\BearShare Applications
2007-11-10 20:14 d——– C:\Program Files\PokerStars
2007-11-10 14:42 d——– C:\Program Files\Disney
2007-11-10 07:15 d——– C:\Program Files\MySpace
2007-11-10 07:15 d——– C:\Documents and Settings\Tim\Application Data\MySpace
2007-11-09 21:37 d——– C:\Program Files\Wizards of the Coast
2007-11-09 17:18 d——– C:\Program Files\Conquer 2.0
2007-11-09 00:47 d——– C:\Program Files\BitComet
2007-11-09 00:47 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-23 19:05 9,808 —-a-w C:\b.exe
2007-11-23 19:04 36,864 —-a-w C:\svchost.exe
2007-11-23 19:04 111,754 —-a-w C:\a.exe
2007-11-23 16:24 ——— d—–w C:\Documents and Settings\Tim\Application Data\LimeWire
2007-11-23 01:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-22 19:02 ——— d—–w C:\Program Files\Iomega
2007-11-22 17:34 12,800 –s-a-w C:\WINDOWS\system32\rldyt.dll
2007-11-20 23:32 ——— d—–w C:\Program Files\LimeWire
2007-11-20 20:32 ——— d—–w C:\Documents and Settings\Tim\Application Data\Lenovo
2007-11-20 18:49 ——— d—–w C:\Program Files\WordPerfect Office 12
2007-11-20 18:40 ——— d—–w C:\Program Files\Lenovo
2007-11-20 18:40 ——— d—–w C:\Program Files\Common Files\Lenovo
2007-11-20 18:38 23,552 —-a-w C:\WINDOWS\system32\drivers\psasrv.exe
2007-11-20 18:38 17,536 —-a-w C:\WINDOWS\system32\drivers\psadd.sys
2007-11-20 07:39 37,376 —-a-w C:\WINDOWS\system32\tuvsrsr.dll
2007-11-18 22:47 ——— d—–w C:\Program Files\Google
2007-11-18 20:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 05:00 5,427 —-a-w C:\WINDOWS\system32\EGATHDRV.SYS
2007-11-16 17:28 79,875 —-a-w C:\WINDOWS\system32\adssite-remove.exe
2007-11-16 03:17 147,456 —-a-w C:\WINDOWS\system32\vbzip10.dll
2007-11-16 03:14 36,352 —-a-w C:\WINDOWS\system32\tuvwuus.dll
2007-11-13 04:02 6,216 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-12 00:08 796,672 —-a-w C:\WINDOWS\GPInstall.exe
2007-11-11 22:45 1,761 —-a-w C:\WINDOWS\Fonts\acrsecB.fon
2007-10-31 18:03 245,408 —-a-w C:\WINDOWS\system32\unicows.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\Tim\Application Data\Apple Computer
2007-10-07 02:36 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-07 02:36 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-07 02:36 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-07 02:36 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 02:36 ——— d—–w C:\Program Files\Symantec
2007-09-06 11:09 801,144 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 11:00 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-01-10 17:15 839,696 —-a-w C:\WINDOWS\Fonts\Crack.exe
2007-01-10 17:15 839,695 –sh–w C:\WINDOWS\Fonts\svchost.exe
2007-01-10 17:15 839,695 –sh–w C:\WINDOWS\Fonts\svchost.exe
2005-07-29 21:24 472 –sha-r C:\WINDOWS\VGlt\p35Q.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23B760D6-C98B-450B-9B32-26C7775CDF83}]
2007-11-23 11:18 14336 –a—— C:\Program Files\Video Add-on\isfmdl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}]
C:\Program Files\RXToolBar\sfcont.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB71E94E-3DC4-41eb-BBD5-31E82C9FD1D4}]
2007-11-20 06:52 74752 –a—— C:\WINDOWS\system32\gzmrotate.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
2007-11-15 22:14 36352 –a—— C:\WINDOWS\system32\tuvwuus.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2A69F099-CB84-4AA5-96EC-FC657B88B384}"= C:\Program Files\Starware381\bin\Starware381.dll [ ]
"{EFAF6EA3-615D-4F83-8748-2F7A576FCEA6}"= C:\Program Files\Video Add-on\ictmdl.dll [2007-11-22 12:33 78336]

[HKEY_CLASSES_ROOT\clsid\{2a69f099-cb84-4aa5-96ec-fc657b88b384}]

[HKEY_CLASSES_ROOT\clsid\{efaf6ea3-615d-4f83-8748-2f7a576fcea6}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EFAF6EA3-615D-4F83-8748-2F7A576FCEA6}"= C:\Program Files\Video Add-on\ictmdl.dll [2007-11-22 12:33 78336]

[HKEY_CLASSES_ROOT\clsid\{efaf6ea3-615d-4f83-8748-2f7a576fcea6}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 00:51]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe" [2006-05-07 20:34]
"TPWAUDAP"="C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-04-19 17:29]
"PMHandler"="C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe" [2006-08-22 02:54]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 C:\WINDOWS\SkyTel.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 04:45]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 02:40 C:\WINDOWS\AGRSMMSG.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-25 08:19]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 23:17]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 23:13]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 23:17]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-05 14:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-14 21:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 09:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 13:44]
"LPManager"="C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe" [2006-07-03 11:11]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-11-22 06:36]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 19:24]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 18:07]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 21:13]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-01-10 21:01]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 16:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-27 19:03]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [2007-01-10 12:15]
"hid_start"="C:\WINDOWS\System32\Rundll32.exe" [2004-08-04 07:00]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-02 03:29:26]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 17:23:00]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2003-04-06 00:37:38]
Photags AutoDetect.lnk - C:\Program Files\PhoTags Express\Photags AutoDetect.exe [2007-07-04 17:51:24]

[hklm\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{b0883848-1466-4470-a418-3fe7d36694b9}"= C:\WINDOWS\system32\rldyt.dll [2007-11-22 12:34 12800]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"= C:\WINDOWS\system32\tuvwuus.dll [2007-11-15 22:14 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2006-01-11 01:05 13824 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvwuus]
tuvwuus.dll 2007-11-15 22:14 36352 C:\WINDOWS\system32\tuvwuus.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqr.dll
"Notification Packages"= scecli ACGina

R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS
R1 IBMTPCHK;IBMTPCHK;\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys
R2 smi2;smi2;\??\C:\Program Files\SMI2\smi2.sys
S3 TPPWRIF;TPPWRIF;\??\C:\WINDOWS\_tpb0000.tmp\TPPWRIF.sys

*Newly Created Service* - CORE
.
Contents of the 'Scheduled Tasks' folder
"2007-11-11 14:40:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1173451077.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe:-I
"2007-11-21 08:30:00 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 14:03:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\pac.txt 279600 bytes
C:\WINDOWS\system32\rMa18yy

scan completed successfully
hidden files: 2

**************************************************************************
.
Completion time: 2007-11-23 14:08:40 - machine was rebooted
.
— E O F —
thank you for the help, here is the text log from the HJT. again, thank you and i am looking forward to freeing my computer of this coruption.
apaulferguson


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:22:16 PM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Web Buying\v1.8.6\webbuying.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.worldusa.com
O3 - Toolbar: Starware Music - {2a69f099-cb84-4aa5-96ec-fc657b88b384} - C:\Program Files\Starware381\bin\Starware381.dll (file missing)
O3 - Toolbar: IE Custom Tools - {EFAF6EA3-615D-4F83-8748-2F7A576FCEA6} - C:\Program Files\Video Add-on\ictmdl.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [hid_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrotate.dll" DllVerify
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: bemocked - {b0883848-1466-4470-a418-3fe7d36694b9} - C:\WINDOWS\system32\rldyt.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 11782 bytes
Hi :)

You have a password stealing trojan on your machine - you are advised to change all your passwords from a non-infected computer: for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.

You can see which passwords the trojan has gathered;

First, be sure that you are set to see hidden files and folders:

  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labelled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labelled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labelled Hide protected operating system files. Answer Yes to the prompt.
  • Press the Apply button and then the OK button and shutdown My Computer.

Then, using Windows Explorer, navigate to this file:

C:\Documents and Settings\Tim\z.dat - Rename z.dat to z.txt (to do this, right-click on the file and choose Rename)

Do the same for C:\Documents and Settings\Tim\x.dat.

Double-click the files to open them; they should contain all the passwords stolen by the trojan. If you have questions about the above, please ask them. If not, change your passwords from a clean computer, and do the following:

Please download SDFix and save it to your desktop.

Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows directory, typically C:\SDFix)

  • Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
  • Please reboot into Safe Mode. To do this, go to Start>Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)

Once in Safe Mode, do the following:

  • Open the extracted SDFix folder and double-click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any trojan services and registry entries that it finds, then prompt you to press any key to reboot; press any key and it will restart the PC.
  • When the PC restarts SDFix will run again and complete the removal process then display Finished. Press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to clipboard ready for posting back on the forum).

Post back to me with the report of SDFix (C:\SDFix\Report.txt) and a new HijackThis log.
hi ,
thanks for the help, this is the quickest, and most detailed responce i have ever got with a comoputer problome. you guys are great. here is the HJT and sdfix you ask for. thanx again!!!!!!!!!!

YOU GUYS RULE !!!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:25:59 PM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\Rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.worldusa.com
O3 - Toolbar: Starware Music - {2a69f099-cb84-4aa5-96ec-fc657b88b384} - C:\Program Files\Starware381\bin\Starware381.dll (file missing)
O3 - Toolbar: IE Custom Tools - {EFAF6EA3-615D-4F83-8748-2F7A576FCEA6} - C:\Program Files\Video Add-on\ictmdl.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [hid_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrotate.dll" DllVerify
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: bemocked - {b0883848-1466-4470-a418-3fe7d36694b9} - C:\WINDOWS\system32\rldyt.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


================================================================================
===============

SDFix: Version 1.115

Run by [removed] on Fri 11/23/2007 at 07:53 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Tim\Desktop\SDFix

Safe Mode:
Checking Services:

Name:
core

Path:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\X.DAT - Deleted
C:\Z.DAT - Deleted



Folder C:\Temp\abW9 - Removed
Folder C:\Temp\1cb - Removed
Folder C:\WINDOWS\Fonts\' - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 20:11:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000097
"TracesSuccessful"=dword:00000002

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————

File Backups: - C:\DOCUME~1\Tim\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:

Mon 22 Jan 2007 146,432 ..SHR — "C:\Program Files\PhoTags Express\Setup.exe"
Wed 9 Mar 2005 39,936 ..SHR — "C:\Program Files\PhoTags Express\_Setupx.dll"
Tue 15 Aug 2006 4,900,600 …H. — "C:\Program Files\Picasa2\setup.exe"
Wed 10 Jan 2007 839,695 ..SH. — "C:\WINDOWS\Fonts\svchost.exe"
Mon 12 Nov 2007 168 ..SHR — "C:\WINDOWS\system32\9E8A77C5F4.sys"
Mon 12 Nov 2007 6,216 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Sat 17 Nov 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 23 Nov 2007 1,061 A..H. — "C:\Program Files\InterActual\InterActual Player\iti4E.tmp"
Wed 29 Mar 2006 12,424,594 …H. — "C:\SWTOOLS\APPS\AOL\CA\MSIE62K.EXE"
Wed 29 Mar 2006 23,250,289 …H. — "C:\SWTOOLS\APPS\AOL\CA\MSIE698.EXE"
Wed 29 Mar 2006 200,704 …H. — "C:\SWTOOLS\APPS\AOL\US\ACST4.DLL"
Wed 29 Mar 2006 81,920 …H. — "C:\SWTOOLS\APPS\AOL\US\AOLFIREWALLMGR.DLL"
Wed 29 Mar 2006 73,728 …H. — "C:\SWTOOLS\APPS\AOL\US\AOLINSTALLERFW.DLL"
Wed 29 Mar 2006 88,064 …H. — "C:\SWTOOLS\APPS\AOL\US\INSTPH.DLL"
Wed 29 Mar 2006 2,565,456 …H. — "C:\SWTOOLS\APPS\AOL\CA\ADDONS\AIM.EXE"
Wed 29 Mar 2006 24,576 …H. — "C:\SWTOOLS\APPS\AOL\CA\ADDONS\READER.DLL"
Wed 29 Mar 2006 14,115,528 …H. — "C:\SWTOOLS\APPS\AOL\CA\ADDONS\READER.EXE"
Wed 29 Mar 2006 4,406,768 …H. — "C:\SWTOOLS\APPS\AOL\CA\ADDONS\WINAMP.EXE"
Wed 29 Mar 2006 77,824 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\acs\AcsInstN.dll"
Wed 29 Mar 2006 6,961,146 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\acs\acsnet.zip"
Wed 29 Mar 2006 3,025,040 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\acs\acssetup.exe"
Wed 29 Mar 2006 307,289 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\asp\aspcheck.dll"
Wed 29 Mar 2006 7,083,361 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\asp\aspsetup.exe"
Wed 29 Mar 2006 550,488 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\deskbar\deskbr.exe"
Wed 29 Mar 2006 553,984 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\flash\FlashAX.exe"
Wed 29 Mar 2006 2,242,759 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\fw\nisale.exe"
Wed 29 Mar 2006 24,064 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\fw\NISChk.dll"
Wed 29 Mar 2006 57,344 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\ocp\ocpchk.dll"
Wed 29 Mar 2006 748,728 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\ocp\ocpinst.exe"
Wed 29 Mar 2006 7,515,304 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\qt\qt.exe"
Wed 29 Mar 2006 86,016 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\qt\QTInsInf.dll"
Wed 29 Mar 2006 45,056 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\rp\RealChk.dll"
Wed 29 Mar 2006 5,111,296 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\rp\RealPl8.EXE"
Wed 29 Mar 2006 4,378,673 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\rp\real_upd.exe"
Wed 29 Mar 2006 360,448 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\rp\rp9codec.exe"
Wed 29 Mar 2006 40,960 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\sysinfo\SiNdInst.dll"
Wed 29 Mar 2006 473,736 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\sysinfo\SinfInst.exe"
Wed 29 Mar 2006 12,288 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\tb\tbinst.dll"
Wed 29 Mar 2006 516,032 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\tb\tbsetup.exe"
Wed 29 Mar 2006 597,080 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\toolbar\toolbr.exe"
Wed 29 Mar 2006 525,976 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\tpspd\TSsetup.exe"
Wed 29 Mar 2006 57,344 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\tpspd\tsverchk.dll"
Wed 29 Mar 2006 49,152 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\vwpt\AOLVPChk.dll"
Wed 29 Mar 2006 61,440 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\vwpt\VPPrePop.exe"
Wed 29 Mar 2006 3,858,056 …H. — "C:\SWTOOLS\APPS\AOL\CA\comps\vwpt\Vwpt.exe"

Finished!
Hi :)

I understand that downloading music and other files may be important to you; however, the Peer-to-Peer programs that you are using to do that, even if they are not infected with malware, will bring malware into your system. Therefore, the chances of you becoming infected again are very high. This obviously can result in disabling your computer and could even lead to someone stealing sensitive personal data from your computer. Beyond the inconvenience this causes you, these programs also tend to use your computer as a server to spread more infection all over the internet, so your computer becomes a part of the malware problem.

Remember that no matter how clean the program you're using for Peer-to-Peer filesharing may be, it offers no guarantees regarding the cleanliness of files you may choose to download. All files available via Peer-to-Peer filesharing carry a high risk, particularly those that offer you illegitimate methods of using legitimate software programs without paying for them. Any program or file that offers you the ability to access non-freeware programs at no cost, e.g., pirated software and/or cracks/key generators for gaining access to legitimate software, is 100% guaranteed to contain malware.

Here is some information that looks at the rates of infection:

http://www.benedelman.org/spyware/p2p/

With that being said, I recommend that you remove the following Peer-to-Peer program(s):

Kazaa
BearShare
BitComet
LimeWire


Step 1

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s) (when found):

  • Adssite Advanced Toolbar
  • Need2Find
  • RXToolBar
  • Starware

Step 2

Please go to VirusTotal or Jotti and upload C:\CRACK MA.DAT for scanning.

For VirusTotal:

  • Please copy and paste C:\CRACK MA.DAT in the text box next to the Browse… button.
  • Click on Send File.

For Jotti:

  • Please copy and paste C:\CRACK MA.DAT in the text box next to the Browse… button.
  • Click on Submit.

Copy/paste the results in Notepad and save them to your desktop.

Step 3

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\gzmrotate.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nnnlljh.dll
C:\WINDOWS\system32\hggedcc.dll
C:\WINDOWS\system32\ljjgdaa.dll
C:\WINDOWS\system32\rightonadz-uninst.exe
C:\WINDOWS\system32\khfgfca.dll
C:\Documents and Settings\Tim\z.dat
C:\Documents and Settings\Tim\x.dat
C:\n.bat
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\smdat32a.sys
C:\b.exe
C:\svchost.exe
C:\a.exe
C:\WINDOWS\system32\rldyt.dll
C:\WINDOWS\system32\tuvsrsr.dll
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\tuvwuus.dll
C:\WINDOWS\GPInstall.exe
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\Crack.exe
C:\WINDOWS\Fonts\svchost.exe

Folder::

C:\Program Files\Video Add-on
C:\Documents and Settings\Tim\Application Data\Adssite Advanced Toolbar
C:\Program Files\RXToolBar
C:\Program Files\Starware381
C:\WINDOWS\system32\rMa18yy

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23B760D6-C98B-450B-9B32-26C7775CDF83}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB71E94E-3DC4-41eb-BBD5-31E82C9FD1D4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2A69F099-CB84-4AA5-96EC-FC657B88B384}"=-
"{EFAF6EA3-615D-4F83-8748-2F7A576FCEA6}"=-
[-HKEY_CLASSES_ROOT\clsid\{2a69f099-cb84-4aa5-96ec-fc657b88b384}]
[-HKEY_CLASSES_ROOT\clsid\{efaf6ea3-615d-4f83-8748-2f7a576fcea6}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EFAF6EA3-615D-4F83-8748-2F7A576FCEA6}"=-
[-HKEY_CLASSES_ROOT\clsid\{efaf6ea3-615d-4f83-8748-2f7a576fcea6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Host Process"=-
"hid_start"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{b0883848-1466-4470-a418-3fe7d36694b9}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvwuus]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 4

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 5

In your next reply, please post:

  • the Virustotal/Jotti results
  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
hey guy, i am about halfway removing the programs and files, and i now have 2 security toolbars on my browser. what do i do? is this supposed to happen?
hello again. ok another proble. The VirusTotal site tells me that i have alrady analyzed the files but it will not give teopon tio see the results or reanalyze. The Jotti site itelling methat i have Javascript disabled, and i cannot figure out for the life of me how to enable the javascript. Thanks again for your time.
ok i am still working on this, but it is taking longer because it seems that i cannot get y pages to open. at first i thought that it was a problem with the mouse on my laptop, but i plugged in my wireless mouse and still the same problem. is this a problem with the computer itself or is it also a part of the virus. I apologize for the delay.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI