beatmobb
Topic Starter
I have 4 different spyware/malware programs on my computer just trying to remove this pest. I've gotten as far as clicking directly on the file to delete, but it won't happen. WTF!!! Please help!I've used these:AVGAdAwareHiJackThisComboFix (This one stuck at 'deleting files/folders. I got scared and stopped it)
This What Ad-Aware found:Ad-Aware SE Build 1.06r1Logfile Created on:Thursday, December 13, 2007 10:12:15 AMCreated with Ad-Aware SE Personal, free for private use.Using definitions file:SE1R208 10.12.2007»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»References detected during the scan:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Win32.TrojanDownloader.Small(TAC index:7):10 total references»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Ad-Aware SE Settings===========================Set : Search for negligible risk entriesSet : Safe mode (always request confirmation)Set : Scan active processesSet : Scan registrySet : Deep-scan registryExtended Ad-Aware SE Settings===========================Set : Unload recognized processes & modules during scanSet : Scan registry for all users instead of current user onlySet : Always try to unload modules before deletionSet : During removal, unload Explorer and IE if necessarySet : Let Windows remove files in use at next rebootSet : Delete quarantined objects after restoringSet : Include basic Ad-Aware settings in log fileSet : Include additional Ad-Aware settings in log fileSet : Include reference summary in log fileSet : Include alternate data stream details in log fileSet : Play sound at scan completion if scan locates critical objects12-13-2007 10:12:15 AM - Scan started. (Custom mode)Listing running processes»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»#:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 684 ThreadCreationTime : 12-13-2007 5:59:30 PM BasePriority : Normal#:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 744 ThreadCreationTime : 12-13-2007 5:59:36 PM BasePriority : Normal#:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\SYSTEM32\ ProcessID : 768 ThreadCreationTime : 12-13-2007 5:59:38 PM BasePriority : High Win32.TrojanDownloader.Small Object Recognized! Type : Process Data : ddccyxy.dll TAC Rating : 7 Category : Malware Comment : mljjjhf.dll.dmp Object : C:\WINDOWS\SYSTEM32\Warning! Win32.TrojanDownloader.Small Object found in memory(C:\WINDOWS\SYSTEM32\ddccyxy.dll)#:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 812 ThreadCreationTime : 12-13-2007 5:59:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe#:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 824 ThreadCreationTime : 12-13-2007 5:59:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe#:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1016 ThreadCreationTime : 12-13-2007 5:59:50 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe#:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1120 ThreadCreationTime : 12-13-2007 5:59:55 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe#:8 [msmpeng.exe] FilePath : C:\Program Files\Windows Defender\ ProcessID : 1264 ThreadCreationTime : 12-13-2007 5:59:57 PM BasePriority : Normal FileVersion : 1.1.1593.0 ProductVersion : 1.1.1593.0 ProductName : Windows Defender CompanyName : Microsoft Corporation FileDescription : Service Executable InternalName : MsMpEng.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : MsMpEng.exe#:9 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1320 ThreadCreationTime : 12-13-2007 5:59:58 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe#:10 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1404 ThreadCreationTime : 12-13-2007 5:59:58 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe#:11 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1588 ThreadCreationTime : 12-13-2007 6:00:02 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe#:12 [wisptis.exe] FilePath : C:\WINDOWS\SYSTEM32\ ProcessID : 416 ThreadCreationTime : 12-13-2007 6:00:21 PM BasePriority : High FileVersion : 1.7.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 1.7.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Microsoft Tablet PC Component InternalName : WISPTIS.EXE LegalCopyright : Copyright © 1998-2003 Microsoft Corp. OriginalFilename : WISPTIS.EXE#:13 [tabbtnu.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 544 ThreadCreationTime : 12-13-2007 6:00:22 PM BasePriority : Above Normal FileVersion : 1.0.2201.0 ProductVersion : 1.0.2201.0 ProductName : Tablet PC CompanyName : Microsoft Corporation FileDescription : Tablet PC Buttons Service InternalName : tabbtnu.exe LegalCopyright : Copyright © 1998-2002 Microsoft Corp. OriginalFilename : tabbtnu.exe#:14 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 672 ThreadCreationTime : 12-13-2007 6:00:25 PM BasePriority : Normal FileVersion : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) ProductVersion : 6.00.2900.3156 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE Win32.TrojanDownloader.Small Object Recognized! Type : Process Data : ddccyxy.dll TAC Rating : 7 Category : Malware Comment : mljjjhf.dll.dmp Object : C:\WINDOWS\system32\Warning! Win32.TrojanDownloader.Small Object found in memory(C:\WINDOWS\system32\ddccyxy.dll)#:15 [ctfmon.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1172 ThreadCreationTime : 12-13-2007 6:00:31 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE#:16 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 1808 ThreadCreationTime : 12-13-2007 6:01:14 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Win32.TrojanDownloader.Small Object Recognized! Type : Process Data : ddccyxy.dll TAC Rating : 7 Category : Malware Comment : mljjjhf.dll.dmp Object : C:\WINDOWS\SYSTEM32\Warning! Win32.TrojanDownloader.Small Object found in memory(C:\WINDOWS\SYSTEM32\ddccyxy.dll)Memory scan result:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 0Objects found so far: 3Started registry scan»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Registry Scan result:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 0Objects found so far: 3Started deep registry scan»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Deep registry scan result:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 0Objects found so far: 3Started Tracking Cookie scan»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Tracking cookie scan result:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 0Objects found so far: 3Deep scanning and examining files (C:)»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Disk Scan Result for C:\WINDOWS\system32\»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 0Objects found so far: 3Performing conditional scans…»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.TrojanDownloader.Small Object Recognized! Type : Regkey Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Value : EnableConsoleTracing Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Value : FileTracingMask Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Value : ConsoleTracingMask Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Value : MaxFileSize Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\tracing\fwcfg Value : FileDirectory Win32.TrojanDownloader.Small Object Recognized! Type : RegValue Data : TAC Rating : 7 Category : Malware Comment : Rootkey : HKEY_USERS Object : .default\software\microsoft\windows\shellnoroam\muicache Value : @shell32.dll,-12693Conditional scan result:»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»New critical objects: 7Objects found so far: 1010:14:35 AM Scan CompleteSummary Of This Scan»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»Total scanning time:00:02:19.661Objects scanned:129928Objects identified:7Objects ignored:0New critical objects:7