This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJ Log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:45:51 AM, on 12/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\ULI5289\ALi5289.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Spybot - Search & Destroy\SpybotSD.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\WINDOWS\system32\nqcqwmga.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\wuauclt.exeC:\Documents and Settings\Gili\Desktop\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankO4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autocloseO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: DomainService - - C:\WINDOWS\system32\nqcqwmga.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe–End of file - 3340 bytesPop-Ups, that is. This is the situation at the moment. Help? Thanks.
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
    [*]I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.

    [*]The fixes are specific to your problem and should only be used for the issues on this machine.

    [*]Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.

    [*]It's often worth reading through these instructions and printing them for ease of reference.

    [*]If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.

    [*]Please reply to this thread. Do not start a new topic.

    As I am still training here, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.


    Show all hidden files:
      [*]Click Start.

      [*]Open My Computer.

      [*]Select the Tools menu and click Folder Options.

      [*]Select the View Tab.

      [*]Under the Hidden files and folders heading select Show hidden files and folders.

      [*]Uncheck the Hide protected operating system files (recommended) option.

      [*]Click Yes to confirm.

      [*]Click OK.

      Please do not delete anything unless instructed to.


      Next, rename HijackThis.exe to scanner.exe.
      Scan again with HijackThis, and "copy/paste" a new log file into this thread.


      I need to see another log from HijackThis.
        [*]Run Hijackthis.

        [*]Click on Open the Misc Tools section.

        [*]Next click on Open uninstall manager.

        [*]Press the Save list button.

        [*]Save the file to your desktop, with the default name of uninstall_list

        [*]Copy & Paste the entire contents of that file in your in your next post.

        Thanks,

        jpshortstuff
Thanks!So…I hope I got this right. I renamed HiJackThis and ran it again. This is the log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:22:18 PM, on 12/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\ULI5289\ALi5289.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Gili\Desktop\scanner.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {20907D5B-6893-4A22-BDD7-83B54A802D04} - C:\WINDOWS\system32\jkklm.dllO2 - BHO: {58116da7-724a-b039-f4e4-302a38393713} - {31739383-a203-4e4f-930b-a4277ad61185} - C:\WINDOWS\system32\qqeeljce.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)O2 - BHO: (no name) - {A70E9493-2ACF-4AAD-B243-4B217C8648DC} - (no file)O2 - BHO: (no name) - {B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1} - C:\WINDOWS\system32\tygn.dll (file missing)O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\yayyaxu.dll (file missing)O2 - BHO: (no name) - {C27F3316-913F-429C-B563-BE9AEF2C1371} - (no file)O2 - BHO: (no name) - {E1AA8E3A-63FA-365D-D829-3BE6778F03B7} - C:\WINDOWS\system32\ybeupl.dll (file missing)O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autocloseO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO20 - Winlogon Notify: hsijxizk - hsijxizk.dll (file missing)O20 - Winlogon Notify: yayyaxu - yayyaxu.dll (file missing)O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe–End of file - 4425 bytesAnd…this is the unistall_list log:7-Zip 4.57AC3Filter (remove only)Ad-Aware SE PersonalAdobe Bridge 1.0Adobe Common File InstallerAdobe Flash Player PluginAdobe Help Center 1.0Adobe Illustrator CS2Adobe InDesign CS2Adobe Photoshop CS2Adobe Reader 7.0.9Adobe Stock Photos 1.0Adobe SVG Viewer 3.0Ahead Nero Burning ROMAhead NeroVision ExpressAIM 6AOL Instant MessengerApple Software UpdateAthlon 64 Processor DriverAvanquest updateCanon EOS 5D WIA DriverCanon EOS Kiss_N REBEL_XT 350D WIA DriverCanon EOS-1Ds Mark II WIA DriverCanon Utilities Digital Photo Professional 3.2Canon Utilities EOS UtilityCanon Utilities Original Data Security ToolsCanon Utilities PhotoStitchCanon Utilities WFT-E1/E2 UtilityDeluxeFTP 6.0.1DivX CodecDivX Content UploaderDivX ConverterDivX PlayerDivX Web PlayereMuleEV Nova (remove only)Final Fantasy VIIFlickr Uploadr 2.3Google Gmail NotifierHijackThis 2.0.2HP Photo & Imaging 3.1HP PSC & OfficeJet 3.0HP Software UpdateIndigo Prophecy DemoIntel A/V Codecs V2.0J2SE Runtime Environment 5.0 Update 10J2SE Runtime Environment 5.0 Update 11J2SE Runtime Environment 5.0 Update 6J2SE Runtime Environment 5.0 Update 9Jade EmpireJava™ 6 Update 2Java™ 6 Update 3Java™ SE Runtime Environment 6 Update 1Macromedia Extension ManagerMacromedia Flash 8Macromedia Flash 8 Video EncoderMacromedia Flash Player 8Macromedia Flash Player 8MediaMonkey 2.5Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1 Hotfix (KB928366)Microsoft .NET Framework 2.0Microsoft Kernel-Mode Driver Framework Feature Pack 1.5Microsoft Office XP Professional with FrontPageMicrosoft Visual C++ 2005 RedistributableMotorola Driver InstallationMotorola Phone ToolsMozilla Firefox (2.0.0.11)MSXML 4.0 SP2 (KB927978)MSXML 4.0 SP2 (KB936181)NVIDIA DriversPhotomatix Pro version 2.4Power MP3 WMA Converter 2006, (ver 3.42)QuickTimeRealPlayerRosetta Stone Ltd ServicesSecurity Update for Microsoft .NET Framework 2.0 (KB928365)Security Update for Windows Media Player 10 (KB936782)Security Update for Windows XP (KB890046)Security Update for Windows XP (KB893756)Security Update for Windows XP (KB896358)Security Update for Windows XP (KB896423)Security Update for Windows XP (KB896428)Security Update for Windows XP (KB899587)Security Update for Windows XP (KB899591)Security Update for Windows XP (KB900725)Security Update for Windows XP (KB901017)Security Update for Windows XP (KB901214)Security Update for Windows XP (KB902400)Security Update for Windows XP (KB904706)Security Update for Windows XP (KB905414)Security Update for Windows XP (KB905749)Security Update for Windows XP (KB908519)Security Update for Windows XP (KB911562)Security Update for Windows XP (KB911927)Security Update for Windows XP (KB913433)Security Update for Windows XP (KB913580)Security Update for Windows XP (KB914388)Security Update for Windows XP (KB914389)Security Update for Windows XP (KB917344)Security Update for Windows XP (KB917953)Security Update for Windows XP (KB918118)Security Update for Windows XP (KB918439)Security Update for Windows XP (KB919007)Security Update for Windows XP (KB920213)Security Update for Windows XP (KB920670)Security Update for Windows XP (KB920683)Security Update for Windows XP (KB920685)Security Update for Windows XP (KB921503)Security Update for Windows XP (KB922819)Security Update for Windows XP (KB923191)Security Update for Windows XP (KB923414)Security Update for Windows XP (KB923689)Security Update for Windows XP (KB923980)Security Update for Windows XP (KB924191)Security Update for Windows XP (KB924270)Security Update for Windows XP (KB924496)Security Update for Windows XP (KB924667)Security Update for Windows XP (KB925902)Security Update for Windows XP (KB926255)Security Update for Windows XP (KB926436)Security Update for Windows XP (KB927779)Security Update for Windows XP (KB927802)Security Update for Windows XP (KB928255)Security Update for Windows XP (KB928843)Security Update for Windows XP (KB929123)Security Update for Windows XP (KB929969)Security Update for Windows XP (KB930178)Security Update for Windows XP (KB931261)Security Update for Windows XP (KB931784)Security Update for Windows XP (KB932168)Security Update for Windows XP (KB933566)Security Update for Windows XP (KB933729)Security Update for Windows XP (KB935839)Security Update for Windows XP (KB935840)Security Update for Windows XP (KB936021)Security Update for Windows XP (KB937143)Security Update for Windows XP (KB937894)Security Update for Windows XP (KB938127)Security Update for Windows XP (KB938829)Security Update for Windows XP (KB939653)Security Update for Windows XP (KB941202)Security Update for Windows XP (KB941568)Security Update for Windows XP (KB941569)Security Update for Windows XP (KB942615)Security Update for Windows XP (KB943460)Security Update for Windows XP (KB944653)SimCity 4 DeluxeSoundMAXSpybot - Search & DestroyThe Rosetta StoneULi M5289 SATA Controller DriverULi PCI 10-100 Fast Ethernet Controller DriverULi PCI to AGP Controller DriverUpdate for Windows XP (KB894391)Update for Windows XP (KB900485)Update for Windows XP (KB908531)Update for Windows XP (KB910437)Update for Windows XP (KB911280)Update for Windows XP (KB916595)Update for Windows XP (KB920872)Update for Windows XP (KB922582)Update for Windows XP (KB927891)Update for Windows XP (KB930916)Update for Windows XP (KB931836)Update for Windows XP (KB933360)Update for Windows XP (KB938828)Update for Windows XP (KB942763)Update for Windows XP (KB942840)Winamp (remove only)Windows Installer 3.1 (KB893803)Windows Media Format RuntimeWindows Media Player 10Windows XP Hotfix - KB873339Windows XP Hotfix - KB885835Windows XP Hotfix - KB885836Windows XP Hotfix - KB885884Windows XP Hotfix - KB886185Windows XP Hotfix - KB888302Windows XP Hotfix - KB890859Windows XP Hotfix - KB891781WinRAR archiverWinZipYAMAHA SoftSynthesizer S-YXG70YOU DON'T KNOW JACK Volume 3
Hi Gilco



You don't appear to be running any Anti-Virus software.

Install Anti-Virus software! Without any anti-virus software, your computer is wide open to infection. If you don't have any Anti-Virus software I strongly recommend you download Avast! or AVG Free



You need to disable TeaTimer, so that it doesn't interfere with our fix.

This is a two step process.
First step:
    [*]Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)

    [*]If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.

    [*]If you have Version 1.4, Click on Exit Spybot S&D Resident

    Second step, For both versions :
      [*]Open Spybot S&D

      [*]Click Mode, choose Advanced Mode

      [*]Go to the bottom of the vertical panel on the left, click Tools

      [*]Then, also in left panel, click Resident shows a red/white shield.

      [*]If your firewall raises a question, say OK

      [*]In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active

      [*]OK any prompts.

      [*]Use File, Exit to terminate Spybot

      [*]Reboot your machine for the changes to take effect.


      Please download ATF Cleaner by Atribune.
      Download - ATF Cleaner»
      Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

      (If you use FireFox or the Opera browser
      To keep saved passwords, click No at the prompt.)

      It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



      Download ComboFix by sUBs from here or here

      **Save it to your desktop**

      Double click on ComboFix.exe & follow the prompts.
      When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

      Note:
      Do not mouseclick combofix's window whilst it's running. That may cause it to stall



      Thanks,

      jpshortstuff
Here's the ComboFix log: ComboFix 07-12-15.5 - Gili 2007-12-15 18:08:22.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1650 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Gili\Favorites\Online Security Guide.lnk C:\WINDOWS\pppatc~1 C:\WINDOWS\system32\fskrrbal.dll C:\WINDOWS\system32\gmsywodu.dll C:\WINDOWS\system32\install.exe C:\WINDOWS\system32\jkklm.dll C:\WINDOWS\system32\labrrksf.ini C:\WINDOWS\system32\lmuongcs.ini C:\WINDOWS\system32\mlkkj.ini C:\WINDOWS\system32\mlkkj.ini2 C:\WINDOWS\system32\qqeeljce.dll C:\WINDOWS\system32\scgnouml.dll C:\WINDOWS\system32\sks~1 C:\WINDOWS\system32\uegmhmcp.dll C:\WINDOWS\system32\xgtiiftx.ini C:\WINDOWS\system32\xtfiitgx.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\LEGACY_DOMAINSERVICE ((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 ))))))))))))))))))))))))))))))) . 2007-12-15 18:12 . 2007-12-15 18:12 0 –a—— C:\WINDOWS\system32\mcrh.tmp 2007-12-15 00:36 . 2007-12-15 00:36 d–h—– C:\WINDOWS\PIF 2007-12-14 18:06 . 2007-12-14 18:06 54,156 –ah—– C:\WINDOWS\QTFont.qfn 2007-12-14 18:06 . 2007-12-14 18:06 1,409 –a—— C:\WINDOWS\QTFont.for 2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Program Files\Apple Software Update 2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Documents and Settings\All Users\Application Data\Apple 2007-12-14 18:03 . 2007-12-14 18:03 d——– C:\Program Files\7-Zip 2007-12-12 01:31 . 2007-12-12 01:31 d——– C:\Documents and Settings\Gili\Application Data\Talkback 2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx 2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts 2007-12-10 03:32 . 2007-12-10 12:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-12-10 03:26 . 2007-12-10 03:26 d——– C:\Program Files\Enigma Software Group 2007-12-10 01:57 . 2007-12-10 01:57 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft 2007-12-03 22:59 . 2007-12-03 23:14 d——– C:\Program Files\Photomatix 2007-12-03 22:38 . 2007-12-03 22:55 d——– C:\Program Files\eMule 2007-12-03 17:23 . 2007-12-03 17:24 d——– C:\Program Files\MioNetApplet 2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Program Files\Avanquest update 2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Documents and Settings\Gili\Application Data\InstallShield 2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Gili\Application Data\Canon 2007-11-27 17:39 . 2007-12-06 17:51 d——– C:\Program Files\Canon 2007-11-27 17:37 . 2007-12-06 17:50 d——– C:\Program Files\Common Files\Canon . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-14 23:07 ——— d—–w C:\Program Files\QuickTime 2007-12-14 23:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-12-10 06:23 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent DNA 2007-12-01 22:09 ——— d—–w C:\Program Files\Java 2007-11-30 21:48 ——— d—–w C:\Documents and Settings\Gili\Application Data\Viewpoint 2007-11-30 21:46 ——— d—–w C:\Program Files\Kodak 2007-11-30 21:44 ——— d—–w C:\Program Files\LightSurf 2007-11-29 22:32 ——— d—–w C:\Program Files\Motorola Phone Tools 2007-11-29 22:31 ——— d–h–w C:\Program Files\InstallShield Installation Information 2007-11-29 22:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\BVRP Software 2007-11-24 18:34 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent 2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-10 02:22 ——— d—–w C:\Documents and Settings\Gili\Application Data\Bioshock 2007-11-02 23:23 ——— d—–w C:\Program Files\The Rosetta Stone 2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent_DNA 2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent 2007-10-30 04:13 ——— d—–w C:\Documents and Settings\Gili\Application Data\SecondLife 2007-10-29 20:00 ——— d—–w C:\Program Files\RosettaStoneLtdServices 2007-10-29 20:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices 2007-10-28 16:20 218,064 —-a-w C:\Documents and Settings\Gili\Application Data\GDIPFONTCACHEV1.DAT 2007-10-28 15:52 ——— d—–w C:\Program Files\AIM6 2007-10-28 15:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads 2007-10-21 17:46 ——— d—–w C:\Program Files\Easy CD-DA Extractor 9 2007-10-21 07:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint 2006-12-10 05:19 24,192 —-a-w C:\Documents and Settings\Gili\usbsermptxp.sys 2006-12-10 05:19 22,768 —-a-w C:\Documents and Settings\Gili\usbsermpt.sys 2006-12-10 05:12 92,064 —-a-w C:\Documents and Settings\Gili\mqdmmdm.sys 2006-12-10 05:12 9,232 —-a-w C:\Documents and Settings\Gili\mqdmmdfl.sys 2006-12-10 05:12 79,328 —-a-w C:\Documents and Settings\Gili\mqdmserd.sys 2006-12-10 05:12 66,656 —-a-w C:\Documents and Settings\Gili\mqdmbus.sys 2006-12-10 05:12 6,208 —-a-w C:\Documents and Settings\Gili\mqdmcmnt.sys 2006-12-10 05:12 5,936 —-a-w C:\Documents and Settings\Gili\mqdmwhnt.sys 2006-12-10 05:12 4,048 —-a-w C:\Documents and Settings\Gili\mqdmcr.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}] C:\Program Files\QdrDrive\QdrDrive8.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1}] C:\WINDOWS\system32\tygn.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1AA8E3A-63FA-365D-D829-3BE6778F03B7}] C:\WINDOWS\system32\ybeupl.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48] "ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 16:56] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2007-08-31 16:46] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56] "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hsijxizk] hsijxizk.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayyaxu] yayyaxu.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gili^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Gili\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA] 2007-11-02 16:10 286016 –a—— C:\Program Files\BitTorrent_DNA\dna.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] 2003-06-26 17:50 212992 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2003-06-25 10:24 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] 2001-07-09 04:50 155648 -ra—— C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pho] C:\Documents and Settings\Gili\Application Data\A?pPatch\?hkntfs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule10] C:\Program Files\QdrModule\QdrModule10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack10] C:\Program Files\QdrPack\QdrPack10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\qttask.exe -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Program Files\Steam\Steam.exe -silent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "RosettaStoneLtdController"=2 (0x2) "IDriverT"=3 (0x3) R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys S3 PciCon;PciCon;\??\D:\PciCon.sys S4 RosettaStoneLtdController;RosettaStoneLtdController;"C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c219698-e164-11db-b8e2-0015f27269c9}] \Shell\AutoRun\command - F:\wd_windows_tools\setup.exe . Contents of the 'Scheduled Tasks' folder "2007-12-14 23:04:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-09-13 04:41:07 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2500 series#1147495092.job" - C:\Program Files\HP\hpcoretech\comp\hpdarc.exe . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-15 18:15:10 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … ************************************************************************** . Completion time: 2007-12-15 18:17:11 - machine was rebooted . 2007-12-13 00:02:03 — E O F — And here's the HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:18:56 PM, on 12/15/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\ULI5289\ALi5289.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Gili\Desktop\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing) O2 - BHO: (no name) - {B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1} - C:\WINDOWS\system32\tygn.dll (file missing) O2 - BHO: (no name) - {E1AA8E3A-63FA-365D-D829-3BE6778F03B7} - C:\WINDOWS\system32\ybeupl.dll (file missing) O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: hsijxizk - hsijxizk.dll (file missing) O20 - Winlogon Notify: yayyaxu - yayyaxu.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – End of file - 3913 bytes
Hi

1. Please open Notepad
    [*]Click Start , then Run

    [*]Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    File::C:\WINDOWS\system32\mcrh.tmpC:\WINDOWS\system32\tygn.dllC:\WINDOWS\system32\ybeupl.dllC:\WINDOWS\system32\hsijxizk.dllC:\WINDOWS\system32\yayyaxu.dllFolder::C:\Documents and Settings\All Users\Application Data\ViewpointC:\Program Files\QdrDriveRegistry::[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1AA8E3A-63FA-365D-D829-3BE6778F03B7}][-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hsijxizk][-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayyaxu]
    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [external image: Posted Image]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
      [*]Combofix.txt

      [*]A new HijackThis log.

      Please do an online scan with Kaspersky WebScanner

      Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

      You will be prompted to install an ActiveX component from Kaspersky,
      Click Yes.
        [*]The program will launch and then begin downloading the latest definition files:


        [*]Once the files have been downloaded click on NEXT


        [*]Now click on Scan Settings


        [*]In the scan settings make sure that the following are selected:

        o Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)

        o Scan Options:
        Scan Archives Scan Mail Bases


        [*]Click OK


        [*]Now under select a target to scan:

        Select My Computer

        [*]The program will start and scan your system.


        [*]The scan will take a while so be patient and let it run.


        [*]Once the scan is complete it will display if your system has been infected.

        o Now click on the Save as Text button:

        [*]Save the file to your desktop.

        Please post the results of the Kaspersky scan in your next reply, along with a fresh HijackThis log.

        Also, please describe how your computer is behaving at the moment.

        Thanks,

        jpshortstuff
ComboFix log: ComboFix 07-12-15.5 - Gili 2007-12-15 19:10:46.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1634 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gili\Desktop\CFScript.txt * Created a new restore point FILE C:\WINDOWS\system32\hsijxizk.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\tygn.dll C:\WINDOWS\system32\yayyaxu.dll C:\WINDOWS\system32\ybeupl.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\Viewpoint C:\WINDOWS\system32\mcrh.tmp . ((((((((((((((((((((((((( Files Created from 2007-11-16 to 2007-12-16 ))))))))))))))))))))))))))))))) . 2007-12-15 19:08 . 2007-12-15 19:08 0 –a—— C:\Documents and Settings\Gili\.exe 2007-12-15 00:36 . 2007-12-15 00:36 d–h—– C:\WINDOWS\PIF 2007-12-14 18:06 . 2007-12-14 18:06 54,156 –ah—– C:\WINDOWS\QTFont.qfn 2007-12-14 18:06 . 2007-12-14 18:06 1,409 –a—— C:\WINDOWS\QTFont.for 2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Program Files\Apple Software Update 2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Documents and Settings\All Users\Application Data\Apple 2007-12-14 18:03 . 2007-12-14 18:03 d——– C:\Program Files\7-Zip 2007-12-12 01:31 . 2007-12-12 01:31 d——– C:\Documents and Settings\Gili\Application Data\Talkback 2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx 2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts 2007-12-10 03:32 . 2007-12-10 12:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-12-10 03:26 . 2007-12-10 03:26 d——– C:\Program Files\Enigma Software Group 2007-12-10 01:57 . 2007-12-10 01:57 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft 2007-12-03 22:59 . 2007-12-03 23:14 d——– C:\Program Files\Photomatix 2007-12-03 22:38 . 2007-12-03 22:55 d——– C:\Program Files\eMule 2007-12-03 17:23 . 2007-12-03 17:24 d——– C:\Program Files\MioNetApplet 2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Program Files\Avanquest update 2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Documents and Settings\Gili\Application Data\InstallShield 2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Gili\Application Data\Canon 2007-11-27 17:39 . 2007-12-06 17:51 d——– C:\Program Files\Canon 2007-11-27 17:37 . 2007-12-06 17:50 d——– C:\Program Files\Common Files\Canon . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-16 00:08 0 —-a-w C:\Documents and Settings\Gili\.exe 2007-12-14 23:07 ——— d—–w C:\Program Files\QuickTime 2007-12-14 23:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-12-10 06:23 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent DNA 2007-12-01 22:09 ——— d—–w C:\Program Files\Java 2007-11-30 21:48 ——— d—–w C:\Documents and Settings\Gili\Application Data\Viewpoint 2007-11-30 21:46 ——— d—–w C:\Program Files\Kodak 2007-11-30 21:44 ——— d—–w C:\Program Files\LightSurf 2007-11-29 22:32 ——— d—–w C:\Program Files\Motorola Phone Tools 2007-11-29 22:31 ——— d–h–w C:\Program Files\InstallShield Installation Information 2007-11-29 22:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\BVRP Software 2007-11-24 18:34 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent 2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-10 02:22 ——— d—–w C:\Documents and Settings\Gili\Application Data\Bioshock 2007-11-02 23:23 ——— d—–w C:\Program Files\The Rosetta Stone 2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent_DNA 2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent 2007-10-30 04:13 ——— d—–w C:\Documents and Settings\Gili\Application Data\SecondLife 2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll 2007-10-29 20:00 ——— d—–w C:\Program Files\RosettaStoneLtdServices 2007-10-29 20:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices 2007-10-28 16:20 218,064 —-a-w C:\Documents and Settings\Gili\Application Data\GDIPFONTCACHEV1.DAT 2007-10-28 15:52 ——— d—–w C:\Program Files\AIM6 2007-10-28 15:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads 2007-10-27 22:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll 2007-10-21 17:46 ——— d—–w C:\Program Files\Easy CD-DA Extractor 9 2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll 2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll 2007-09-17 18:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll 2007-09-17 18:22 739,840 —-a-w C:\WINDOWS\system32\DivX.dll 2006-12-10 05:19 24,192 —-a-w C:\Documents and Settings\Gili\usbsermptxp.sys 2006-12-10 05:19 22,768 —-a-w C:\Documents and Settings\Gili\usbsermpt.sys 2006-12-10 05:12 92,064 —-a-w C:\Documents and Settings\Gili\mqdmmdm.sys 2006-12-10 05:12 9,232 —-a-w C:\Documents and Settings\Gili\mqdmmdfl.sys 2006-12-10 05:12 79,328 —-a-w C:\Documents and Settings\Gili\mqdmserd.sys 2006-12-10 05:12 66,656 —-a-w C:\Documents and Settings\Gili\mqdmbus.sys 2006-12-10 05:12 6,208 —-a-w C:\Documents and Settings\Gili\mqdmcmnt.sys 2006-12-10 05:12 5,936 —-a-w C:\Documents and Settings\Gili\mqdmwhnt.sys 2006-12-10 05:12 4,048 —-a-w C:\Documents and Settings\Gili\mqdmcr.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48] "ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 16:56] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2007-08-31 16:46] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56] "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gili^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Gili\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA] 2007-11-02 16:10 286016 –a—— C:\Program Files\BitTorrent_DNA\dna.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] 2003-06-26 17:50 212992 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2003-06-25 10:24 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] 2001-07-09 04:50 155648 -ra—— C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pho] C:\Documents and Settings\Gili\Application Data\A?pPatch\?hkntfs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule10] C:\Program Files\QdrModule\QdrModule10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack10] C:\Program Files\QdrPack\QdrPack10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\qttask.exe -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Program Files\Steam\Steam.exe -silent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "RosettaStoneLtdController"=2 (0x2) "IDriverT"=3 (0x3) R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys S3 PciCon;PciCon;\??\D:\PciCon.sys S4 RosettaStoneLtdController;RosettaStoneLtdController;"C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c219698-e164-11db-b8e2-0015f27269c9}] \Shell\AutoRun\command - F:\wd_windows_tools\setup.exe . Contents of the 'Scheduled Tasks' folder "2007-12-14 23:04:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-09-13 04:41:07 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2500 series#1147495092.job" - C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 2500 series#1147495092 . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-15 19:14:35 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-15 19:15:16 C:\ComboFix2.txt … 2007-12-15 18:17 . 2007-12-13 00:02:03 — E O F — Kaspersky Log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Saturday, December 15, 2007 9:45:37 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 16/12/2007 Kaspersky Anti-Virus database records: 483501 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 130301 Number of viruses found: 9 Number of infected objects: 23 Number of suspicious objects: 0 Duration of the scan process: 01:15:05 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\cert8.db Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\history.dat Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\key3.db Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\parent.lock Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\search.sqlite Object is locked skipped C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/BlackBox.class Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1 ZIP: infected - 3 skipped C:\Documents and Settings\Gili\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\AOL OCP\AIM\Storage\data\giliofleaves\localStorage\common.cls Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Gili\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Gili\Local Settings\History\History.IE5\MSHist012007121520071216\index.dat Object is locked skipped C:\Documents and Settings\Gili\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Gili\ntuser.dat Object is locked skipped C:\Documents and Settings\Gili\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\qoobox\Quarantine\C\WINDOWS\system32\fskrrbal.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\WINDOWS\system32\gmsywodu.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\WINDOWS\system32\qqeeljce.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\WINDOWS\system32\scgnouml.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\WINDOWS\system32\uegmhmcp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\WINDOWS\system32\xtfiitgx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP115\A0016756.exe Infected: Trojan-Downloader.Win32.Tibs.rl skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0016959.dll Infected: not-a-virus:AdWare.Win32.AdBand.e skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0016960.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0017004.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017037.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017164.exe Infected: Trojan-Downloader.Win32.Agent.fuc skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017248.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018831.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018832.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018833.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018834.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018835.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018836.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP122\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. New HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:47:54 PM, on 12/15/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\ULI5289\ALi5289.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Gili\Desktop\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – End of file - 3550 bytes The PC seems fine (no pop-ups, although I usually get them at start-up) but Kaspersky picked up a buncha infections.
Hi

Run ATFCleaner. Place a check mark next to Java Cache, and then hit Empty Selected.


I'm going to bug you about installing an Anti-Virus program now. Without one, you are very likely to get yourself more infections, and we don't like seeing return visitors.


As well as the Anti-Virus, you don't appear to have a Firewall running. It is equally critical to have both of these security softwares intalled and running, if you want to stand a chance of preventing infection.

Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
1) ZoneAlarm
2) Agnitum
3) Sunbelt/Kerio
4) Comodo


After this, reboot your computer and post a fresh HijackThis log, and describe all (if any) remaining problems with your computer.

Thanks,

jpshortstuff
Installed Avast! and ran it. The PC rebooted and ran the scan upon reboot. Here's the log: 12/16/2007 10:58 Scan of all local drives File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0017000.exe\[UPX] is infected by Win32:PurityScan-Q [Trj], Deleted File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017164.exe\[UPX] is infected by Win32:Agent-NMX [Trj], Deleted File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017247.exe is infected by Win32:Adware-gen [Adw], Deleted Number of searched folders: 8580 Number of tested files: 122955 Number of infected files: 3 HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:56:02 AM, on 12/16/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\ULI5289\ALi5289.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Alwil Software\Avast4\setup\avast.setup C:\Documents and Settings\Gili\Desktop\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – End of file - 4405 bytes The PC seems fine, although Avast! didn't pick up as many infections as Kaspersky did yesterday.
The items found by both Avast! and Kaspersky are nothing to worry about, they are leftovers that we will deal with in the final post.How about the firewall, are you going to get one of those?
Hi Gilco

Log looks good :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.


Re-enable TeaTimer:
  • Open Spybot
  • Click on Tools in bottom left hand corner.
  • Click on Resident.
  • Check Resident "TeaTimer" box.
  • Click on Allow change ONLY to popup box with:
  • Entry: SpybotSD Teatimer
  • Click on Mode, select Default mode
  • Close Spybot

Now that you appear to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:
    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
All done. This part is unclear: # Click on Allow change ONLY to popup box with: # Entry: SpybotSD Teatimer Where would I find that in SpyBot?
When you "Check Resident "TeaTimer" box." it usually comes up with various popup boxes. One of them is "Entry: SpybotSD Teatimer", this one you can allow, the rest deny. If you didn't get them, don't worry I think thats fine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI