This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need some help with some irritable spyware

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well essentially i have pop-up web pages, constant java security "warnings", very slow connection while browsing and playing games, and my computer likes to take its time loading whatever needs to be loaded… i'm pretty sure it got infected from an out of date java since i can't remove the program from my computer successfuly. any help would be greatly appreciated :) (i also ran spyware doctor many a time, but it cant get it all off my computer)

heres my log

Logfile of HijackThis v1.99.1
Scan saved at 11:38:57 PM, on 1/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\VentSrv\ventrilo_svc.exe
C:\Program Files\VentSrv\ventrilo_srv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Windows NT\meweledus77798.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Insider\Insider.exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\J-Fisch\Desktop\DarkAdapted.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wudfhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=,
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: Web Assistent - {43DAB78C-B845-83AD-A86A-7DFB90277939} - C:\Program Files\psdriver\psdriver.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {845945B0-0E1E-49E1-A3DC-D1766AABF711} - C:\Program Files\Windows Media Player\mepov24418.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll
O2 - BHO: BndShell3 BHO Class - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - C:\Program Files\ISM\BndDrive7.dll (file missing)
O2 - BHO: BndDrive2 BHO Class - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - C:\Program Files\ISM\BndDrive3.dll
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [{6B-BA-A1-11-ZN}] "c:\windows\system32\nsdsregs.exe" SKY002
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.341.0\SeekmoSA.exe"
O4 - HKLM\..\Run: [SDTray] C:\Program Files\Spyware Doctor\SDTrayApp.exe
O4 - HKLM\..\Run: [meweledus] C:\Program Files\Windows NT\meweledus77798.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\J-Fisch\Application Data\Microsoft\Windows\uovej.exe
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AGC.lnk = C:\Program Files\AGC\agc.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon…/cx_tgctlcm.jsp
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectkitsetup.cox.net/wizlet/…flowActiveX.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F780BF6-729E-4774-95E4-AA923B483927}: NameServer = 194.54.90.226
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O18 - Filter: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InstallTest - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" /test (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Metric Conversion Calculator Installer - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" /update (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Here you go, and thanks again µTorrent Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Photoshop 7.0 AGC AOL Instant Messenger ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver ATI HYDRAVISION AVG Free Edition Azureus Vuze Badongo BitTornado 0.3.7 BitTorrent 4.4.1 C-Media WDM Audio Driver Combined Community Codec Pack 2007-02-22 Command & Conquer 3 Command & Conquer The First Decade Compact Wireless-G USB Adapter Cox Online Support Controls DAEMON Tools DAO DAO Declan's Japanese FlashCards v1.4 Digidesign Shared Plug-Ins DirectShow .SHN FIlter DivX Codec DivX Player DVD Decrypter (Remove Only) Enable S3 for USB Device FLV Player 1.3.3 Fraps (remove only) Free Download Manager 2.1 FruityLoops Studio Producer Edition v4.01 Google Toolbar for Internet Explorer Haali Media Splitter Half-Life Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB926239) ILLUSION ????2 Indeo® Software Intel® PRO Network Adapters and Drivers Internet Speed Monitor iTunes Java™ SE Runtime Environment 6 Update 1 LockBox LookSmart Toolbar LucasArts' Curse of Monkey Island LucasArts' Grim Fandango Macromedia Shockwave Player Magic ISO Maker v5.4 (build 0251) Matroska Pack Metric Conversion Calculator Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft User-Mode Driver Framework Feature Pack 1.0 Mozilla Firefox (2.0.0.11) MSXML 6.0 Parser (KB933579) Nero PhotoShow Elite Nero Suite PACE System Files PeerGuardian 2.0 QuickTime RapidLeecher RapidLeecher Real Alternative 1.31 Riva FLV Encoder 2.0 RM2k3 English RTP 1.0 Sam & Max Season 1 ScummVM 0.8.2 Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB944653) Seekmo Browser and Wowpapers Tools Sierra Utilities Spy Sweeper Spyware Doctor 5.0 Starcraft SUPER © Version 2006.19 (FIX) System Shock2 The Sims 2 TitanTV Client components for ATI Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) UseNeXT VDMSound 2.0.4 Ventrilo Client Ventrilo Server VideoLAN VLC media player 0.8.4a Viewpoint Manager (Remove Only) Viewpoint Media Player WinAVIVideoConverter Windows Driver Package - Microsoft WPD (12/01/2006 1.2.0.0) Windows Installer 3.1 (KB893803) Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinImage WinRAR archiver World of Warcraft XviD MPEG-4 Video Codec Yahoo! Toolbar Zune
Hi

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.



If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go

  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Report.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Report.txt \/


SDFix: Version 1.124

Run by [removed] on Sun 01/06/2008 at 02:08 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\1AE.TMP - Deleted
C:\PROGRA~1\PAGE~1.HTM - Deleted
C:\PROGRA~1\MESSEN~1\RTEKED~1.HTM - Deleted
C:\PROGRA~1\WINDOW~1\MEWELE~1.EXE - Deleted
C:\Documents and Settings\J-Fisch\Desktop\Click to Find and Fix Errors.lnk - Deleted
C:\Program Files\Insider\Insider.exe - Deleted
C:\Program Files\Insider\UnInstall.exe - Deleted
C:\Program Files\.autoreg - Deleted
C:\Documents and Settings\J-Fisch\Application Data\.rdr.ini - Deleted
C:\DOCUME~1\J-Fisch\LOCALS~1\Temp\MBDownloader_876923.exe - Deleted
C:\WINDOWS\system32\help.txt - Deleted
C:\WINDOWS\system32\vx.tll - Deleted



Folder C:\Documents and Settings\J-Fisch\Application Data\WinTouch - Removed
Folder C:\Program Files\Insider - Removed
Folder C:\Temp\tn3 - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 14:18:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,d0,6f,d3,db,8d,7c,b7,8e,38,d6,6b,45,26,24,b9,8f,28,..
"hj34z0"=hex:36,40,f1,3f,87,8a,7d,31,3f,78,ae,fb,bc,38,2d,12,f4,02,3e,81,c8,..

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\XP\23]
"DisplayName"="\x3e98\23\x40d0\23"
"DeviceDesc"="\x3e98\23\x40d0\23"
"ProviderName"=""
"MFG"="\x435c\x616c\x7373\"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\x5058\23\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"07267.inf"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"OfflineDetectionPending"=dword:00000001

scanning hidden files …


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 6


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Valve\\Steam\\Steam.exe"="C:\\Valve\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike source beta\\hl2.exe"="C:\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike source beta\\hl2.exe:*:Enabled:hl2"
"C:\\Valve\\Steam\\SteamApps\\[removed]\\condition zero\\hl.exe"="C:\\Valve\\Steam\\SteamApps\\[removed]\\condition zero\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp:*:Enabled:KazaaLite"
"C:\\Program Files\\BitTorrent\\btdownloadgui.exe"="C:\\Program Files\\BitTorrent\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\World of Warcraft\\WoW-1.1.1-patch-enUS-Downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.1.1-patch-enUS-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.2.1-patch-enUS-Downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.2.1-patch-enUS-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe"="C:\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\eXeem\\eXeem.exe"="C:\\Program Files\\eXeem\\eXeem.exe:*:Enabled:eXeem"
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Warcraft III\\war3.exe"="C:\\Program Files\\Warcraft III\\war3.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Lionhead Studios Ltd\\Black & White\\runblack.exe"="C:\\Program Files\\Lionhead Studios Ltd\\Black & White\\runblack.exe:*:Enabled:lh"
"C:\\Program Files\\World of Warcraft\\WoW-1.5.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.5.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Kazaa Lite Resurrection\\kazaalite.kpp"="C:\\Program Files\\Kazaa Lite Resurrection\\kazaalite.kpp:*:Enabled:kazaalite"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\World of Warcraft\\WoW-1.5.1.4449-to-1.6.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.5.1.4449-to-1.6.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.6.0.4500-to-1.6.1-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.6.0.4500-to-1.6.1-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.6.1.4544-to-1.7.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.6.1.4544-to-1.7.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.4-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.4-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\Kazaa Lite Revolution\\kazaalite.kpp"="C:\\Program Files\\Kazaa Lite Revolution\\kazaalite.kpp:*:Enabled:kazaalite"
"C:\\Program Files\\VentSrv\\ventrilo_srv.exe"="C:\\Program Files\\VentSrv\\ventrilo_srv.exe:*:Enabled:ventrilo_srv"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\J-Fisch\\Local Settings\\Temp\\Temporary Internet Files\\Content.IE5\\ODYF89IV\\WowExpansionMaster_1024_2100_B_English.avi-downloader[1].exe"="C:\\Documents and Settings\\J-Fisch\\Local Settings\\Temp\\Temporary Internet Files\\Content.IE5\\ODYF89IV\\WowExpansionMaster_1024_2100_B_English.avi-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\J-Fisch\\Local Settings\\Temporary Internet Files\\Content.IE5\\UPZCD4ZM\\WowExpansionMaster_1024_2100_B_English.avi-downloader[1].exe"="C:\\Documents and Settings\\J-Fisch\\Local Settings\\Temporary Internet Files\\Content.IE5\\UPZCD4ZM\\WowExpansionMaster_1024_2100_B_English.avi-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Starcraft\\StarCraft.exe"="C:\\Program Files\\Starcraft\\StarCraft.exe:*:Disabled:Starcraft"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"c:\\windows\\system32\\rlvknlg.exe"="c:\\windows\\system32\\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"C:\\WINDOWS\\csrss.exe"="C:\\WINDOWS\\csrss.exe:*:Enabled:1C1D1407011BA664"
"C:\\WINDOWS\\svchost.exe"="C:\\WINDOWS\\svchost.exe:*:Disabled:svchost"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:Blizzard Repair Utility"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Fri 13 May 2005 217,073 A.SHR — "C:\WINDOWS\meta4.exe"
Mon 24 Oct 2005 66,560 A.SHR — "C:\WINDOWS\MOTA113.exe"
Thu 13 Oct 2005 422,400 A.SHR — "C:\WINDOWS\x2.64.exe"
Mon 7 Mar 2005 56 ..SHR — "C:\WINDOWS\system32\72C6F1F7B0.sys"
Fri 7 Oct 2005 308,224 A.SHR — "C:\WINDOWS\system32\avisynth.dll"
Thu 14 Jul 2005 27,648 A.SHR — "C:\WINDOWS\system32\AVSredirect.dll"
Sun 26 Jun 2005 616,448 A.SHR — "C:\WINDOWS\system32\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR — "C:\WINDOWS\system32\cygz.dll"
Sat 24 Jan 2004 70,656 A.SHR — "C:\WINDOWS\system32\i420vfw.dll"
Sun 29 Oct 2006 11,690 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 27 Apr 2006 2,945,024 A.SHR — "C:\WINDOWS\system32\Smab.dll"
Mon 28 Feb 2005 240,128 A.SHR — "C:\WINDOWS\system32\x.264.exe"
Sat 24 Jan 2004 70,656 A.SHR — "C:\WINDOWS\system32\yv12vfw.dll"
Thu 5 Aug 2004 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 31 Dec 2007 35,329 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\EHGammaLib2501.dll"
Mon 31 Dec 2007 88,576 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\rbap550.dll"
Mon 31 Dec 2007 30,720 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\RBInternetEncodings600.dll"
Mon 31 Dec 2007 39,936 A..H. — "C:\Documents and Settings\J-Fisch\Application Data\RBShell555.dll"
Wed 23 Aug 2006 72,192 ..SHR — "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Sun 1 Apr 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 13 Sep 2004 94,458 …H. — "C:\Program Files\Ahead\Nero PhotoShow\data\Nero PhotoShow Elite.exe"
Tue 4 Jun 2002 84,992 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Tue 4 Jun 2002 44,032 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Mon 9 Dec 2002 73,766 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Mon 9 Dec 2002 65,575 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Tue 4 Jun 2002 20,480 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Mon 9 Dec 2002 176,165 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Mon 9 Dec 2002 94,208 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Mon 9 Dec 2002 217,127 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sat 3 Nov 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 548,940 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Mon 9 Dec 2002 102,439 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Fri 30 Mar 2007 857 …HR — "C:\Documents and Settings\J-Fisch\Application Data\SecuROM\UserData\securom_v7_01.bak"
Fri 2 Nov 2007 354 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic101.tmp"
Sat 24 Nov 2007 189 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic11.tmp"
Sat 24 Nov 2007 82 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic13.tmp"
Thu 20 Sep 2007 390 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic15.tmp"
Mon 17 Sep 2007 920 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic16.tmp"
Tue 18 Sep 2007 172 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic168.tmp"
Tue 18 Sep 2007 161 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic169.tmp"
Mon 17 Sep 2007 278 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic17.tmp"
Mon 17 Sep 2007 176 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic18.tmp"
Wed 19 Sep 2007 316 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic180.tmp"
Wed 19 Sep 2007 460 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic181.tmp"
Sun 15 Jul 2007 145 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic1A8.tmp"
Wed 28 Nov 2007 455 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic1F6.tmp"
Sun 2 Dec 2007 312 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic1FF.tmp"
Wed 24 Oct 2007 102 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic286.tmp"
Wed 24 Oct 2007 452 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic289.tmp"
Wed 24 Oct 2007 121 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic28C.tmp"
Thu 11 Oct 2007 177 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic2A.tmp"
Sun 2 Dec 2007 306 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic2AB.tmp"
Sun 23 Sep 2007 400 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic33.tmp"
Mon 17 Sep 2007 161 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic38.tmp"
Mon 17 Sep 2007 161 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3A.tmp"
Thu 11 Oct 2007 336 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3AF.tmp"
Mon 17 Sep 2007 278 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3B.tmp"
Thu 11 Oct 2007 250 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3B4.tmp"
Mon 17 Sep 2007 456 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3C.tmp"
Sun 2 Dec 2007 375 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3CD.tmp"
Mon 17 Sep 2007 161 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3D.tmp"
Sun 2 Dec 2007 555 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3D9.tmp"
Sun 2 Dec 2007 225 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic3DD.tmp"
Tue 11 Dec 2007 289 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic44F.tmp"
Tue 11 Dec 2007 507 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic451.tmp"
Tue 16 Oct 2007 435 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic5A7.tmp"
Mon 17 Sep 2007 172 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic6C.tmp"
Tue 25 Dec 2007 103 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\tic9C1.tmp"
Mon 5 Nov 2007 513 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticAE.tmp"
Thu 27 Dec 2007 371 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticCC0.tmp"
Tue 18 Sep 2007 161 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticE9.tmp"
Tue 18 Sep 2007 172 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticEA.tmp"
Tue 18 Sep 2007 172 A..H. — "C:\Documents and Settings\J-Fisch\Local Settings\Temp\Free Download Manager\ticED.tmp"
Fri 13 Jul 2007 493,201 A..H. — "C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\New Folder (2)\Character - Mitsuru.zip"
Fri 13 Jul 2007 525,374 A..H. — "C:\Documents and Settings\J-Fisch\Desktop\J-Feezle\HWOE\New Folder (2)\Character - Fuuka.zip"

Finished!


Combofix.txt \/



ComboFix 08-01-04.1 - J-Fisch 2008-01-06 14:48:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.709 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\SeekmoSA
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht
C:\Documents and Settings\J-Fisch\Application Data\EHGammaLib2501.dll
C:\Documents and Settings\J-Fisch\Application Data\rbap550.dll
C:\Documents and Settings\J-Fisch\Application Data\RBInternetEncodings600.dll
C:\Documents and Settings\J-Fisch\Application Data\RBShell555.dll
C:\Documents and Settings\J-Fisch\Application Data\Seekmo
C:\Documents and Settings\J-Fisch\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\J-Fisch\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\J-Fisch\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\ISM
C:\Program Files\ISM\archupd.exe
C:\Program Files\ISM\BndDrive.dll
C:\Program Files\ISM\BndDrive2.dll
C:\Program Files\ISM\BndDrive3.dll
C:\Program Files\ISM\BndDrive6.dll
C:\Program Files\ISM\bndloader.exe
C:\Program Files\ISM\dictionary.gz
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\kazooupd.exe
C:\Program Files\ISM\syncupd.exe
C:\Program Files\ISM\synupd.exe
C:\Program Files\ISM\targets.gz
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\ISM2
C:\Program Files\ISM2\cringupd.exe
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\hydramedupd.exe
C:\Program Files\ISM2\ISMPack5.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\ISM2\ISMPack7.exe
C:\Program Files\ISM2\ISMPack8.exe
C:\Program Files\ISM2\targets.gz
C:\Program Files\pasystem
C:\Program Files\pasystem\support.dat
C:\Program Files\pasystem\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive8.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kupd.exe
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack10.exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\QdrPack\zhydupd.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\hosts
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\winpfz32.sys

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-06 14:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 14:07 . 2008-01-06 14:07 d——– C:\WINDOWS\ERUNT
2008-01-06 14:06 . 2008-01-06 14:06 d——– C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-31 18:25 . 2007-12-31 18:25 d——– C:\Program Files\Ventrilo
2007-12-27 19:30 . 2007-12-27 19:30 d——– C:\Program Files\RcvSystem
2007-12-15 01:23 . 2007-12-31 18:49 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-15 01:23 . 2007-12-15 01:23 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 20:43 ——— d—–w C:\Documents and Settings\J-Fisch\Application Data\Free Download Manager
2008-01-06 20:18 ——— d—–w C:\Program Files\VentSrv
2008-01-06 15:42 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-01 00:25 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 23:06 ——— d—–w C:\Documents and Settings\J-Fisch\Application Data\Azureus
2007-12-30 03:24 ——— d—–w C:\Program Files\World of Warcraft
2007-12-28 23:39 ——— d—–w C:\Program Files\Free Download Manager
2007-11-28 15:14 ——— d—–w C:\Program Files\Common Files\riio
2007-11-19 18:53 ——— d—–w C:\Program Files\Azureus
2007-11-18 01:30 ——— d—–w C:\Program Files\EA GAMES
2007-11-15 15:03 ——— d—–w C:\Program Files\MagicISO
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2006-01-01 12:18 36 —-a-w C:\Documents and Settings\J-Fisch\klextlock.dat
2005-05-13 22:12 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 16:13 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-10-14 02:27 422,400 –sha-r C:\WINDOWS\x2.64.exe
2005-03-07 17:39 56 –sh–r C:\WINDOWS\system32\72C6F1F7B0.sys
2005-10-08 00:14 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 17:31 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 20:32 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 03:37 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 05:00 70,656 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-10-29 07:58 11,690 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2006-04-27 15:24 2,945,024 –sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 18:16 240,128 –sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 05:00 70,656 –sha-r C:\WINDOWS\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{43DAB78C-B845-83AD-A86A-7DFB90277939}]
2007-04-18 06:33 24064 –a—— C:\Program Files\psdriver\psdriver.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{845945B0-0E1E-49E1-A3DC-D1766AABF711}]
C:\Program Files\Windows Media Player\mepov24418.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ABA9A9C-8791-4d61-8D5B-BCC9448EA573}]
C:\Program Files\ISM\BndDrive7.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"AIM"="C:\Program Files\AIM\aim.exe" [2004-04-27 16:18 61440]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2004-11-11 19:50 212992]
"PaSystem"="C:\Program Files\pasystem\pasystem.exe" [ ]
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 22:41 94208]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-22 08:16 579072]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-12-22 08:16 406528]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 04:48 77824 C:\WINDOWS\SOUNDMAN.EXE]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 21:00 270336]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43 45056]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 15:24 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-26 14:17 282624]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-03-14 16:03 24104]
"{6B-BA-A1-11-ZN}"="c:\windows\system32\nsdsregs.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 19:09 4865600]
"meweledus"="C:\Program Files\Windows NT\meweledus77798.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 07:20 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{43DAB78C-B845-83AD-A86A-7DFB90277939}"= C:\Program Files\psdriver\psdriver.dll [2007-04-18 06:33 24064]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

S2 InstallTest;InstallTest;"C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" []
S2 Metric Conversion Calculator Installer;Metric Conversion Calculator Installer;"C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" []
S3 FLASHSYS;FLASHSYS;C:\WINDOWS\system32\DRIVERS\FLASHSYS.sys []
S3 kbeepm;kbeepm;C:\DOCUME~1\J-Fisch\LOCALS~1\Temp\kbeepm.sys []
S3 PCAlertDriver;PCAlertDriver;C:\Program Files\MSI\Core Center\NTGLM7X.sys []
S3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys []
S3 WEBNTACCESS;WEBNTACCESS;C:\WINDOWS\system32\NTACCESS.SYS []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 14:57:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ginamsi.dll
.
Completion time: 2008-01-06 15:00:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-06 21:00:42
.
2007-12-23 09:02:27 — E O F —


Hijackthis log \/


Logfile of HijackThis v1.99.1
Scan saved at 3:02:06 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\VentSrv\ventrilo_svc.exe
C:\Program Files\VentSrv\ventrilo_srv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Web Assistent - {43DAB78C-B845-83AD-A86A-7DFB90277939} - C:\Program Files\psdriver\psdriver.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {845945B0-0E1E-49E1-A3DC-D1766AABF711} - C:\Program Files\Windows Media Player\mepov24418.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - C:\Program Files\ISM\BndDrive7.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [{6B-BA-A1-11-ZN}] "c:\windows\system32\nsdsregs.exe" SKY002
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\Run: [meweledus] C:\Program Files\Windows NT\meweledus77798.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AGC.lnk = C:\Program Files\AGC\agc.exe
O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Google; Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate; English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon…/cx_tgctlcm.jsp
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectkitsetup.cox.net/wizlet/…flowActiveX.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F780BF6-729E-4774-95E4-AA923B483927}: NameServer = 194.54.90.226
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InstallTest - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" /test (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Metric Conversion Calculator Installer - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" /update (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hi

Just need to run a few tests.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.


Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\x2.64.exe
Click Send.
Please post the results of this scan to this thread.

Do the same for these files:
C:\WINDOWS\system32\72C6F1F7B0.sys
C:\WINDOWS\system32\x.264.exe
C:\WINDOWS\system32\yv12vfw.dll
C:\WINDOWS\x2.64.exe \/ Antivirus Version Last Update Result AhnLab-V3 2008.1.5.11 2008.01.05 - AntiVir 7.6.0.46 2008.01.06 - Authentium 4.93.8 2008.01.06 - Avast 4.7.1098.0 2008.01.06 - AVG 7.5.0.516 2008.01.07 - BitDefender 7.2 2008.01.07 - CAT-QuickHeal 9.00 2008.01.05 - ClamAV 0.91.2 2008.01.07 - DrWeb 4.44.0.09170 2008.01.06 - eSafe 7.0.15.0 2008.01.06 suspicious Trojan/Worm eTrust-Vet 31.3.5432 2008.01.04 - Ewido 4.0 2008.01.06 - FileAdvisor 1 2008.01.07 - Fortinet 3.14.0.0 2008.01.06 - F-Prot 4.4.2.54 2008.01.06 - F-Secure 6.70.13030.0 2008.01.06 - Ikarus T3.1.1.15 2008.01.07 - Kaspersky 7.0.0.125 2008.01.07 - McAfee 5200 2008.01.04 - Microsoft 1.3109 2008.01.07 - NOD32v2 2768 2008.01.06 - Norman 5.80.02 2008.01.04 - Panda 9.0.0.4 2008.01.06 - Prevx1 V2 2008.01.07 - Rising 20.25.62.00 2008.01.06 - Sophos 4.24.0 2008.01.07 - Sunbelt 2.2.907.0 2008.01.05 - Symantec 10 2008.01.07 - TheHacker 6.2.9.182 2008.01.06 - VBA32 3.12.2.5 2008.01.06 - VirusBuster 4.3.26:9 2008.01.06 - Webwasher-Gateway 6.6.2 2008.01.06 - Additional information File size: 422400 bytes MD5: d1cdd4d4895fd5c1914728f4f77adf97 SHA1: 5a5da8e75a99e18cfce7a244f992d6578fa46d67 PEiD: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser packers: UPX packers: UPX packers: UPX C:\WINDOWS\system32\72C6F1F7B0.sys \/ Antivirus Version Last Update Result AhnLab-V3 2008.1.5.11 2008.01.05 - AntiVir 7.6.0.46 2008.01.06 - Authentium 4.93.8 2008.01.06 - Avast 4.7.1098.0 2008.01.06 - AVG 7.5.0.516 2008.01.07 - BitDefender 7.2 2008.01.07 - CAT-QuickHeal 9.00 2008.01.05 - ClamAV 0.91.2 2008.01.07 - DrWeb 4.44.0.09170 2008.01.06 - eSafe 7.0.15.0 2008.01.06 - eTrust-Vet 31.3.5432 2008.01.04 - Ewido 4.0 2008.01.06 - FileAdvisor 1 2008.01.07 - Fortinet 3.14.0.0 2008.01.06 - F-Prot 4.4.2.54 2008.01.06 - F-Secure 6.70.13030.0 2008.01.06 - Ikarus T3.1.1.15 2008.01.07 - Kaspersky 7.0.0.125 2008.01.07 - McAfee 5200 2008.01.04 - Microsoft 1.3109 2008.01.07 - NOD32v2 2768 2008.01.06 - Norman 5.80.02 2008.01.04 - Panda 9.0.0.4 2008.01.06 - Prevx1 V2 2008.01.07 - Rising 20.25.62.00 2008.01.06 - Sophos 4.24.0 2008.01.07 - Sunbelt 2.2.907.0 2008.01.05 - Symantec 10 2008.01.07 - TheHacker 6.2.9.182 2008.01.06 - VBA32 3.12.2.5 2008.01.06 - VirusBuster 4.3.26:9 2008.01.06 - Webwasher-Gateway 6.6.2 2008.01.06 - Additional information File size: 56 bytes MD5: a183a4b98c1683234d0a96675c733e7d SHA1: 6dc71bc5f2617fd12815829e911d526fd294d141 PEiD: - C:\WINDOWS\system32\x.264.exe \/ Antivirus Version Last Update Result AhnLab-V3 2008.1.5.11 2008.01.05 - AntiVir 7.6.0.46 2008.01.06 - Authentium 4.93.8 2008.01.06 - Avast 4.7.1098.0 2008.01.06 - AVG 7.5.0.516 2008.01.07 - BitDefender 7.2 2008.01.07 - CAT-QuickHeal 9.00 2008.01.05 - ClamAV 0.91.2 2008.01.07 - DrWeb 4.44.0.09170 2008.01.06 - eSafe 7.0.15.0 2008.01.06 suspicious Trojan/Worm eTrust-Vet 31.3.5432 2008.01.04 - Ewido 4.0 2008.01.06 - FileAdvisor 1 2008.01.07 - Fortinet 3.14.0.0 2008.01.06 - F-Prot 4.4.2.54 2008.01.06 - F-Secure 6.70.13030.0 2008.01.06 - Ikarus T3.1.1.15 2008.01.07 - Kaspersky 7.0.0.125 2008.01.07 - McAfee 5200 2008.01.04 - Microsoft 1.3109 2008.01.07 - NOD32v2 2768 2008.01.06 - Norman 5.80.02 2008.01.04 - Panda 9.0.0.4 2008.01.06 - Prevx1 V2 2008.01.07 - Rising 20.25.62.00 2008.01.06 - Sophos 4.24.0 2008.01.07 - Sunbelt 2.2.907.0 2008.01.05 - Symantec 10 2008.01.07 - TheHacker 6.2.9.182 2008.01.06 - VBA32 3.12.2.5 2008.01.06 - VirusBuster 4.3.26:9 2008.01.06 - Webwasher-Gateway 6.6.2 2008.01.06 - Additional information File size: 240128 bytes MD5: 5fdd7d827c1cc58567367d03d24548ce SHA1: 9937882f96f025991634b2833c5f4bcaef70beb2 PEiD: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser packers: UPX packers: UPX packers: UPX C:\WINDOWS\system32\yv12vfw.dll \/ Antivirus Version Last Update Result AhnLab-V3 2008.1.5.11 2008.01.05 - AntiVir 7.6.0.46 2008.01.06 - Authentium 4.93.8 2008.01.06 - Avast 4.7.1098.0 2008.01.06 - AVG 7.5.0.516 2008.01.07 - BitDefender 7.2 2008.01.07 - CAT-QuickHeal 9.00 2008.01.05 - ClamAV 0.91.2 2008.01.07 - DrWeb 4.44.0.09170 2008.01.06 - eSafe 7.0.15.0 2008.01.06 - eTrust-Vet 31.3.5432 2008.01.04 - Ewido 4.0 2008.01.06 - FileAdvisor 1 2008.01.07 - Fortinet 3.14.0.0 2008.01.06 - F-Prot 4.4.2.54 2008.01.06 - F-Secure 6.70.13030.0 2008.01.06 - Ikarus T3.1.1.15 2008.01.07 - Kaspersky 7.0.0.125 2008.01.07 - McAfee 5200 2008.01.04 - Microsoft 1.3109 2008.01.07 - NOD32v2 2768 2008.01.06 - Norman 5.80.02 2008.01.04 - Panda 9.0.0.4 2008.01.06 - Prevx1 V2 2008.01.07 - Rising 20.25.62.00 2008.01.06 - Sophos 4.24.0 2008.01.07 - Sunbelt 2.2.907.0 2008.01.05 - Symantec 10 2008.01.07 - TheHacker 6.2.9.182 2008.01.06 - VBA32 3.12.2.5 2008.01.06 - VirusBuster 4.3.26:9 2008.01.06 - Webwasher-Gateway 6.6.2 2008.01.06 - Additional information File size: 70656 bytes MD5: 7029a7634c8dfa8ee619e79b1b9a378f SHA1: 2126dc5c319feb0b0f543216c64d242a5067f560 PEiD: - packers: UPX packers: UPX packers: UPX
Hi


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\x2.64.exe 
C:\WINDOWS\system32\Smab.dll
C:\WINDOWS\system32\x.264.exe
C:\Program Files\Windows Media Player\mepov24418.dll
C:\Program Files\Windows NT\meweledus77798.exe
C:\DOCUME~1\J-Fisch\LOCALS~1\Temp\kbeepm.sys

Folder::
C:\Program Files\psdriver
C:\Program Files\ISM
C:\Program Files\pasystem

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{43DAB78C-B845-83AD-A86A-7DFB90277939}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{845945B0-0E1E-49E1-A3DC-D1766AABF711}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ABA9A9C-8791-4d61-8D5B-BCC9448EA573}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PaSystem"=-
"QdrModule9"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{6B-BA-A1-11-ZN}"=-
"meweledus"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{43DAB78C-B845-83AD-A86A-7DFB90277939}"=-
 
Driver::
kbeepm

DirLook::
C:\Program Files\Common Files\riio
C:\Program Files\RcvSystem

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
ComboFix 08-01-04.1 - J-Fisch 2008-01-08 20:17:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.645 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\J-Fisch\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\J-Fisch\LOCALS~1\Temp\kbeepm.sys
C:\Program Files\Windows Media Player\mepov24418.dll
C:\Program Files\Windows NT\meweledus77798.exe
C:\WINDOWS\system32\Smab.dll
C:\WINDOWS\system32\x.264.exe
C:\WINDOWS\x2.64.exe
.
The following files were disabled during the run:
C:\Program Files\Spyware Doctor\klg.dat


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\J-Fisch\Application Data\EHGammaLib2501.dll
C:\Documents and Settings\J-Fisch\Application Data\rbap550.dll
C:\Documents and Settings\J-Fisch\Application Data\RBInternetEncodings600.dll
C:\Documents and Settings\J-Fisch\Application Data\RBShell555.dll
C:\Program Files\psdriver
C:\Program Files\psdriver\psdriver.dll
C:\Program Files\psdriver\psdriver.sys
C:\WINDOWS\system32\Smab.dll
C:\WINDOWS\system32\x.264.exe
C:\WINDOWS\x2.64.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_KBEEPM
——-\kbeepm


((((((((((((((((((((((((( Files Created from 2007-12-09 to 2008-01-09 )))))))))))))))))))))))))))))))
.

2008-01-06 14:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 14:07 . 2008-01-06 14:07 d——– C:\WINDOWS\ERUNT
2008-01-06 14:06 . 2008-01-06 14:06 d——– C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-31 18:25 . 2007-12-31 18:25 d——– C:\Program Files\Ventrilo
2007-12-27 19:30 . 2007-12-27 19:30 d——– C:\Program Files\RcvSystem
2007-12-15 01:23 . 2008-01-06 18:34 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-15 01:23 . 2007-12-15 01:23 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 03:39 ——— d—–w C:\Program Files\Spyware Doctor
2008-01-09 02:21 ——— d—–w C:\Documents and Settings\J-Fisch\Application Data\Free Download Manager
2008-01-08 21:21 ——— d—–w C:\Program Files\World of Warcraft
2008-01-08 14:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-06 20:18 ——— d—–w C:\Program Files\VentSrv
2008-01-01 00:25 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 23:06 ——— d—–w C:\Documents and Settings\J-Fisch\Application Data\Azureus
2007-12-28 23:39 ——— d—–w C:\Program Files\Free Download Manager
2007-11-28 15:14 ——— d—–w C:\Program Files\Common Files\riio
2007-11-19 18:53 ——— d—–w C:\Program Files\Azureus
2007-11-18 01:30 ——— d—–w C:\Program Files\EA GAMES
2007-11-15 15:03 ——— d—–w C:\Program Files\MagicISO
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2006-01-01 12:18 36 —-a-w C:\Documents and Settings\J-Fisch\klextlock.dat
2005-05-13 22:12 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 16:13 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-03-07 17:39 56 –sh–r C:\WINDOWS\system32\72C6F1F7B0.sys
2005-10-08 00:14 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 17:31 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 20:32 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 03:37 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 05:00 70,656 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-10-29 07:58 11,690 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2004-01-25 05:00 70,656 –sha-r C:\WINDOWS\system32\yv12vfw.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\Common Files\riio —-


—- Directory of C:\Program Files\RcvSystem —-

2007-12-27 16:27 20480 –a—— C:\Program Files\RcvSystem\httpdchk.dll


((((((((((((((((((((((((((((( snapshot@2008-01-06_15.00.28.56 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"AIM"="C:\Program Files\AIM\aim.exe" [2004-04-27 16:18 61440]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2004-11-11 19:50 212992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 22:41 94208]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-22 08:16 579072]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [2007-12-22 08:16 406528]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 04:48 77824 C:\WINDOWS\SOUNDMAN.EXE]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 21:00 270336]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43 45056]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 15:24 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-26 14:17 282624]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-03-14 16:03 24104]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 19:09 4865600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 07:20 219136]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

S2 InstallTest;InstallTest;"C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" []
S2 Metric Conversion Calculator Installer;Metric Conversion Calculator Installer;"C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" []
S3 FLASHSYS;FLASHSYS;C:\WINDOWS\system32\DRIVERS\FLASHSYS.sys []
S3 PCAlertDriver;PCAlertDriver;C:\Program Files\MSI\Core Center\NTGLM7X.sys []
S3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys []
S3 WEBNTACCESS;WEBNTACCESS;C:\WINDOWS\system32\NTACCESS.SYS []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 21:39:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ginamsi.dll
.
Completion time: 2008-01-08 21:42:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-09 03:42:05
ComboFix2.txt 2008-01-06 21:00:45
.
2007-12-23 09:02:27 — E O F —





Logfile of HijackThis v1.99.1
Scan saved at 9:43:00 PM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\VentSrv\ventrilo_svc.exe
C:\Program Files\VentSrv\ventrilo_srv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\AGC\agc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AGC.lnk = C:\Program Files\AGC\agc.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon…/cx_tgctlcm.jsp
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200401…meInstaller.exe
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectkitsetup.cox.net/wizlet/…flowActiveX.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F780BF6-729E-4774-95E4-AA923B483927}: NameServer = 194.54.90.226
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A999749-0961-4593-B4ED-E9A3136D1F95}: NameServer = 194.54.90.226
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InstallTest - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\InstallTest.exe" /test (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Metric Conversion Calculator Installer - Unknown owner - C:\Program Files\Digital Design Ltd\Metric Conversion Calculator\MCCINST.EXE" /update (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hi

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

Folder::
C:\Program Files\Common Files\riio 
C:\Program Files\RcvSystem

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.Re-enable the anti-virus before reconnecting to the Internet.


In your next reply post:
Kaspersky Report
ComboFix.txt
New HJT log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI