This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE popups

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm using Firefox and I'm getting tons of pop-ups from IE at xxxxxxxxx every 5 seconds or so. Please help!! Thanks so much in advance.

I ran Hijackthis and here's the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:34 PM, on 1/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utexas.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {62780D18-D103-03D3-323A-01F43008B839} - C:\Program Files\Whijqzmv\fdjztxca.dll (file missing)
O2 - BHO: (no name) - {97A0FC12-608D-1C29-DA26-48E677865999} - C:\WINDOWS\system32\zwgmt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: {a0a94711-999d-430a-9124-eb67a012bb9f} - {f9bb210a-76be-4219-a034-d99911749a0a} - C:\WINDOWS\system32\kkhejctc.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [{BF-F7-75-54-ZN}] C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKLM\..\Run: [io43mvuiw4kj] C:\WINDOWS\io43mvuiw4kj.exe
O4 - HKLM\..\Run: [vwtgfeje] rundll32.exe "C:\Program Files\lixoluls\jqzonojw.dll",Init
O4 - HKLM\..\Run: [rovoleri] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\rovoleri.dll"
O4 - HKLM\..\Run: [bohudqbm] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\bohudqbm.dll"
O4 - HKLM\..\Run: [enenknkp] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\enenknkp.dll"
O4 - HKLM\..\Run: [abepglcj] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\abepglcj.dll"
O4 - HKLM\..\Run: [olidopcv] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\olidopcv.dll"
O4 - HKLM\..\Run: [142bf7fb] rundll32.exe "C:\WINDOWS\system32\puxxoxel.dll",b
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Teid] "C:\Documents and Settings\Agnes Ho\My Documents\F?nts\m?iexec.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: TA_Start.lnk = C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: TA_Start.lnk = C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &KewlBar Search - res://C:\Program Files\KewlBar 5.0\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.hebphoto.com/common/UserUpload/ImageUploader3.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: winrge32 - winrge32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 8114 bytes


Edit: link removed for security reasons
Hello alex188 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.



Please print out or copy this page to Notepad. Make sure to download all the required tools to your desktop before starting. If there is anything that you do not understand, ask your question(s) before proceeding with the fixes.

A. Tools to download:
  • Right click HERE and Save As (in IE it's "Save Target As") in order to download DelDomains.inf to your desktop.
  • Download SDFix and save it to your Desktop.
  • Download ComboFix and save it to your desktop.

**Note: In the event you already have SDFix and/or ComboFix, these are new versions that I need you to download. It is important that they are saved directly to your desktop**


B. Running the Tools


1. Run DelDomains:

Right click DelDomains.inf and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.


Very Important!

Before running SDFix and ComboFix
:
  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with both SDFix and ComboFix and remove some of their embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Also, make sure you are physically disconnected from the Internet (unplug the cable) after downloading the programs but before running the files.


2. Run SDFix:

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Now reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually
  • Instead of Windows loading as normal, the Advanced Options Menu should appear
  • Select the first option, to run Windows in Safe Mode, then press Enter
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
  • Finally, copy the content of Report.txt to Notepad and Save it to your Desktop as you will be asked to post it later on.


3. Run ComboFix:

WARNING:
  • IF you have not already done so ComboFix will disconnect your machine from the Internet when it starts.
  • Do not re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection when Combofix has completely finished, just restart your computer to restore the connection.

Double-click on combofix.exe and follow the prompts. When finished, it will produce a report for you.


**Note: Do not mouseclick comboFix's window while it's running. That may cause it to stall**


C. After ComboFix has finished its run:
  • Restart/re-enable all the programs that you disabled before running the tools.
  • Physically reconnect to the internet.

D. Posting Logs/Reports:
  • Report.txt
  • C:\ComboFix.txt
  • A new HijackThis log run after all the tools have been run.
SDFix: Version 1.135

Run by [removed] on Fri 02/01/2008 at 03:48 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\PROGRA~1\COMPLU~1\WUOPRY~1.HTM - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\Temp\abW9\tPho.log - Deleted
C:\WINDOWS\PerfInfo\clA6coorCouc.exe - Deleted
C:\WINDOWS\PerfInfo\clA6coorCoud.exe - Deleted
C:\Documents and Settings\Agnes Ho\Start Menu\Programs\Startup\TA_Start.lnk - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\pac.txt - Deleted



Folder C:\Program Files\Temporary - Removed
Folder C:\Temp\abW9 - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed
Folder C:\WINDOWS\PerfInfo - Removed
Folder C:\WINDOWS\system32\g2 - Removed
Folder C:\WINDOWS\system32\rMa02yy - Removed


Removing Temp Files…

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 15:54:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\WINDOWS\\system32"="C:\\WINDOWS\\system32:*:Enabled:lockx"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe"="C:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Disabled:pando"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Disabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\qxalwsux.exe"="C:\\WINDOWS\\system32\\qxa"
"C:\\WINDOWS\\system32\\fagcmdsd.exe"="C:\\WINDOWS\\system32\\fag"
"C:\\WINDOWS\\system32\\maouegvq.exe"="C:\\WINDOWS\\system32\\mao"
"C:\\WINDOWS\\system32\\pkjwtiij.exe"="C:\\WINDOWS\\system32\\pkj"
"C:\\WINDOWS\\system32\\umhybicy.exe"="C:\\WINDOWS\\system32\\umh"
"C:\\WINDOWS\\system32\\xnqsrxjc.exe"="C:\\WINDOWS\\system32\\xnq"
"C:\\WINDOWS\\system32\\upqbtexw.exe"="C:\\WINDOWS\\system32\\upq"
"C:\\WINDOWS\\system32\\ayqhfmbw.exe"="C:\\WINDOWS\\system32\\ayq"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 4 Aug 2004 60,416 A.SH. — "C:\i386\msimn.exe"
Fri 7 Dec 2007 31 A..H. — "C:\WINDOWS\uccspecc.sys"
Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Tue 15 Jan 2008 848 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 22 Nov 2007 20,810 ..SH. — "C:\WINDOWS\system32\yzogrebw.dllbox"
Sat 7 Jan 2006 13 A..H. — "C:\Documents and Settings\All Users\Application Data\13.sys"
Fri 6 Oct 2006 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 24 Nov 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 8 Dec 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sat 29 Sep 2007 19,968 A..H. — "C:\Documents and Settings\Guest\Desktop\sarah\~WRL0005.tmp"
Sat 29 Sep 2007 29,696 A..H. — "C:\Documents and Settings\Guest\Desktop\sarah\~WRL3015.tmp"
Wed 23 Jan 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT3.tmp"
Sun 16 Apr 2006 27,136 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Templates\~WRL0052.tmp"
Sat 25 Nov 2006 20,480 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0003.tmp"
Thu 30 Nov 2006 21,504 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0004.tmp"
Sat 25 Nov 2006 19,968 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 26 Apr 2006 26,624 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0050.tmp"
Wed 26 Apr 2006 26,624 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0266.tmp"
Tue 20 Feb 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0696.tmp"
Tue 20 Feb 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL0892.tmp"
Wed 16 Nov 2005 45,056 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1151.tmp"
Wed 1 Nov 2006 55,296 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1232.tmp"
Wed 16 Nov 2005 45,568 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1269.tmp"
Fri 21 Sep 2007 95,744 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1554.tmp"
Fri 21 Sep 2007 98,304 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1563.tmp"
Tue 30 Jan 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL1729.tmp"
Thu 30 Nov 2006 23,040 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL2092.tmp"
Tue 10 Apr 2007 20,480 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL2277.tmp"
Wed 11 Apr 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL2437.tmp"
Sat 21 Apr 2007 39,424 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL2880.tmp"
Tue 10 Apr 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL3138.tmp"
Wed 11 Apr 2007 20,992 …H. — "C:\Documents and Settings\Agnes Ho\Application Data\Microsoft\Word\~WRL3919.tmp"
Sat 12 Nov 2005 69,120 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0003.tmp"
Wed 16 Nov 2005 62,976 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0012.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0198.tmp"
Wed 16 Nov 2005 61,440 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0342.tmp"
Wed 16 Nov 2005 66,048 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0353.tmp"
Wed 16 Nov 2005 63,488 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0490.tmp"
Wed 16 Nov 2005 65,536 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0521.tmp"
Wed 16 Nov 2005 63,488 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL0926.tmp"
Wed 16 Nov 2005 60,416 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1183.tmp"
Wed 16 Nov 2005 60,416 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1254.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1306.tmp"
Wed 16 Nov 2005 61,952 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1383.tmp"
Wed 16 Nov 2005 64,512 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1459.tmp"
Wed 16 Nov 2005 63,488 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL1712.tmp"
Wed 16 Nov 2005 54,272 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL2480.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL2639.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL2848.tmp"
Wed 16 Nov 2005 65,536 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL3051.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL3171.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL3189.tmp"
Wed 16 Nov 2005 65,024 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL3330.tmp"
Wed 16 Nov 2005 64,000 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall05\ntr311\~WRL3335.tmp"
Sun 7 Oct 2007 24,576 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL0003.tmp"
Mon 8 Oct 2007 30,720 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL0106.tmp"
Mon 8 Oct 2007 31,744 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL0811.tmp"
Mon 8 Oct 2007 25,600 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL1771.tmp"
Mon 8 Oct 2007 28,672 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL3158.tmp"
Mon 8 Oct 2007 28,160 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N355P\~WRL3441.tmp"
Thu 8 Nov 2007 99,840 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N356P\~WRL0002.tmp"
Sat 24 Nov 2007 31,232 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N356P\~WRL1746.tmp"
Fri 21 Sep 2007 114,176 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\fall07\N455\~WRL4089.tmp"
Mon 24 Apr 2006 26,112 A..H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring06\n311\~WRL3985.tmp"
Thu 12 Apr 2007 23,040 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0407.tmp"
Thu 12 Apr 2007 22,016 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0428.tmp"
Thu 12 Apr 2007 21,504 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0746.tmp"
Thu 12 Apr 2007 22,016 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0801.tmp"
Thu 12 Apr 2007 20,992 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0861.tmp"
Wed 11 Apr 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0863.tmp"
Thu 12 Apr 2007 22,528 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0972.tmp"
Thu 12 Apr 2007 22,528 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL0990.tmp"
Wed 11 Apr 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL1072.tmp"
Thu 12 Apr 2007 22,016 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL1156.tmp"
Thu 12 Apr 2007 20,992 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL2332.tmp"
Thu 12 Apr 2007 23,040 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL2726.tmp"
Thu 12 Apr 2007 24,064 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL2763.tmp"
Wed 11 Apr 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL2956.tmp"
Wed 11 Apr 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3040.tmp"
Thu 12 Apr 2007 23,040 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3664.tmp"
Thu 12 Apr 2007 21,504 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3732.tmp"
Thu 12 Apr 2007 23,040 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3841.tmp"
Wed 11 Apr 2007 20,480 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3917.tmp"
Thu 12 Apr 2007 20,992 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N227\~WRL3918.tmp"
Sat 21 Apr 2007 39,424 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL0248.tmp"
Sat 21 Apr 2007 38,912 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL0722.tmp"
Sat 21 Apr 2007 39,424 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL1528.tmp"
Sat 21 Apr 2007 40,960 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL2079.tmp"
Sat 21 Apr 2007 38,912 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL2338.tmp"
Sat 21 Apr 2007 38,400 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL2527.tmp"
Fri 20 Apr 2007 38,400 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL3415.tmp"
Sun 22 Apr 2007 40,960 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL3750.tmp"
Sun 22 Apr 2007 41,472 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N325\~WRL3892.tmp"
Tue 10 Apr 2007 20,992 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL0387.tmp"
Tue 10 Apr 2007 19,968 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL1004.tmp"
Tue 10 Apr 2007 20,480 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL1713.tmp"
Tue 10 Apr 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL1756.tmp"
Tue 10 Apr 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL2946.tmp"
Tue 10 Apr 2007 19,456 …H. — "C:\Documents and Settings\Agnes Ho\My Documents\spring07\N354\~WRL4018.tmp"
Sun 8 Apr 2007 8 A..H. — "C:\Documents and Settings\Agnes Ho\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 9 Apr 2007 8 A..H. — "C:\Documents and Settings\Agnes Ho\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\Agnes Ho\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\Agnes Ho\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Tue 10 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Tue 10 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Fri 13 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Fri 13 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!

——————————————————————————————————————————————————————-




ComboFix 08-02.01.6 - Agnes Ho 2008-02-01 16:09:39.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.208 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-02-01 15:46 . 2008-02-01 15:46 d——– C:\WINDOWS\ERUNT
2008-01-26 22:23 . 2008-01-26 22:23 d——– C:\Program Files\Trend Micro
2008-01-11 22:26 . 2008-01-11 22:26 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2008-01-02 09:40 . 2008-01-02 09:40 d——– C:\Documents and Settings\All Users\Application Data\Corel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 22:04 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 16:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-01 04:25 ——— d—–w C:\Documents and Settings\Agnes Ho\Application Data\AdobeUM
2008-01-15 23:27 ——— d—–w C:\Documents and Settings\Agnes Ho\Application Data\Corel
2008-01-15 15:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 11:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 00:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-03 01:22 ——— d—–w C:\Documents and Settings\Agnes Ho\Application Data\Symantec
2007-12-31 05:45 ——— d—–w C:\Program Files\TomaWeb
2007-12-29 05:38 ——— d—–w C:\Program Files\Taiji Software
2007-12-25 20:56 ——— d—–w C:\Program Files\Common Files\Corel
2007-12-25 20:55 ——— d—–w C:\Program Files\Corel
2007-12-25 20:44 ——— d—–w C:\Program Files\Norton 360
2007-12-25 20:29 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-25 20:29 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-25 20:29 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-25 20:29 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-25 20:29 ——— d—–w C:\Program Files\Symantec
2007-12-25 07:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 11:22 ——— d—–w C:\Program Files\QuickTime
2007-12-12 11:22 ——— d—–w C:\Program Files\DellSupport
2007-12-07 11:45 ——— d—–w C:\Program Files\Coupons
2007-12-01 05:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 05:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 05:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 05:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 05:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 05:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 05:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 05:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 05:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-21 20:21 123 —-a-w C:\Documents and Settings\Agnes Ho\mit.bat
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2006-01-08 04:55 13 —ha-w C:\Documents and Settings\All Users\Application Data\13.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 339,968 2005-03-30 02:05:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe

—-a-w 81,920 2004-07-27 21:50:18 C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe

—-a-w 221,184 2004-07-27 21:50:42 C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe

—-a-w 185,784 2007-04-03 15:18:59 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 48,752 2005-10-06 00:06:34 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
—-a-w 116,072 2007-07-18 01:54:00 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

—-a-w 53,248 2005-02-23 21:19:56 C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe

—-a-w 460,784 2007-03-15 16:09:36 C:\Program Files\DellSupport\bak\DSAgnt.exe

—-a-w 68,856 2007-07-11 13:16:42 C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe

—-a-w 221,184 2003-09-04 01:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe

—-a-w 32,881 2003-11-19 22:48:14 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe

—-a-w 131,072 2004-09-14 13:50:48 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe

—-a-w 98,304 2005-08-21 22:21:36 C:\Program Files\QuickTime\bak\qttask.exe

—-a-w 100,056 2005-09-03 02:22:46 C:\Program Files\SymNetDrv\bak\SNDMon.exe

—-a-w 127,035 2004-12-06 06:05:00 C:\WINDOWS\system32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
C:\Program Files\Whijqzmv\fdjztxca.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97A0FC12-608D-1C29-DA26-48E677865999}]
C:\WINDOWS\system32\zwgmt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f9bb210a-76be-4219-a034-d99911749a0a}]
C:\WINDOWS\system32\kkhejctc.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Teid"="C:\Documents and Settings\Agnes Ho\My Documents\F?nts\m?iexec.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 22:20 339968 C:\WINDOWS\STSYSTRA.EXE]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"{BF-F7-75-54-ZN}"="C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe" [ ]
"142bf7fb"="C:\WINDOWS\system32\puxxoxel.dll" [ ]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 19:54 116072]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 14:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrge32]
winrge32.dll

S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 14:12]

*Newly Created Service* - COMHOST
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 16:10:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-01 16:11:11
ComboFix-quarantined-files.txt 2008-02-01 22:11:08
ComboFix2.txt 2008-02-01 22:07:46
.
2008-01-13 07:07:29 — E O F —

————————————————————————————————————————————————————-


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:50 PM, on 2/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utexas.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {62780D18-D103-03D3-323A-01F43008B839} - C:\Program Files\Whijqzmv\fdjztxca.dll (file missing)
O2 - BHO: (no name) - {97A0FC12-608D-1C29-DA26-48E677865999} - C:\WINDOWS\system32\zwgmt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: {a0a94711-999d-430a-9124-eb67a012bb9f} - {f9bb210a-76be-4219-a034-d99911749a0a} - C:\WINDOWS\system32\kkhejctc.dll (file missing)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [{BF-F7-75-54-ZN}] C:\Documents and Settings\Agnes Ho\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKLM\..\Run: [142bf7fb] rundll32.exe "C:\WINDOWS\system32\puxxoxel.dll",b
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Teid] "C:\Documents and Settings\Agnes Ho\My Documents\F?nts\m?iexec.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &KewlBar; Search - res://C:\Program Files\KewlBar 5.0\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.hebphoto.com/common/UserUpload/ImageUploader3.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: winrge32 - winrge32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 6398 bytes
In addition to the infections that have already been removed, your system is infected with a file infector that has replaced several legitimate files with malware. After we have cleaned up your system a bit more, we will attempt to replace the changed files back.


A. We first need to reveal hidden files so that we can submit a file for analysis:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


B. There is a file in your log of which I am unsure. For that reason, I need you to submit it to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Documents and Settings\All Users\Application Data\13.sys

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.



C. Please download FindAWF to your Desktop.
  • Double-click FindAWF.exe to start the tool.
  • Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
**Do not run any other option unless directed to do so.**
ast file scanned at least one scanner reported something about: PINCrax_.50_[BETA].rar (MD5: cc9bcb0165260bc6cf96e255f064872e, size: 154626 bytes), detected by: Scanner Malware name A-Squared X AntiVir TR/PSW.Steal.98304.2 ArcaVir X Avast X AVG Antivirus X BitDefender Generic.PWStealer.2EAF3D54 ClamAV X CPsecure X Dr.Web X F-Prot Antivirus X F-Secure Anti-Virus X Fortinet X Ikarus Generic.PWStealer Kaspersky Anti-Virus X NOD32 X Norman Virus Control X Panda Antivirus X Rising Antivirus X Sophos Antivirus X VirusBuster X VBA32 X ————————————————————————————————————————————— Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Fri 02/01/2008 The current time is: 22:01:13.71 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\DELLSU~1\BAK 03/15/2007 10:09 AM 460,784 DSAgnt.exe 1 File(s) 460,784 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 08/21/2005 04:21 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\PROGRA~1\SYMNET~1\BAK 09/02/2005 08:22 PM 100,056 SNDMon.exe 1 File(s) 100,056 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 03/29/2005 08:05 PM 339,968 atiptaxx.exe 1 File(s) 339,968 bytes Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK 10/05/2005 06:06 PM 48,752 ccApp.exe 1 File(s) 48,752 bytes Directory of C:\PROGRA~1\CYBERL~1\POWERDVD\BAK 02/23/2005 03:19 PM 53,248 DVDLauncher.exe 1 File(s) 53,248 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\BAK 07/11/2007 07:16 AM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 07:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\MUSICM~1\MUSICM~3\BAK 09/14/2004 07:50 AM 131,072 mm_tray.exe 1 File(s) 131,072 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 12/06/2004 12:05 AM 127,035 tfswctrl.exe 1 File(s) 127,035 bytes Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK 07/27/2004 03:50 PM 81,920 issch.exe 07/27/2004 03:50 PM 221,184 ISUSPM.exe 2 File(s) 303,104 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/03/2007 09:18 AM 185,784 realsched.exe 1 File(s) 185,784 bytes Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK 11/19/2003 04:48 PM 32,881 jusched.exe 1 File(s) 32,881 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 460784 Mar 15 2007 "C:\Program Files\DellSupport\bak\DSAgnt.exe" 98304 Aug 21 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 100056 Sep 2 2005 "C:\Program Files\SymNetDrv\bak\SNDMon.exe" 339968 Mar 29 2005 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 116072 Jul 17 2007 "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" 48752 Oct 5 2005 "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe" 53248 Feb 23 2005 "C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe" 52272 Feb 24 2007 "C:\Program Files\Google\googletoolbar4user.exe" 583696 Apr 3 2007 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe" 138168 Feb 24 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 11 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 135168 Mar 15 2006 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mm_tray.exe" 131072 Sep 14 2004 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe" 127035 Dec 6 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 127035 Dec 6 2004 "C:\WINDOWS\system32\dla\bak\tfswctrl.exe" 81920 Jul 27 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe" 221184 Jul 27 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe" 185784 Apr 3 2007 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe" end of report
Hi Alex,

I think that you were able to read just like me that this baby is a "password" stealer. That means that we will have to clean this up immediately before even contemplating any file replacement. We must assume that this trojan has already stolen some of your password so I STRONGLY suggest that, using a different machine, that you go and change all the passwords to sites that you do not want the bad guys to know about or use. That would include banking passwords and all other such info.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\Documents and Settings\All Users\Application Data\13.sys

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97A0FC12-608D-1C29-DA26-48E677865999}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f9bb210a-76be-4219-a034-d99911749a0a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Teid"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{BF-F7-75-54-ZN}"=-
"142bf7fb"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrge32]

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply after you re-enable all the programs that were disabled during the running of ComboFix:
  • Combofix.txt
  • A new HijackThis log.
Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Once you have finished changing your passwords and running the above script, post your results and we will continue with the file replacement.

Good Luck,

Trevuren
After dragging the script to ComboFix, an error box pops up that says: "You can not rename ComboFix as ComboFix. Please use another name."
Have brought that error to the attention of the developer. We will have to wait and see. I have not run into that error before with this tool. Perhaps the file infector?
Hello Alex, it's unfortunate that ComboFix is behaving erratically on your machine. So, I made you a special copy of ComboFix which may be downloaded from here ==> http://subs.geekstogo.com/Beta/ComboFix.exe

Running this copy won't solve your issues but it should produce a log of events that'll help me troubleshoot it. Please double click ComboFix.exe to run it. If you get the error message "You cannot rename ComboFix as ComboFix", it should also pop up a log of errors. Kindly post this log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI