This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] IE Pop Ups

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have been receiving pop-ups from my internet explorer, from websites such as, Setthetrend, and other websites. I know I have seen multiple other posts with the same issues, and I have gone through every step I could, and have been used HiJackThis, ComboFix, and SDFix to try and see if there is anything out of the ordinary, yet I haven't been able to find the source of where these pop-ups are coming from. I'm hoping that there is something that I am not seeing, or something that will be able to help me be rid of this.
I have AVG's Free Anti-Spyware, and Anti-virus program installed, I have also ran Kaspersky, and also have Zonealarm Firewall running as well

Here is the Hijackthis report.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:43:53 PM, on 2/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\CACHEM~1\CachemanXP.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gryffins\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CachemanXP (CachemanXPService) - Outertech - C:\PROGRA~1\CACHEM~1\CachemanXP.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 6019 bytes


Here is the SDFix report.


SDFix: Version 1.135

Run by [removed] on Fri 02/01/2008 at 03:12 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found






Removing Temp Files…

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 15:23:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d346prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,8e,86,a1,52,ba,06,11,d5,0a,06,38,a3,ba,33,18,3d,ce,..
"hj34z0"=hex:26,cb,e2,33,b5,5a,2e,d7,95,6f,0f,49,5a,1c,81,a6,3a,67,7e,15,6b,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d346prt\Cfg\0Jf41]
"khjeh"=hex:20,02,00,00,8e,86,a1,52,38,b2,51,8d,0a,06,38,a3,4e,30,18,3d,ce,..
"hj34z0"=hex:d2,c8,e2,33,b5,5a,2e,d7,95,6f,0f,49,5a,1c,81,a6,3a,67,7e,15,23,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Lsa]
"LsaPid"=dword:00000330
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager]
"PendingFileRenameOperations"=str(7):"\??\C:\WINDOWS\system32\drivers\core.cache.dsk\0!\??\C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\core.cache.dsk.vir\0\??\C:\WINDOWS\system32\drivers\core.cache.dsk\0!\??\C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\core.cache.dsk.vir\0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters]
"VideoInitTime"=dword:00000399
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Watchdog\Display]
"ShutdownCount"=dword:00000008
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WEBNTACCESS\0000]
"Service"="WEBNTACCESS"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="WEBNTACCESS"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Epoch]
"Epoch"=dword:00002cd5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{CEF4957C-3142-4C93-B3E7-DA73AAFF5267}]
"LeaseObtainedTime"=dword:47a3a29b
"T1"=dword:c7a3a29a
"T2"=dword:67a3a29a
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{CEF4957C-3142-4C93-B3E7-DA73AAFF5267}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:47a3a29b
"T1"=dword:c7a3a29a
"T2"=dword:67a3a29a

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{56CA5D3B-3002-4E7B-90FE-071D8FDF3814}]
"DisplayName"="DAEMON Tools"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————


Files with Hidden Attributes:


Finished!


And here is the Combofix report.

ComboFix 08-02.01.6 - Gryffins 2008-02-01 14:49:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1035 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\My Documents\My Completed Downloads\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-02-01 14:45 . 2008-02-01 14:45 167,545 –a—— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-02-01 14:18 . 2008-02-01 14:18 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-01 14:00 . 2008-02-01 14:01 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2008-02-01 13:52 . 2008-02-01 13:52 d——– C:\Deckard
2008-02-01 13:43 . 2008-02-01 13:46 d——– C:\Documents and Settings\Gryffins\.housecall6.6
2008-02-01 13:43 . 2008-02-01 13:43 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-01 13:37 . 2008-02-01 13:37 d——– C:\Program Files\Trend Micro
2008-02-01 13:34 . 2008-02-01 13:35 d——– C:\Program Files\Panda Security
2008-02-01 13:01 . 2008-02-01 13:01 d——– C:\Program Files\Kaspersky Lab
2008-02-01 13:01 . 2008-02-01 13:01 d——– C:\KAV
2008-02-01 12:29 . 2008-02-01 12:29 d——– C:\Documents and Settings\LocalService\Application Data\Xfire
2008-02-01 12:06 . 2008-02-01 12:24 d——– C:\Program Files\GatheringRO
2008-02-01 11:28 . 2008-02-01 11:28 d——– C:\Documents and Settings\Gryffins\Application Data\Grisoft
2008-02-01 11:28 . 2007-05-30 04:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-01 11:26 . 2008-02-01 11:26 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-01 11:26 . 2008-02-01 14:53 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-01 11:24 . 2008-02-01 11:24 d——– C:\WINDOWS\RebirthRO Full
2008-02-01 11:24 . 2008-02-01 12:03 d——– C:\Program Files\RebirthRO
2008-02-01 11:22 . 2008-02-01 11:22 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-01 06:09 . 2008-02-01 06:09 d–hs—- C:\Diskeeper
2008-02-01 04:19 . 2008-02-01 04:23 139,264 –a—— C:\WINDOWS\War3Unin.exe
2008-02-01 04:19 . 2008-02-01 04:23 55,138 –a—— C:\WINDOWS\War3Unin.dat
2008-02-01 04:19 . 2008-02-01 04:23 2,829 –a—— C:\WINDOWS\War3Unin.pif
2008-02-01 04:18 . 2008-02-01 04:24 d——– C:\Program Files\Warcraft III
2008-02-01 04:16 . 2008-02-01 04:16 d——– C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-02-01 03:45 . 2008-02-01 03:47 d——– C:\Program Files\Xfire
2008-02-01 03:45 . 2008-02-01 13:48 d——– C:\Documents and Settings\Gryffins\Application Data\Xfire
2008-02-01 03:36 . 2008-02-01 03:36 d——– C:\Program Files\Webroot
2008-02-01 03:36 . 2008-02-01 03:36 d——– C:\Program Files\Common Files\Webroot Shared
2008-02-01 03:36 . 2008-02-01 03:36 d——– C:\Documents and Settings\Gryffins\Application Data\Webroot
2008-02-01 03:36 . 2008-02-01 03:36 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2008-02-01 03:36 . 2007-08-09 13:56 69,960 –a—— C:\WINDOWS\Unwash6.exe
2008-02-01 03:27 . 2008-02-01 11:28 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-01 03:23 . 2008-02-01 03:56 d——– C:\WINDOWS\system32\drivers\upload
2008-02-01 03:11 . 2008-02-01 03:11 d——– C:\WINDOWS\Sun
2008-02-01 03:09 . 2008-02-01 03:09 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-01 03:09 . 2008-02-01 09:52 d——– C:\Documents and Settings\Gryffins\Application Data\AVG7
2008-02-01 03:09 . 2008-02-01 03:28 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-01 03:09 . 2008-02-01 03:09 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-02-01 03:09 . 2008-02-01 03:09 86,144 –a—— C:\WINDOWS\system32\drivers\processrr.sys
2008-02-01 02:49 . 2008-02-01 02:49 d——– C:\Documents and Settings\Gryffins\Application Data\vlc
2008-02-01 02:46 . 2008-02-01 02:46 d——– C:\Program Files\D-Tools
2008-02-01 02:46 . 2004-03-12 22:41 156,800 –a—— C:\WINDOWS\system32\drivers\d346bus.sys
2008-02-01 02:46 . 2004-03-12 22:41 5,248 –a—— C:\WINDOWS\system32\drivers\d346prt.sys
2008-02-01 02:32 . 2008-02-01 02:32 d——– C:\Program Files\Lavasoft
2008-02-01 02:32 . 2008-02-01 02:32 d——– C:\Documents and Settings\Gryffins\Application Data\Lavasoft
2008-02-01 02:27 . 2008-02-01 02:27 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-02-01 02:27 . 2008-02-01 02:27 d——– C:\Program Files\iTunes
2008-02-01 02:27 . 2008-02-01 02:27 d——– C:\Program Files\iPod
2008-02-01 02:27 . 2008-02-01 02:27 d——– C:\Program Files\Bonjour
2008-02-01 02:27 . 2008-02-01 02:27 d——– C:\Documents and Settings\Gryffins\Application Data\Apple Computer
2008-02-01 02:27 . 2008-02-01 14:52 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-01 02:27 . 2008-01-15 02:39 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2008-02-01 02:27 . 2008-02-01 02:28 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-01 02:26 . 2008-02-01 02:26 d——– C:\Program Files\Common Files\Apple
2008-02-01 02:08 . 2008-02-01 02:09 d——– C:\Program Files\Winamp
2008-02-01 02:08 . 2008-02-01 12:09 d——– C:\Documents and Settings\Gryffins\Application Data\Winamp
2008-02-01 01:56 . 2008-02-01 04:26 d——– C:\Documents and Settings\Gryffins\Application Data\Azureus
2008-02-01 01:56 . 2008-02-01 01:56 d——– C:\Documents and Settings\All Users\Application Data\Azureus
2008-02-01 01:55 . 2008-02-01 01:56 d——– C:\Program Files\Azureus
2008-02-01 01:53 . 2008-02-01 01:53 d——– C:\Program Files\Java
2008-02-01 01:53 . 2008-02-01 01:53 d——– C:\Program Files\Common Files\Java
2008-02-01 01:53 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-02-01 01:48 . 2008-02-01 01:48 d——– C:\Program Files\ACE Mega CoDecS Pack
2008-02-01 01:36 . 2008-02-01 01:37 d——– C:\Documents and Settings\Gryffins\Application Data\SecondLife
2008-02-01 01:35 . 2008-02-01 01:35 d——– C:\WINDOWS\system32\Lang
2008-02-01 01:35 . 2008-02-01 01:35 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-02-01 01:35 . 2008-02-01 01:35 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-02-01 01:34 . 2008-02-01 14:50 5,040,160 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-01 01:34 . 2008-02-01 14:50 61,364 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-01 01:33 . 2008-02-01 01:33 d——– C:\Program Files\VideoLAN
2008-02-01 01:30 . 2008-02-01 01:30 d——– C:\Program Files\IMVU
2008-02-01 01:30 . 2008-02-01 01:30 d——– C:\Documents and Settings\Gryffins\Application Data\IMVU
2008-02-01 01:27 . 2008-02-01 01:28 d——– C:\Program Files\SecondLifeWindLight
2008-02-01 01:24 . 2008-02-01 01:25 d——– C:\Program Files\RegistryFix
2008-02-01 01:21 . 2008-02-01 01:21 d——– C:\Program Files\Diskeeper Corporation
2008-02-01 01:21 . 2008-02-01 01:21 d——– C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2008-02-01 01:08 . 2008-02-01 01:08 d——– C:\Program Files\ZoneAlarmSB
2008-02-01 01:08 . 2008-02-01 01:08 d——– C:\Program Files\VIA
2008-02-01 01:08 . 2005-04-14 07:54 331,184 ——— C:\WINDOWS\system32\difxapi.dll
2008-02-01 01:08 . 2006-10-18 17:39 17,920 -ra—— C:\WINDOWS\system32\drivers\xfilt.sys
2008-02-01 01:08 . 2006-10-17 20:22 9,216 -ra—— C:\WINDOWS\system32\drivers\videX32.sys
2008-02-01 01:07 . 2008-02-01 01:07 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-01 01:06 . 2008-02-01 01:06 d——– C:\WINDOWS\system32\RTCOM
2008-02-01 01:06 . 2008-02-01 01:39 d——– C:\Program Files\DAP
2008-02-01 01:06 . 2008-02-01 14:52 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-01 01:05 . 2008-02-01 01:05 d——– C:\Program Files\Realtek
2008-02-01 01:05 . 2008-02-01 01:10 d–h—– C:\Program Files\InstallShield Installation Information
2008-02-01 01:03 . 2008-02-01 13:49 d——– C:\Program Files\Trillian
2008-02-01 01:02 . 2008-02-01 01:02 25,992 –a—— C:\WINDOWS\system32\pgdfgsvc.exe
2008-01-16 14:38 . 2008-01-16 14:38 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-01-10 15:27 . 2008-01-10 15:27 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 20:27 1,424,384 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-02-01 10:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-01 09:06 50,688 —-a-w C:\WINDOWS\system32\wbhelp2.dll
2008-02-01 09:05 315,392 —-a-w C:\WINDOWS\HideWin.exe
2008-02-01 09:00 502,272 —-a-w C:\WINDOWS\system32\winlogon.exe
2008-02-01 08:59 ——— d—–w C:\Program Files\QuickTime
2008-02-01 08:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-02-01 08:58 ——— d—–w C:\Program Files\Apple Software Update
2008-02-01 08:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-02-01 08:57 ——— d—–w C:\Program Files\MSI
2008-02-01 08:57 ——— d—–w C:\Program Files\CachemanXP
2008-02-01 08:51 ——— d–h–w C:\Program Files\Uninstall Information
2008-02-01 08:48 ——— d—–w C:\Program Files\microsoft frontpage
2007-12-14 17:21 9,216 —-a-w C:\WINDOWS\system32\drivers\FlashSys.sys
2007-12-06 01:30 4,632,576 —-a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-12-05 10:53 356,352 —-a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-05 09:41 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 09:41 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 09:41 8,523,776 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 09:41 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 09:41 7,435,392 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 09:41 6,901,760 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 09:41 6,549,504 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 09:41 5,773,568 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 09:41 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 09:41 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 09:41 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 09:41 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 09:41 385,024 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 09:41 356,352 —-a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 09:41 35,328 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 09:41 35,328 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 09:41 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 09:41 3,710,976 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 09:41 3,420,160 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 09:41 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 09:41 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 09:41 2,498,560 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 09:41 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 09:41 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 09:41 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 09:41 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 09:41 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-12-05 09:41 1,474,560 —-a-w C:\WINDOWS\system32\nview.dll
2007-12-05 09:41 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 09:41 1,228,800 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 09:41 1,089,536 —-a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 09:41 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-12-01 02:42 16,858,624 —-a-w C:\WINDOWS\RTHDCPL.exe
2007-11-21 02:15 1,826,816 —-a-w C:\WINDOWS\SkyTel.exe
2007-11-15 00:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-15 00:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-08 01:31 1,191,936 —-a-w C:\WINDOWS\RtlUpd.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-01 01:08 262144 –a—— C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-01 01:08 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"LiveMonitor"="C:\Program Files\MSI\Live Update 3\LMonitor.exe" [2007-01-17 17:01 496640]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2008-02-01 01:06 4568576]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-30 18:42 16858624 C:\WINDOWS\RTHDCPL.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 14:54 37376]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe" [2007-11-19 14:40 231952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-01 03:27 219136]

C:\Documents and Settings\Gryffins\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-01-16 14:37:56 2872144]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"NoDesktopCleanupWizard"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svchostIO"=2 (0x2)
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)

R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 20:22]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-10-18 17:39]
R1 processrr;processrr;C:\WINDOWS\system32\drivers\processrr.sys [2008-02-01 03:09]
R2 CachemanXPService;CachemanXP;C:\PROGRA~1\CACHEM~1\CachemanXP.exe [2007-06-02 11:11]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-08-09 13:56]
S4 svchostIO;svchostIO;C:\WINDOWS\system32\drivers\upload\ComServ.exe /name:"svchostIO" /start:"svchost.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 08:58:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 14:53:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\CACHEM~1\CachemanXP.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
.
**************************************************************************
.
Completion time: 2008-02-01 14:54:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 22:54:25
ComboFix2.txt 2008-02-01 20:45:36
ComboFix3.txt 2008-02-01 20:31:05

Any help would be greatly appreciated.

Thank you so much
Hello,

Welcome to the forum, while running some of the programs you ran is somewhat commendable, if you dont know what your doing you can bork your system so its best to wait for assistance from a helper in the forum.

C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete <–This is your problem

Drag Combofx to the trash, its out dated and the latest version should get that file.


Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI