This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help Me remove this trojan horse

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hoping this is what you need to help me get rid of this thing…

Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:48 AM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: (no name) - {724d43a0-0d85-11d4-9908-00400523e39a} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 6395 bytes


COMBOFIX

ComboFix 08-02.02.5 - Shellee 2008-02-02 7:18:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.201 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Shellee\Application Data\DriveCleaner Free
C:\Documents and Settings\Shellee\Application Data\DriveCleaner Free\Logs\update.log
C:\Temp\fse
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\acnyfoya.dll
C:\WINDOWS\system32\amjatdkf.dll
C:\WINDOWS\system32\ati2dva.dll
C:\WINDOWS\system32\awgbgrqh.dll
C:\WINDOWS\system32\befonpjs.dll
C:\WINDOWS\system32\bflrdbbp.dll
C:\WINDOWS\system32\biefepjl.dll
C:\WINDOWS\system32\bkmtorny.dll
C:\WINDOWS\system32\blcctchy.dll
C:\WINDOWS\system32\bmrleqfw.dll
C:\WINDOWS\system32\bphewptb.dll
C:\WINDOWS\SYSTEM32\btpwehpb.ini
C:\WINDOWS\system32\bygxsuiw.dll
C:\WINDOWS\SYSTEM32\ccqctgfl.ini
C:\WINDOWS\system32\cinajfhm.dll
C:\WINDOWS\system32\cywqaohu.dll
C:\WINDOWS\system32\drivers\xdiseufd.dat
C:\WINDOWS\system32\eclbstol.dll
C:\WINDOWS\system32\eeoghnvv.dll
C:\WINDOWS\system32\ellnanfm.dll
C:\WINDOWS\system32\eoyufqcg.dll
C:\WINDOWS\system32\eromfixk.dll
C:\WINDOWS\system32\erriaasm.dll
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\SYSTEM32\facrenbn.ini
C:\WINDOWS\system32\fafdgbni.dll
C:\WINDOWS\system32\fhihjccm.dll
C:\WINDOWS\system32\fmgxrakh.dll
C:\WINDOWS\SYSTEM32\gcqfuyoe.ini
C:\WINDOWS\system32\gkdnoeqb.dll
C:\WINDOWS\SYSTEM32\gtpoyees.ini
C:\WINDOWS\SYSTEM32\hkarxgmf.ini
C:\WINDOWS\system32\hoxlonio.dll
C:\WINDOWS\SYSTEM32\hqrgbgwa.ini
C:\WINDOWS\system32\icuxteep.dll
C:\WINDOWS\system32\ieopdhsr.dll
C:\WINDOWS\system32\ijcrwvvn.dll
C:\WINDOWS\SYSTEM32\inbgdfaf.ini
C:\WINDOWS\system32\isrbhjjl.dll
C:\WINDOWS\system32\jautkquq.dll
C:\WINDOWS\system32\kmfkmxmu.dll
C:\WINDOWS\system32\kpxatdvn.dll
C:\WINDOWS\SYSTEM32\kxifmore.ini
C:\WINDOWS\system32\lfgtcqcc.dll
C:\WINDOWS\system32\lwletcyy.dll
C:\WINDOWS\system32\lwqhcggv.dll
C:\WINDOWS\system32\mcsxbfsy.dll
C:\WINDOWS\system32\mpxhhord.dll
C:\WINDOWS\SYSTEM32\msaairre.ini
C:\WINDOWS\system32\nbnercaf.dll
C:\WINDOWS\system32\ncaowkpn.dll
C:\WINDOWS\system32\ogntfagt.dll
C:\WINDOWS\SYSTEM32\peetxuci.ini
C:\WINDOWS\system32\pifxddht.dll
C:\WINDOWS\SYSTEM32\pqstv.ini
C:\WINDOWS\SYSTEM32\pqstv.ini2
C:\WINDOWS\system32\pvwkjuqx.dll
C:\WINDOWS\system32\pxjmhpqw.dll
C:\WINDOWS\system32\qvsflmhn.dll
C:\WINDOWS\system32\rawylpnc.dll
C:\WINDOWS\system32\rdobxdvq.dll
C:\WINDOWS\system32\rkwuoejs.dll
C:\WINDOWS\system32\rvfcjhut.dll
C:\WINDOWS\system32\rvqrhxlh.dll
C:\WINDOWS\system32\seeyoptg.dll
C:\WINDOWS\system32\sitqypbt.dll
C:\WINDOWS\system32\tkmjbrbm.dll
C:\WINDOWS\SYSTEM32\tuhjcfvr.ini
C:\WINDOWS\system32\twtbqwox.dll
C:\WINDOWS\system32\ucnefmac.dll
C:\WINDOWS\SYSTEM32\ueboanky.ini
C:\WINDOWS\SYSTEM32\uhoaqwyc.ini
C:\WINDOWS\system32\uljgovdo.dll
C:\WINDOWS\system32\urchndih.dll
C:\WINDOWS\system32\utmcqvid.dll
C:\WINDOWS\system32\vsgmiuul.dll
C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\SYSTEM32\wefsucxw.ini
C:\WINDOWS\SYSTEM32\wfqelrmb.ini
C:\WINDOWS\system32\wgrjjtgc.dll
C:\WINDOWS\system32\whlnuhct.dll
C:\WINDOWS\SYSTEM32\wqphmjxp.ini
C:\WINDOWS\system32\wxcusfew.dll
C:\WINDOWS\system32\wxlteqlr.dll
C:\WINDOWS\system32\xhwqulhw.dll
C:\WINDOWS\SYSTEM32\xowqbtwt.ini
C:\WINDOWS\system32\xprbkecc.dll
C:\WINDOWS\system32\yknaobeu.dll
C:\WINDOWS\system32\yqgehaod.dll
C:\WINDOWS\system32\yshmlcib.dll
F:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_AECVPYFY
——-\LEGACY_DOMAINSERVICE
——-\aecvpyfy


((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.

2008-02-02 06:30 . 2008-02-02 07:08 d——– C:\Program Files\Enigma Software Group
2008-02-02 05:17 . 2007-10-10 15:55 6,065,664 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-02 05:17 . 2007-06-30 19:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-02 05:17 . 2007-06-30 19:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-02 05:17 . 2007-10-10 15:55 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-02 05:17 . 2007-10-10 15:55 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-02 05:17 . 2007-10-10 15:55 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-02 05:17 . 2007-10-10 15:55 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-02 05:17 . 2007-10-10 15:55 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-02 05:17 . 2007-10-10 02:59 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-02 04:41 . 2008-02-02 04:41 d——– C:\Program Files\CCleaner
2008-02-02 03:14 . 2008-02-02 03:19 d——– C:\Documents and Settings\Shellee\Application Data\AVG7
2008-02-02 03:14 . 2008-02-02 03:14 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-02 03:14 . 2008-02-02 05:41 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-01 23:55 . 2008-02-01 23:55 d——– C:\Documents and Settings\Shellee\Application Data\VSRevoGroup
2008-02-01 23:53 . 2008-02-01 23:53 d——– C:\Program Files\VS Revo Group
2008-02-01 23:31 . 2008-02-02 05:25 334,848 –a—— C:\WINDOWS\SYSTEM32\vtsqp.exe
2008-01-28 17:56 . 2008-01-28 17:58 d——– C:\Program Files\mobile PhoneTools
2008-01-28 17:38 . 2008-01-28 17:39 d——– C:\Program Files\Motorola Phone Tools
2008-01-28 17:36 . 2008-01-28 17:36 24,192 –a—— C:\Documents and Settings\Shellee\usbsermptxp.sys
2008-01-28 17:36 . 2008-01-28 17:36 22,768 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbsermpt.sys
2008-01-28 17:36 . 2008-01-28 17:36 22,768 –a—— C:\Documents and Settings\Shellee\usbsermpt.sys
2008-01-20 00:26 . 2008-02-01 23:26 13,505 –a—— C:\logfile
2008-01-20 00:19 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\SYSTEM32\ptpusb.dll
2008-01-20 00:18 . 2008-01-20 00:18 d——– C:\Program Files\Common Files\Kodak
2008-01-20 00:18 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\SYSTEM32\ptpusd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 11:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-02 11:02 ——— d—–w C:\Program Files\Apoint
2008-02-02 11:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-02 08:12 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-02 07:31 ——— d—–w C:\Program Files\QuickTime
2008-02-02 07:30 ——— d—–w C:\Program Files\DellSupport
2008-01-29 01:56 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-29 01:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-01-29 01:24 ——— d—–w C:\Program Files\LiveUpdate
2008-01-20 08:23 ——— d—–w C:\Program Files\Kodak
2008-01-20 07:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-19 18:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2007-10-15 18:35 5,910 —-a-w C:\Documents and Settings\Shellee\Application Data\wklnhst.dat
2007-05-09 16:57 99,640 —-a-w C:\Documents and Settings\Shellee\Application Data\GDIPFONTCACHEV1.DAT
2007-04-14 22:05 280,644 ——w C:\WINDOWS\INF\pm3sp.dll
2006-12-15 00:43 4,148 —-a-w C:\Documents and Settings\Shellee\Application Data\ViewerApp.dat
.
—-a-w		   135,168 2008-02-02 11:02:07  C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent .exe
—-a-w		   155,648 2008-02-02 11:01:46  C:\Program Files\Apoint\Apoint .exe
—-a-w		   344,064 2008-02-02 13:30:50  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   228,088 2008-02-02 11:02:03  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   290,816 2008-02-02 11:01:53  C:\Program Files\Dell\Media Experience\PCMService .exe
—-a-w		   579,072 2008-02-02 13:30:56  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   385,024 2008-02-02 11:01:49  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		 4,670,968 2008-02-02 11:02:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w		   127,035 2008-02-02 11:01:55  C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-02-02 05:25 749568]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-02 05:43 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-02 03:14 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-03-19 12:57:09 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 14:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Shellee^Start Menu^Programs^Startup^Cyber-shot Viewer Media Check Tool.lnk]
path=C:\Documents and Settings\Shellee\Start Menu\Programs\Startup\Cyber-shot Viewer Media Check Tool.lnk
backup=C:\WINDOWS\pss\Cyber-shot Viewer Media Check Tool.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Shellee^Start Menu^Programs^Startup^wkcalrem.LNK]
path=C:\Documents and Settings\Shellee\Start Menu\Programs\Startup\wkcalrem.LNK
backup=C:\WINDOWS\pss\wkcalrem.LNKStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcsm]
C:\Program Files\Common Files\DriveCleaner Free\dcsm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-05-26 11:45 257088 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
——— 2003-12-05 20:08 50688 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-01 23:31 648704 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2005-03-19 13:10 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
–a—— 2006-03-24 17:01 144448 C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2003-11-19 15:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2008-02-01 23:31 5032448 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 16:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McSysmon"=2 (0x2)
"McShield"=2 (0x2)
"McRedirector"=2 (0x2)
"mcpromgr"=2 (0x2)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"mcmispupdmgr"=3 (0x3)
"McAfee HackerWatch Service"=2 (0x2)
"Emproxy"=3 (0x3)

S2 DP1112;DP1112;C:\WINDOWS\system32\Drivers\DP.sys []
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 21:41]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 01:08:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-20 07:46:33 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\RUNDLL32.EXElC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.20.2.sxt _RegistrationOffer@16
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 07:33:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\0.log 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-02-02 7:38:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 15:37:59
.
2008-01-08 23:04:28 — E O F —

CCleaner

2Wire Wireless Client
Ad-Aware SE Personal
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0.1
AI RoboForm (All Users)
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft Software Suite
AT&T Yahoo! Applications
ATI Control Panel
ATI Display Driver
Avanquest update
AVG 7.5
AVG Anti-Spyware 7.5
AviSynth 2.5
BlackBerry Desktop Software 4.2.2
Broadcom Management Programs 2
CCleaner (remove only)
CCScore
Conexant D110 MDC V.9x Modem
Consumer Complete Care Services Agreement
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Picture Studio v3.0
Dell System Restore
DellSupport
Digital Line Detect
DivX Content Uploader
DivX Web Player
DVD X Rescue
DVDXCopy Platinum 3.2.1
EPSON CardMonitor
EPSON Copy Utility 3
EPSON CX4600 Reference Guide
EPSON PhotoStarter3.2
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
fflink
First Step Guide
HijackThis 2.0.0
Hotfix for Windows XP (KB914440)
Image Transfer
ImageMixer for Sony
ImageMixer VCD2
Intel® PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 1
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Keynote Connector
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
Learn2 Player (Uninstall Only)
Macromedia Flash Player
mCore
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Picture It! Photo Premium 9
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Streets and Trips 2004
Microsoft Web Publishing Wizard 1.52
Microsoft Word 2002
Microsoft Works
Microsoft Works 2004 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MicroStaff WINASPI
mIWA
mIWCA
mLogView
mMHouse
mobile PhoneTools
Modem Helper
Move Networks Media Player for Internet Explorer
Mozilla Firefox (1.5.0.11)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
mToolkit
Musicmatch for Windows Media Player
mWlsSafe
mXML
My Way Search Assistant
mZConfig
netbrdg
Netflix Preview Player
NetWaiting
NHJ Photo Manager
OfotoXMI
Picture Package
Pocket DVD Wizard
PowerDVD 5.3
Qualxserve Service Agreement
Quicken WillMaker Plus 2006
QuickSet
QuickTime
RealPlayer Basic
RedLightCenter
Revo Uninstaller 1.42
Roxio Activation Module
Roxio Creator Audio
Roxio Creator Data
Roxio Creator EasyArchive
Roxio Media Manager
SBC Yahoo! DSL Activation
ScanToWeb
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
SFR
SHASTA
Shockwave
skin0001
SKINXSDK
Sonic Creator Copy
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony Picture Utility
Sony USB Driver
Spybot - Search & Destroy
staticcr
tooltips
TurboTax Deluxe Deduction Maximizer 2006
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB946627)
Viewpoint Media Player
VPRINTOL
WebFldrs XP
WexTech AnswerWorks
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WIRELESS
Witches and Wizards Clipart
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI